SOC2C

Is this your company? Buyers are checking Level Access here. Claim levelaccess.com free to control the listing, earn the badge buyers trust, and see who's evaluating you.

Claim free
Level Access logo

Level Access

Trust level
Listed
Unverified

Sourced from public information. Not yet verified by the company.

Level Access is SOC 2 Type II compliant. Level Access also holds ISO 27001.

Framework
Auditor
Last report
Renewal
View official trust center ↗

About

Level Access provides a comprehensive platform designed to support all aspects of an effective accessibility compliance program. Our powerful testing engine, workflow automation, and reporting capabilities help organizations identify and remediate accessibility defects efficiently. By integrating accessible development best practices and offering an extensive training course library, Level Access enables teams to seamlessly incorporate accessibility into their existing development processes. Our platform ensures rapid conformance with WCAG 2.1 AA and other leading accessibility standards, stre

Compliance & infrastructure

Hosting
AWS
Data handled
Credit card informationPersonal health informationAccessibility metadataWebsite form data

Documents

21

Subprocessors

15
  • D
    DataDog, Inc. · SIEM
    USA
  • A
    Amazon Web Services · Cloud provider
    USA (Ohio and California)
  • M
    Microsoft · Cloud provider
    USA
  • A
    Amplitude, Inc. · User behavior analytics
    USA (California)
  • M
    Mailgun (Sinch) · Platform email notifications
    USA (California)
  • A
    Auth0 · Secure access for customers
    USA (Washington State)
  • P
    Pendo · Software optimization
    USA (North Carolina)
  • H
    Harness · Feature flag provider
    USA (California)
  • M
    MongoDB · Database hosting for the software platform
    USA (New York)
  • Z
    Zendesk · Customer support ticketing system
    USA (California)
  • G
    Google · Website usage statistics
    USA (California)
  • S
    Stripe · Payment processing
    USA
Show all 15 subprocessors
  • A
    Airbrake · Application performance and security monitoring
    USA
  • E
    Elastic · Data indexing
    USA
  • C
    CDN77 · Content delivery
    USA

Compliance leadership

The person who leads Level Access's SOC 2 isn't listed yet. Claim this profile to add it.

Penetration test

Unknown. Level Access's penetration test vendor isn't listed yet.

Claim this profile to add it.

Recent updates

Level Access Signs CSA AI Trustworthy PledgeJun 2026

Level Access has signed the Cloud Security Alliance (CSA) AI Trustworthy Pledge, joining organizations committed to advancing responsible and secure AI. The pledge represents a public commitment to developing and deploying AI systems in alignment with key principles, including safety, transparency, ethical accountability, and privacy protection. Level Access is publicly listed among participating organizations: View CSA AI Trustworthy Pledge signatories By participating in this initiative, Level Access reinforces its approach to AI governance—prioritizing secure design, responsible use, and protection of customer data. This milestone supports our broader commitment to transparency and trust as we continue to evolve AI-enabled capabilities across our products and services.

Datadog / axios npm Supply Chain Incident – No Impact to Level AccessApr 2026

Level Access is not impacted by the recently disclosed npm supply chain incident involving malicious versions of the `axios` package (versions 1.14.1 and 0.30.4), which Datadog reported may affect certain Datadog open‑source CI/CD and serverless tooling. After internal review, we confirm that Level Access does not use the affected Datadog packages or installation methods associated with this incident. We have additionally scanned our environment and found no instances of the malicious `axios` versions or related indicators of compromise. Based on our assessment, there is no impact to Level Access systems, products, or customer data. No mitigation actions are required at this time. As part of our ongoing security program, we continue to monitor updates from Datadog and relevant security intelligence sources and will take appropriate action should the situation change. If you have any questions or concerns, please be in touch.

Cisco Catalyst SD‑WAN Vulnerabilities – No Impact to Level AccessMar 2026

Level Access is not impacted by the recently disclosed vulnerabilities affecting Cisco Catalyst SD‑WAN systems (CVE‑2026‑20127 and CVE‑2022‑20775). After internal review, we confirm that Level Access does not use Cisco Catalyst SD‑WAN or other Cisco SD‑WAN solutions in our environment. Our infrastructure is hosted in Amazon Web Services (AWS) and managed exclusively through AWS‑native services. Level Access does not manage or operate physical network devices or SD‑WAN controllers. As a result, these vulnerabilities are not applicable, and no mitigation actions are required. As part of our ongoing security program, we continue to monitor relevant security advisories and threat intelligence to proactively assess potential risks. If you have any questions or concerns, please be in touch.

Fortinet Critical Vulnerability – No Impact to Level AccessFeb 2026

Level Access is not impacted by the recently disclosed critical vulnerability affecting certain Fortinet products (CVE‑2026‑24858). After internal review, we confirm that Level Access does not use Fortinet products in our environment. Therefore, no mitigation actions are required. We will continue to monitor advisories from FortiGuard Labs and relevant security intelligence sources as part of our ongoing commitment to proactive risk management. If you have any questions or concerns, please be in touch.

Trust Center Update: Apache Tika Vulnerability – No Impact to Level AccessDec 2025

Level Access is not impacted by the recently disclosed critical vulnerability in Apache Tika (CVE-2025-66516). After internal review, we confirm that Level Access does not use Apache Tika in our environment. Therefore, no mitigation actions are required. If you have any questions or concerns, please be in touch.

This listing is partial

7/11 details · 64%

SOC2C shows the verified essentials. 4 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.

  • Auditorraises trust
    Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
  • Report dateraises trust
    Add your most recent report period so buyers see how current your SOC 2 is.
  • Renewal date
    Add your renewal window so buyers know your coverage is active.
  • Security controls
    Confirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Claim free to control your listing

Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.

Frequently asked

Is Level Access SOC 2 compliant?
Level Access is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is Level Access ISO 27001 certified?
According to Level Access's public trust center, Level Access is ISO 27001 certified. On SOC2C this listing is Listed.
Is Level Access SOC 2 Type I or Type II?
Level Access is SOC 2 Type II compliant. A Type II report covers how security controls operated over a period (typically 3 to 12 months), a stronger signal than a point-in-time Type I.
Can I use Level Access's SOC 2 for a vendor risk assessment?
Yes. Level Access's SOC 2 status, frameworks, auditor, and renewal timing are on SOC2C for vendor risk and security reviews. Request the underlying report through SOC2C to complete your third-party risk file.
Is Level Access penetration tested?
Level Access hasn't listed its penetration testing on SOC2C yet. SOC 2 Type II programs typically include periodic third-party penetration tests; the company can add who performed theirs.