World-class security built for enterprises.
At LVRG, delivering enterprise-grade security and ensuring customer trust is paramount. We are committed to the protection of all our customers' data and the lawful, compliant use and processing of that data. LVRG's infrastructure has been purpose-built to meet the robust security, compliance and privacy needs of the modern enterprise.
Our Commitment to Security
LVRG drives transparency and alignment across teams while automating what was previously manual data entry. With this level of data transparency also comes great responsibility to maintain the highest standards of data privacy and security. With an ongoing focus on security, data privacy, and GDPR readiness, we aim to strike a balance between transparent communications and maintaining your employees’ and customers’ privacy rights.
Security and Privacy Are at the Forefront of Every Decision We Make
LVRG was built from the ground up with enterprise security in mind. Our customers entrust sensitive data to our care. Keeping it secure is our mission. We ensure the security of your data in our sales management software with encryption in transit and at rest. The application undergoes regular penetration testing and security reviews by white hat security firms. LVRG is designed to be GDPR compliant. We are also SOC 2 Type II-certified. LVRG’s computing infrastructure is provided by Amazon Web Services, a secure cloud services platform. Amazon’s physical infrastructure has been accredited under ISO 27001, SOC 1/SOC 2/SSAE 16/ISAE 3402, PCI Level 1, FISMA Moderate, and Sarbanes-Oxley.
Without our customers, we are nothing - so every decision we make is with the customer first. At LVRG, our team operates around the clock to uphold customer trust and stay abreast of the evolving security landscape through meticulous, ongoing research by both our team and expert advisors. World class security controls and privacy policies are LVRG's #1 priority.
Andrew Stroup
— CEO, LVRGEnterprise Ready Compliance
SOC 2 Type II
We are in-process for SOC 2 Type II certification. This certification is reserved for organizations that have demonstrated standard operating procedures for organizational oversight, vendor management, risk management, and regulatory oversight over a length of time.
CSA STAR
We are registered with CSA STAR, the industry’s most powerful program for security assurance in the cloud.
Secure And Reliable Infrastructure
Amazon Web Services (AWS)
LVRG uses Amazon Web Services (AWS), exclusively, for the hosting of staging and production environments. AWS data centers are monitored by 24×7 security, biometric scanning, video surveillance and are SOC 1, SOC 2, and SOC 3 certified.
World-Class Application Security
Data Encryption
Data is encrypted in-transit using bank-grade TLS 1.2, the safest method available today. Data is encrypted at-rest using 256-bit encryption via native AWS capabilities.
OAuth
Customers always authenticate via their platforms of choice (Okta, GSuite or Office365) and never set a LVRG-specific password.
Continuous Commitment to Security
Penetration Testing
In addition to our annual SOC 2 audits, LVRG is committed to conducting manual penetration testing by specialized Tier-1 vendors. Latest reports from our partners at Casaba are available upon request. Additionally, we use multiple scanning services to continuously scan our application, both from outside and inside, daily.
Continuous Threat Monitoring
We employ multiple solutions to provide continuous threat intelligence and vulnerability testing, with real-time alerting. Static and dynamic code analysis is a core component of our continuous integration and delivery software development approach.
Dedicated Security
We employ onsite staff responsible for reviewing, updating, testing and maintaining our security and privacy controls in accordance with our SOC 2 certification and in preparation for new certifications, security threats, laws and regulations.
Security Project Reviews
All engineering projects must go through architecture reviews and receive sign off from the Security team before work can begin.
Security Code Reviews
Engineers are required to complete a security review checklist as part of the software development life cycle (SDLC) for all code changes.
Internal Processes
SSO / SCIM / MDM
We never use or store passwords internally. From the wifi and applications we use to do our jobs, to how we secure our physical location, the only authentication source-of-truth is our SSO / SCIM / MDM solution. LVRG does not support login or password-driven access. All access controls are centralized around tight integration with our IAM system (Okta), MDM (Okta), and AWS IAM per industry best practices.
Breach Notifications
We treat breaches with the highest level of urgency and are committed to delivering timely communications to customers who might be impacted. Any breaches will be communicated within 72 hours per internal process and GDPR compliance. There have been no recorded breaches to date.
Employee Devices
We use Macs exclusively. Each Mac is fully-managed. Only managed machines can get onto our network, or AWS. Our policies prohibit anyone from being able to move customer data to an unauthorized device, as well as to any laptop or other device. Our policies restrict all employees from downloading data from our production environment, mounting external drives in MacOS on personal devices, or transferring files online without leaving a significant trail behind.
Mandatory Employee Training
All employees are required to complete training on data privacy and best practices for securing and handling user data.
Employee Background Checks
All employees go through thorough background checks executed by a Tier 1 vendor as a prerequisite for employment.
How does LVRG Maintain GDPR Compliance?
Data Protection by Design and by Default (Article 25)
- All customer data is stored in logically separated AWS VPC environemnts with full encryption, using native AWS means and AES 256-bit encryption algorithm
- Review of data sharing and processing agreements of all partner organizations to ensure compliance with the provisions of the GDPR
- Exclusive use of AWS infrastructure for all data processing
Right to Data Portability (Article 20)
- Export activity by request
Right to Erasure (Article 17)
- Data deletion requests are triple-validated, and thorough
Pseudonymisation (Article 5(c))
- Everything is encrypted, everywhere
- No personal data in application logs
Breach Notifications (Article 33)
- Early notification upon identified breach
- Details about our commitments are outlined in our EUSA
Sensitive Content
- Automated sensitive content flagging and notification
- LVRG does not collect or store PCI, HIPAA or Special Categories of Personal Data (Article 9)
Opt-Outs for All External Communications
- All customers have the right and option to opt-out of LVRG communications
Employee Training
- Mandatory onboarding training on data protection, GDPR, and the rights and freedoms of data subjects
- Quarterly engineering training on InfoSec and web application security
Security Is Our Top Priority
If you have any questions about LVRG security, please contact our IT Security Team anytime at security@lvrg.ai.