← Back to Legal Centre

TRUST & SECURITY

Controls are published only to the level the evidence supports.

Controlled-proving revision: 11 September 2026

Security principles

Levqor uses fail-closed exposure, least-privilege/authority boundaries, evidence-backed state, bounded retries/actions and independent verification for material work. Possession of credentials, a route, CI, a Preview or a payment integration does not itself grant business authority.

Customer identity and access

The customer portal reuses authenticated account identity rather than treating a project/meeting reference alone as sufficient access to private evidence. Current routes distinguish public information from authenticated controls. Customers must protect sign-in links and report suspected compromise.

Material actions

The current controlled-proving implementation keeps external outreach, public distribution, live payment/refund execution and production-data mutation separately gated. Application, privacy and support actions must expose explicit validation-only or fail-closed states where execution is disabled rather than pretending an action completed.

Evidence and integrity

BC1 meeting billability requires provenance, suppression-clear, duplicate-clear, approved-method, qualification, commercial-relevance and attendance evidence, plus an acceptance record for an accepted result. Personal-data minimisation is built into the delivery artifact: raw attendee name/contact is not required in the deterministic result artifact.

Fraud and abuse

Suspicious identity, payment, evidence, access, suppression and provider behaviour may cause a pause, restriction or investigation. Levqor's Acceptable Use & Anti-Abuse Policy identifies prohibited conduct and available controls.

Privacy and suppression

Prospect/contact data is source/provenance bound, subject to freshness and suppression controls, and is not made acceptable merely by model confidence. A direct-marketing objection is intended to survive rediscovery or provider refresh.

AI safety boundary

Public AI is grounded to current Pipeline information and must not invent private customer, payment or meeting state. Autonomous support or delivery donors do not receive authority merely because their code exists.

Availability and recovery

Levqor maintains operational monitoring, evidence/audit and recovery capabilities in the wider estate, but monitoring claims remain fail-closed where live process evidence is unavailable. This page does not publish a numeric uptime, recovery-time, backup-retention or human-response SLA that has not been specifically frozen and evidenced for First Three.

Certifications

No ISO, SOC, PCI, Cyber Essentials or other certification is claimed by this page unless a current certificate is separately verified and published. Use of external standards in Levqor's internal assurance work is not the same as certification.

Security reporting

Use the Responsible Disclosure route for suspected vulnerabilities or security issues. Do not access another customer's data or continue exploitation after demonstrating the issue.

Release boundary

Published support, billing, privacy and partners role-mailbox delivery has been independently proved. Exact-current accessibility, formal performance, buyer/full-journey, body-aware quarantine and changed-surface security acceptance have passed for the controlled proving release. Current whole-system assurance remains evidence-bounded, and technical publication does not itself grant prospect-contact, payment, distribution or broader commercial authority.

Customer truth: Levqor does not guarantee sales, revenue, ROI or closed business. First Three is governed by the written qualification and commercial terms agreed before activity begins.