
Trust & Security/SOC 2 Type II
Levr has completed a SOC 2 Type II examination.
An independent CPA firm examined the controls Levr uses to protect customer data and evaluated how those controls operated throughout the review period.
What the report means
Independent evidence that our controls operated over time.
Brokers trust Levr with sensitive information, including bank statements, tax returns, and personal guarantees. Our SOC 2 Type II report provides independent evidence that the controls protecting this information were not simply documented. They were tested across a defined review period.
Controls were defined
The report describes the relevant system and the controls Levr says it operates.
Evidence was tested
The independent CPA firm performed procedures and evaluated evidence from across the review period.
Results were documented
The formal report includes the auditor's opinion, the tests performed, and the results of those tests.
Type I compared with Type II
One date versus a period of operation.
Type I
Evaluates whether controls are suitably designed as of a specific date.
Type II
Evaluates both the design of controls and how effectively they operated throughout a defined period.
Levr holds a Type II reportHow it shows up inside Levr
Controls that follow the full deal workflow.
Encryption
Data is encrypted at rest and protected with HTTPS and TLS in transit, with encrypted backups.
Access control
Role-based permissions and multi-factor authentication on critical systems help limit access to authorized people.
Data isolation
Brokers see their own clients and deals. Lenders see only the applications submitted to them.
Resilience
Encrypted backups and recovery controls support continuity when systems or infrastructure fail.
The framework
Five Trust Services Criteria.
Security is included in every SOC 2 examination. Availability, processing integrity, confidentiality, and privacy may also be included based on the scope of the service and engagement.
Security
Protection against unauthorized access, disclosure, and damage.
Availability
Systems remain available for operation and use.
Processing integrity
Processing is complete, valid, accurate, timely, and authorized.
Confidentiality
Information designated as confidential remains protected.
Privacy
Personal information is collected, used, retained, and disposed of appropriately.
For diligence teams
Request the formal report.
SOC 2 reports are restricted-use documents. Qualified lender partners and enterprise brokers can request Levr's Type II report under NDA.
A documented basis for evaluating Levr's controls without relying only on security claims or questionnaire answers.
SOC 2 is an examination and report, not a certification. The exact systems, controls, criteria, review period, testing, and results are documented in Levr's restricted-use report.