Trust & Security at Levr

Loan files are some of the most sensitive documents a business ever shares — bank statements, tax returns, financial statements, personal guarantees. Here is exactly how we protect them, in plain language. The formal versions live in our Privacy Policy and Terms of Service; this page is the human-readable map to both.

SOC 2 Compliant
Secure Broker Certified
BBB Accredited
Built on Google Cloud

The three promises

Your data is yours

We never sell it, and we never share customer data with third parties without explicit permission. When you leave, your data does not become ours to keep using.

Your data is siloed

Brokers see only their own clients and deals. Lenders see only what is submitted to them. Your deal data is never exposed to a competing lender and never used to train anything.

Your data is encrypted

Bank-level 256-bit encryption protects everything, in transit and at rest. The same standard major financial institutions use.

Compliance and independent verification

We do not ask you to take our word for any of this. Levr maintains SOC 2 compliance and undergoes regular third-party security audits and penetration testing, most recently in 2026. Levr is also certified by Secure Broker, the independent certification for commercial finance brokerages, and our infrastructure runs on Google Cloud Platform, which independently maintains SOC 2, ISO 27001, and GDPR compliance for the underlying data centers.

Lenders and enterprise partners: detailed security documentation, audit reports, and completed security questionnaires are available on request. Contact us and we will get them to your compliance team quickly. This is a normal part of lender onboarding and we are fast at it.

How your data is protected, layer by layer

Infrastructure. Fully cloud-based on Google Cloud Platform, inside a private environment segregated from the public internet.
Encryption. 256-bit at rest, HTTPS/TLS in transit, encrypted backups. Document links are signed and expire, so a leaked URL goes dead instead of leaking a file.
Access control. Role-based, least privilege, for customers and for our own team, with multi-factor authentication on critical systems.
Audit trail. Every submission and document action logged, from intake to funding.
Your documents

Who sees what

DataYouPeople you inviteThe lender you submit toOther brokersOther lenders
Your documents✓ submitted files onlyNeverNever
Your deal pipeline✓ their deals onlyNeverNever
Your commission dataNever✓ their payouts onlyNeverNever

The rule is simple: data moves only where you send it. Submitting a deal to one lender shares that application with that lender and nobody else. It is never pooled, resold, or used to train models.

Resilience: what happens if something breaks

Backups of all customer data run daily, encrypted, and are stored in a separate region from the primary database, so even a data-center-level incident does not threaten your files. Critical databases keep point-in-time recovery. And because documents live in Levr instead of email threads, a lost laptop no longer means lost client files.

How we build

Security is part of how the product gets made, not a bolt-on: code is peer-reviewed with security review before it ships, we follow OWASP secure-coding standards, automated scans check our code and dependencies continuously, and an incident response plan with named owners exists for the scenarios we hope never happen.

Common questions

Does Levr sell my data?

No. We never sell customer data, and we never share it with third parties without your explicit permission.

Can other lenders see my application?

No. A submission goes only to the lender you choose. Deal data is siloed per lender and is never visible to competitors or used to train anything.

Who can see the documents my client uploads?

The client, you as their broker, anyone the client explicitly invites, and the lender the deal is submitted to. Nobody else, including other brokers and lenders on the platform.

What encryption does Levr use?

Bank-level 256-bit encryption at rest, HTTPS/TLS in transit, and encrypted backups, on Google Cloud infrastructure.

Is Levr SOC 2 compliant?

Yes. Levr maintains SOC 2 compliance and undergoes regular third-party security audits, most recently in 2026. Audit documentation is available to partners on request.

I am a lender. How do I get your security documentation?

Contact us. Detailed security documentation, audit reports, and completed questionnaires are available on request, usually same-week.

How do I report a security concern?

Email [email protected] with the details. Security reports go to the top of the queue and we will acknowledge quickly.

Formal terms: Privacy Policy · Terms of Service, Section 6 · Last reviewed July 2026.

Made for modern brokers

Levr.ai is built for brokers who want an easier way to work. Access 50+ lenders, automate application intake, and close more deals faster, while keeping 100% commission. Scaling revenue while delighting clients has never been easier.