SOC2C

Is this your company? Buyers are checking Lebra Technologies Inc here. Claim lebrahq.com free to control the listing, earn the badge buyers trust, and see who's evaluating you.

Claim free
Lebra Technologies Inc logo

Lebra Technologies Inc

Trust level
Listed
Unverified

Sourced from public information. Not yet verified by the company.

Lebra Technologies Inc is SOC 2 Type II compliant. Lebra Technologies Inc also holds NIST CSF.

Framework
Auditor
Last report
Renewal
View official trust center ↗

About

Lebra is an AI-powered leadership platform that helps leaders build a culture of belonging and boost employee engagement. By combining AI with human insights, our platform enables more frequent, meaningful connections with employees. Lebra streamlines leadership workflows, automates key interactions, and reduces administrative burdens, allowing leaders to focus on driving productivity and reducing burnout across their teams. Security is a top priority at Lebra. We are committed to ensuring that all personal and organizational data is managed with the highest standards of safety, confidentialit

Compliance & infrastructure

Hosting
AWSGCP
Data handled
Customer personally identifiable informationCredit card informationPersonal health informationStudent data

Documents

12

Subprocessors

8
  • G
    GitHub · Version control
  • A
    Amazon Web Services · Cloud provider
  • S
    Supabase · Cloud provider
  • N
    Nylas, Inc. · Cloud provider
  • V
    Vanta · Security
  • R
    Rippling · Employee management
  • G
    Google Workspace · Identity provider
  • G
    Google Cloud Platform · Cloud provider

Compliance leadership

The person who leads Lebra Technologies Inc's SOC 2 isn't listed yet. Claim this profile to add it.

Penetration test

Unknown. Lebra Technologies Inc's penetration test vendor isn't listed yet.

Claim this profile to add it.

Recent updates

Lebra System StatusJan 2025

https://lebra.betteruptime.com/

This listing is partial

7/11 details · 64%

SOC2C shows the verified essentials. 4 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.

  • Auditorraises trust
    Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
  • Report dateraises trust
    Add your most recent report period so buyers see how current your SOC 2 is.
  • Renewal date
    Add your renewal window so buyers know your coverage is active.
  • Security controls
    Confirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Claim free to control your listing

Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.

Frequently asked

Is Lebra Technologies Inc SOC 2 compliant?
Lebra Technologies Inc is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is Lebra Technologies Inc NIST CSF compliant?
According to Lebra Technologies Inc's public trust center, Lebra Technologies Inc is NIST CSF compliant. On SOC2C this listing is Listed.
Is Lebra Technologies Inc SOC 2 Type I or Type II?
Lebra Technologies Inc is SOC 2 Type II compliant. A Type II report covers how security controls operated over a period (typically 3 to 12 months), a stronger signal than a point-in-time Type I.
Can I use Lebra Technologies Inc's SOC 2 for a vendor risk assessment?
Yes. Lebra Technologies Inc's SOC 2 status, frameworks, auditor, and renewal timing are on SOC2C for vendor risk and security reviews. Request the underlying report through SOC2C to complete your third-party risk file.
Is Lebra Technologies Inc penetration tested?
Lebra Technologies Inc hasn't listed its penetration testing on SOC2C yet. SOC 2 Type II programs typically include periodic third-party penetration tests; the company can add who performed theirs.

Answers published by Lebra Technologies Inc

Reproduced from Lebra Technologies Inc's own trust center. These are the company's statements about its security practices — SOC2C has not tested or verified them, and they may have changed since we last read the page. Check the source ↗

How will your data be stored and shared with GPT-4?
- We use Supabase, built on top of AWS, so essentially AWS for our database provider. We don’t house any data outside of this. - Supabase is SOC2 type 2 and HIPAA complaint. Added security, even though Lebra does not store any HIPAA information. - Supabase data is encrypted at-rest at the storage level using AES256 (advanced Encryption Standard). - Resources: Security at Supabase - Resources: Cloud Security – Amazon Web Services (AWS) - Additionally, health systems use AWS to store HIPAA data: \Epic on AWS | Healthcare & Lifesciences Solutions ([amazon.com)\](https://aws.amazon.com/health/solutions/epic/#:~:text=Epic customers can leverage AWS,controls in the AWS cloud.)) - ChatGPT-4 API - The OpenAI API, which we use, has been evaluated by a third-party security auditor and is SOC 2 Type 2 compliant. - An added benefit of the API is security and privacy. Unlike the use ChatGPT without an API, the data submitted through our API to OPENAI is not used to to train OpenAI models. (See below). - Resources: Security (openai.com)
How will Lebra ensure data is secure?
- Your data is your data. We never sell your data to third parties. - We force all API transactions to use HTTPS protocol. - All of our servers and databases are hosted in the US with SOC 2 and ISO 27001 certified providers. - We maintain complete, regular backups of user data to prevent data loss.
What kind of logging capabilities do you provide the district to access any official information entered into your system by a district employee? For example, are we given a management suite that allows us archival access to any records entered?
Yes, you will be able to archive records. If you need reports ran, we do that on our end.
How does the AI use our data?
The AI in the Lebra platform primarily uses SSM's data to personalize and enhance the employee engagement experience. This includes leveraging details like employee birthdays, names, titles, and past notes/follow-ups. The AI analyzes this data to perform three functions at the moment 1) to generate customized outreach given a specific subject using 'AI assistant' functionality' 2) to generate a relevant agenda using the 'Daily Agenda' functionality and 3) to generate relevant responses in the Lebra "Assistant", which may be provided queries of various forms. In total, these data are used to provide relevant suggestions, reminders, and insights, aiming to foster a more engaged and cohesive work environment.
Will SSM data be shared with any 3rd parties outside the vendor and SSM?
In the case of Lebra, which utilizes GPT-4 created by OpenAI, certain SSM data is indeed shared with OpenAI, a prominent AI research and deployment company. This sharing is essential for the functioning of the AI model within the platform. However, it is important to note that such data sharing is governed by specific agreements, including the OpenAI "Business Terms" (OpenAI Business Terms). These terms typically outline the scope, limitations, and protections related to data sharing and usage.

Business & Industrial peers that completed SOC 2