LEVELFOURINFORMATIONSECURITY

Trust

Our own security

We ask vendors to publish what a customer would need to assess them. This is ours.

Last reviewed 30 August 2026.

Reporting

Report a vulnerability

If you believe you have found a security issue in a Level Four system, write to Security. Machine-readable details, including the address in full, are published at /.well-known/security.txt.

  • Acknowledgement within three business days and an assessment of the report within ten.
  • Good-faith research is welcome. We will not pursue or support legal action against anyone who reports an issue to us in good faith, avoids privacy violations and service disruption, and gives us reasonable time to respond before disclosing.
  • In scope: l4is.ai and its subdomains, and any service operated under them.
  • Out of scope: systems belonging to our clients or to third-party providers. If you have found something in a client system, tell us and we will route it — we will not act on it ourselves without their instruction.
  • No bounty. We do not currently pay for reports. We will credit you publicly if you would like us to.

Client information

How we handle what you give us

These are contractual commitments, not aspirations — they appear in the confidentiality section of every engagement we sign.

  • Access is limited to people engaged on the work. Personnel and contractors working on your engagement, plus our own auditors, assessors, insurers and professional advisers — each under equivalent written confidentiality obligations, with Level Four responsible for their acts as for its own.
  • Ordinary commercial services only. Client material is held using ordinary-course storage, backup and productivity services. We will identify them to you on request. Anything beyond that requires your consent.
  • Some material is never transferred. Penetration test reports and incident records are reviewed by screen share and are not copied to our systems.
  • Retention runs from the most recent engagement, not from a single statement of work, so your register survives between pieces of work. Material is returned or destroyed on request, subject to retention required for legal defense and to backups that cannot practically be reached.
  • Compelled disclosure is notified. If we are required by subpoena or a regulator to disclose your information, we tell you where we are legally permitted to.

Controls

What we run

Email authentication
SPF, DKIM and DMARC published for l4is.ai, with DMARC at an enforcing policy
Authentication
Multi-factor authentication on every account that supports it; phishing-resistant factors where available
Endpoints
Full-disk encryption, automatic patching and screen lock on every device used for client work
Credentials
A password manager for all credentials; no shared accounts
Transport
TLS on this site and on every service used for client material
Sub-processors
Identified to clients on request, and before any change that affects an active engagement

We publish what we actually do, rather than a control list borrowed from a larger organization, and we would rather this page be short and true than long and aspirational. If something you need is missing from it, Contact us and ask.