Is this your company?Buyers are checking Real Magic Inc here. Claim levitate.ai free to control the listing, earn the badge buyers trust, and see who's evaluating you.
Launched in 2017 by ShareFile founder Jesse Lipson, Levitate is a catalyst for building authentic relationships. Dedicated to fostering genuine connections, Levitate’s Happiness Platform equips relationship-based businesses with the tools to cultivate meaningful interactions with clients, referral sources, and prospects. Levitate's Happiness Platform allows customers to send tailored emails at scale, post to social media, keep in touch with clients via text, send surveys & events, generate reviews, schedule meetings, send handwritten cards, remember key facts about their contacts, launch a new
SOC2C shows the verified essentials. 6 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.
Auditorraises trust
Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
Report dateraises trust
Add your most recent report period so buyers see how current your SOC 2 is.
Renewal date
Add your renewal window so buyers know your coverage is active.
Subprocessors
List your subprocessors so buyers can assess fourth-party risk, the way your trust center does.
Hosting
Add where you host (AWS, GCP, Azure) and data residency.
Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.
Frequently asked
Is Real Magic Inc SOC 2 compliant?
Real Magic Inc is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is Real Magic Inc HIPAA compliant?
According to Real Magic Inc's public trust center, Real Magic Inc is HIPAA compliant. On SOC2C this listing is Listed.
Is Real Magic Inc PCI DSS compliant?
According to Real Magic Inc's public trust center, Real Magic Inc is PCI DSS compliant. On SOC2C this listing is Listed.
Is Real Magic Inc SOC 2 Type I or Type II?
Real Magic Inc is SOC 2 Type II compliant. A Type II report covers how security controls operated over a period (typically 3 to 12 months), a stronger signal than a point-in-time Type I.
Can I use Real Magic Inc's SOC 2 for a vendor risk assessment?
Yes. Real Magic Inc's SOC 2 status, frameworks, auditor, and renewal timing are on SOC2C for vendor risk and security reviews. Request the underlying report through SOC2C to complete your third-party risk file.
Is Real Magic Inc penetration tested?
Real Magic Inc hasn't listed its penetration testing on SOC2C yet. SOC 2 Type II programs typically include periodic third-party penetration tests; the company can add who performed theirs.
Can I get Real Magic Inc's SOC 2 report?
Real Magic Inc's SOC 2 report is available on request. Request access through SOC2C and we coordinate the company-side NDA and delivery.
Is Real Magic Inc secure?
Security isn't a single yes/no, but Real Magic Inc is SOC 2 Type II compliant and holds SOC 2 Type II, HIPAA, PCI DSS. SOC2C verifies its compliance posture and shows how strongly each fact is proven.
Does Real Magic Inc have a bug bounty or vulnerability disclosure program?
Real Magic Inc hasn't listed a bug bounty or vulnerability disclosure program on SOC2C. Many companies accept security reports at security@levitate.ai or via a /security page (Real Magic Inc lists a security contact).
Who are Real Magic Inc's subprocessors?
Real Magic Inc's subprocessors aren't listed on SOC2C yet. The company can add them so buyers can assess fourth-party risk.
Where does Real Magic Inc host or store data?
Real Magic Inc's hosting and data-residency details aren't listed on SOC2C yet. The company can add where it hosts (AWS, GCP, Azure) and which data it handles.
Where is Real Magic Inc's trust center or security page?
Real Magic Inc's trust center is at https://trust.levitate.ai. Its verified SOC 2 status, frameworks, and documents are summarized on its SOC2C profile.
What is Levitate?
Levitate helps relationship-based business keep in touch with clients, prospects, and centers of influence in a personal and authentic way. They provide software, custom content, and marketing coaching services to help advisors send personalized, authentic emails at scale. By leveraging metadata from email, calendar, and CRMs, they help their customers strengthen and maintain the personal relationship with their clients to drive organic growth, retention, and cross-sell other services.
How does Levitate differ from other mass-blast email tools?
Levitate sends emails directly from your email server individually, so they never feel like a mass email because they are not. You gain the efficiency of a mass email service, without sacrificing the personal touch. RIAs also love the Outlook Plug-in, which brings the Levitate interface right into your email. This allows you to have key facts on hand when you need them, such as clients' kid’s names, dog’s name, favorite sport, wine preference, and whatever facts that are helpful to have on hand when communicating with a client to make it feel personal --and without the need to log into a separate system.
Why does Levitate connect to my email?
Levitate connects to your email server to allow you to send messages to your clients and other relationships at scale while appearing as if you sent them individually. The permission to allow Levitate to send emails allows you to use the Levitate application but emails are sent from your own email server. The ability to place items on your calendar allows them to set reminders to follow up with contacts or to complete action items, and to use the meeting booking feature. Levitate servers do not store the content of your email messages or the details of the meetings on your calendar (such as meeting descriptions and attachments) unless the emails are sent through the Levitate application. Thier system does scan the replies to emails sent through Levitate to detect whether the email message bounced or whether the recipient requested to unsubscribe from future emails. In those cases, Levitate never stores the content of the message but may save you the effort of unsubscribing them from further group sends. Levitate does not access other emails, either sent or received. Levitate does not sell, trade, or market to your contacts stored in Levitate. Your contacts and your data are your property and always owned by you.
