Privacy & Security
Security and privacy
How LevelFour connects to your accounts, protects your data and uses AI, and how to request a security review or report a vulnerability.
AI and your data
- LevelFour does not use your data to train, fine-tune or otherwise improve AI models, ours or anyone else's. That covers data from your connected accounts, the questions you ask and the answers you get.
- Our agreements with the AI providers we work with forbid them from training on your data.
- AI features see only your organization's data, and only what the person asking is allowed to see.
- We will change this only if your organization opts in, in writing.
Connecting your accounts
You grant LevelFour access through each provider's own access controls: an IAM role on AWS, a service account on Google Cloud, Azure Lighthouse on Azure, or an API key or token you create on other providers. You can revoke it at any time, and LevelFour never asks for a password or a console login.
- Read access. LevelFour reads billing data, resource configuration and usage metrics. Apart from the billing exports you set up for it, it does not read the contents of your storage, databases or application logs.
- Least privilege. LevelFour asks for read-only access wherever the provider offers it. If a provider offers no read-only key, its connector page says so and lists what else the key can do.
- Changes. Other than setting up the cost exports and cost services it reads, LevelFour changes resources in your account only after an admin in your organization approves the change.
Each connector's page lists the exact permissions it needs.
Product and data security
- Single sign-on. Sign in through Google Workspace, Microsoft Entra ID, Okta or any SAML 2.0 identity provider with Enterprise SSO.
- Role-based access control. Viewers get read-only access, which suits contractors and analysts. Members prepare savings and edit boards. Only admins approve a change or manage the organization. LevelFour enforces roles on every request, whether it comes from the dashboard, the API, the CLI or an AI client.
- API keys. Admins create API keys as read-only or read & write, can set them to expire, and can revoke them at any time.
- Audit trail. LevelFour logs every decision on a saving: who made it, when, and from where.
- Internal access. A small group of LevelFour engineers can access production, only to run and support the service. They connect through AWS Systems Manager, with no inbound ports open to the internet.
- Network protection. The API runs in private subnets of an AWS VPC, and the database has no public endpoint.
- Encryption. TLS in transit and AES-256 at rest. LevelFour encrypts the keys and tokens you give it with AWS KMS, and stores its own API keys as one-way hashes.
- Isolation. Each organization's cost and savings data lives in its own database.
- Hosting. Amazon Web Services in the United States (
us-east-1), with automated backups. - Data retention. LevelFour keeps your data while your organization uses it. To leave, revoke access in each provider and ask us to delete your data. We delete it within 30 days of your written request.
Security reviews
Email security@levelfour.ai to get our list of subprocessors, request a data processing agreement, or send us your security questionnaire.
If an incident affects your data, we notify your organization's admins without undue delay.
Vulnerability disclosure policy
Overview
If you find a security issue in LevelFour, tell us. We review and triage every report and fix the issues we confirm. We do not pay bounties.
Scope
In scope:
levelfour.aiand its subdomains, includingdashboard.levelfour.ai,docs.levelfour.aiandapi.levelfour.ai- The LevelFour REST API and MCP server
Report issues that affect confidentiality, integrity or availability, such as:
- authentication or access control flaws, including any way to reach another organization's data
- injection or remote code execution
- cross-site scripting (XSS) or cross-site request forgery (CSRF)
- server-side request forgery (SSRF)
- exposure of sensitive data
- security misconfiguration
Out of scope:
- typos, layout and other content issues
- feature requests and UI suggestions
- issues in third-party applications
- denial of service and volume testing
- social engineering of LevelFour staff or customers
- spam or email deliverability
How to report
Email security@levelfour.ai with:
- a description of the issue
- the URL, page, API endpoint or asset it affects
- the steps to reproduce it
- screenshots, logs or proof-of-concept code that support it
Do not include anyone else's data, or screenshots of an account that is not yours.
Terms and expectations
By sending a report, you agree that:
- you did your research in good faith, on accounts you own, with as little disruption as possible
- you will not publish the issue until we have had a reasonable chance to fix it
We acknowledge each report as soon as we can and may ask you for more detail.