Can Levitate access my email?
Levitate's unique differentiator is the intelligence gained from connecting with your email server. When you connect Levitate with your email system such as Google Apps for Business, Gmail, Office 365, Outlook.com, or traditional Microsoft Exchange Server, their system will have access to data in your address book, email messages, and calendar. They will use meeting history, metadata about sent email messages (name and email of the email sender, recipient, and time/date when message was sent), and your address book to help build your contact list in the Levitate application. Depending on the features included in your Levitate plan, they may also use these statistics about meetings and sent email messages to provide you with reporting, notifications, and analytics to help you better understand the interactions you or your colleagues have had with individuals and companies. Levitate also requires permission to send email, place items on your calendar, and update your contacts. The permission to send email allows you to use the Levitate application to compose email messages to your contacts. The ability to place items on your calendar allows them to set reminders to follow up with contacts or to complete action items. The ability to update your contacts allows Levitate to potentially add contacts to your email address book that were created in Levitate or to sync information from Levitate back into your email address book. Our servers do not store the content of your email messages or the details of the meetings on your calendar (such as meeting descriptions and attachments), unless the emails are sent through the Levitate application. In some cases, our system may scan the replies to emails sent through Levitate to detect whether the email message bounced or whether the recipient requested to unsubscribe from future emails. In those cases, we never store the contents of the message but may save you the effort of unsubscribing them from further group sends.
Is Levitate FINRA compliant?
According to the Security and Exchange Commission (SEC) Rule 17a-4, broker-dealers in the financial services industry are required to retain and index electronic correspondences, including email, with immediate accessibility for a period of two years and with non-immediate access for at least six years. As a result, almost all broker-dealers have turned to digital archiving solutions designed for FINRA and SEC 17a-4 compliance. By design, Levitate emails are always, and only, sent through your own email servers and will therefore work seamlessly with your existing controls and archiving solutions. FINRA Rule 2210 governs three categories of "communications" by FINRA member firms: institutional communications, retail communications and correspondence. The Rule's general content standards apply to all communications and are meant to ensure that communications are fair, balanced and not misleading. To ensure compliance with FINRA Rule 2210, all group emails should continue to be reviewed by you or your compliance officer prior to sending.
How is my email connection secured?
For O365 and G Suite (Gmail), Levitate utilizes OAuth, an open-standard authorization protocol or framework that provides applications like Levitate, secure designated access. Through OAuth, their access is limited to exactly what Levitate needs to function. OAuth doesn’t share password data with the Levitate application but instead uses authorization tokens to prove an identity between your email server and the Levitate application. OAuth allows you to approve Levitate's ability to work with your email system without providing the Levitate application your password directly. This reduces your risk in a major way: In the unlikely event Levitate ever suffered a breach, your email password would not be compromised. For Exchange and IMAP email servers, which are more legacy email servers, Levitate manages credentials as securely as possible. Stored credentials are encrypted using Amazon Web Service’s (AWS) Key Management Service (KMS). AWS KMS uses FIPS 140-2 validated hardware security modules to protect the security of the encryption keys, and each user has a unique encryption key to protect his/her password. With KMS, the encryption key will never leave the hardware security modules, giving both Levitate and their clients additional protection.
Can I use a cloud-based software like Levitate at my firm?
While widespread in use, there are still attorneys that remain skeptical about the legality of cloud computing and whether they can use the cloud technologies in their legal practices. Bar Associations and Law Societies throughout the United States have issued opinions on cloud computing for lawyers and the vast majority highlight that lawyers can use cloud computing, provided they exercise reasonable care to keep client information and files confidential. For example, a provider must be able to ensure a reasonable expectation of security so that a law firm is able to keep its clients’ information confidential. Practice Management Systems and cloud email providers are both examples of cloud computing software. All of Levitate’s server infrastructure (application servers and databases) is hosted in Amazon Web Services, the industry leading cloud hosting provider.
What about Attorney Client Privilege?
Attorney-client privilege preserves the confidentiality of communications between lawyers and clients and protects the client from compelled disclosure of communications with his/her attorney made in confidence. Emails are privileged if the communication is between a lawyer and client and for the purpose of obtaining legal advice. Levitate does not store the content of any emails sent or received, except for those that are sent from Levitate, and would be unable to provide any emails (besides those sent from Levitate) as part of a discovery request. Similar to cloud email providers and other third-party applications like Anti-virus products that scan your emails, Levitate is not ‘another person in the room’ with ears on your confidential conversations.
What about Ethical Rules?
While rules vary from state to state, the ABA passed changes to the Model Rules of Professional Conduct in 2018, modernizing them for legal practices activities related to marketing, advertising, and solicitation. In short, lawyers are allowed to participate in marketing, but they need to follow legal advertising rules and ethical obligations. The American Bar Association (ABA) Rule 7.2 on Communications Concerning a Lawyer's Services specifies that a lawyer can communicate information about their services through any platform, but there are rules about what they can share. For most states, the rule of thumb is to never say anything that is false, deceptive, or misleading in your email communications. Levitate content is built with these considerations in mind but you should never make guarantees for favorable results, mention specialization unless you have the appropriate certifications, or make unverifiable claims.