Legal · Effective 2026-06-01 · v1.0 · Not for public indexing
Technical and Organizational Security Measures
Version 1.0 — Effective Date: June 1, 2026
Document Classification: Confidential
This Technical and Organizational Security Measures document ("TOMs") describes the security controls implemented by Level Up Technology LLC d/b/a Level Up Labs ("Level Up Labs") to protect personal data Processed in connection with the Factimonious platform. It is incorporated by reference into the Factimonious Data Processing Agreement and may be updated from time to time.
1. Infrastructure and Cloud Hosting
Cloud Provider: Amazon Web Services (AWS)
AWS Region(s): United States
AWS independently maintains the following certifications, which underpin the physical and infrastructure-layer controls for the Factimonious platform:
SOC 1 Type II, SOC 2 Type II, SOC 3; ISO 27001, ISO 27017 (cloud security), ISO 27018 (cloud privacy); PCI DSS Level 1 Service Provider; FedRAMP Authorized (where applicable).
AWS compliance reports and certifications are publicly available at aws.amazon.com/compliance/programs/. Level Up Labs's contractual relationship with AWS is governed by the AWS Customer Agreement and AWS Data Processing Addendum.
Level Up Labs own certifications: None currently held. Level Up Labs may pursue independent certifications in the future and will update this document accordingly.
2. Access Control and Identity Management
2.1 Authentication
Level Up Labs requires unique credentials for all personnel accessing systems that Process personal data. Multi-factor authentication (MFA) is required for personnel and contractor access to production environments and cloud infrastructure used to process or store Personal Data. Level Up Labs' key Sub-Processors — Amazon Web Services (infrastructure) and Stripe, Inc. (payment processing) — each maintain multi-factor authentication and other access controls on their respective platforms. Level Up Labs evaluates and matures its own authentication controls, including broader adoption of MFA across all internal systems, commensurate with risk as the Service scales, consistent with the security measures described in the Data Processing Agreement.
2.2 Authorization and Least Privilege
Access model: Role-based access control (RBAC) with the principle of least privilege. Access to production systems Processing personal data is limited to authorized personnel.
2.3 Offboarding
Access for departing personnel is revoked as part of Level Up Labs' standard offboarding process.
3. Encryption
3.1 Data in Transit
Protocol: TLS 1.2 or higher is enforced for all data in transit; TLS 1.0 and 1.1 are disabled.
3.2 Data at Rest
Standard: AES-256 encryption for all data at rest.
Database encryption: AWS RDS storage volumes are encrypted at rest.
Key management: Encryption keys are managed via AWS Key Management Service (KMS).
Backup encryption: Database backups and snapshots are encrypted consistent with the source database (AES-256). Backups are not retained longer than the retention period specified in the Data Processing Agreement.
4. Network Security
Level Up Labs' AWS environment employs network segmentation and access controls, including isolation between environments and restricted inbound and outbound access, designed to limit exposure of systems Processing personal data. Level Up Labs reviews and matures its network security controls as the Service scales.
5. Vulnerability and Patch Management
Level Up Labs performs periodic vulnerability assessments commensurate with risk, including periodic vulnerability assessments and a patch management process commensurate with risk, consistent with the security measures described in the Data Processing Agreement.
6. Logging, Monitoring, and Alerting
Level Up Labs maintains logging and monitoring capabilities within its AWS environment to support the detection of, and response to, potential security events. These capabilities are reviewed and matured as the Service scales.
7. Incident Response and Business Continuity
7.1 Incident Response
Personal Data Breach notification SLA: Customer notified without undue delay after Level Up Labs becomes aware of a confirmed Personal Data Breach. Level Up Labs does not commit to a fixed notification deadline; timing depends on the nature of the Breach and the information available at the time.
Incident Response Plan: Level Up Labs maintains an internal incident response process for security incidents affecting Personal Data. The process covers: (a) identification and internal reporting of a suspected incident; (b) initial assessment of scope, severity, and whether Personal Data is affected; (c) containment and remediation measures appropriate to the incident; (d) notification to affected Customers without undue delay, consistent with Section 8 of the Data Processing Agreement; and (e) a post-incident review to identify any necessary improvements to security measures. This process is reviewed periodically and will be formalized in greater detail as the Service and Level Up Labs' organization scale.
IR Team / Escalation Path
Responsibility for managing security incidents currently rests with the CTO and anyone added to the IR Team, who are responsible for triaging reported incidents, determining scope and severity, coordinating containment and remediation, and ensuring Customer notification obligations under the Data Processing Agreement are met.
7.2 Business Continuity and Disaster Recovery
Backup and recovery: Level Up Labs performs nightly snapshots of production data. As Level Up Labs is currently in beta, restore testing has not yet been conducted; Level Up Labs will conduct a restore test prior to General Availability and at least annually thereafter.
8. Personnel Security and Training
Confidentiality agreements: All personnel and contractors with access to Personal Data are subject to written confidentiality obligations, consistent with Section 4 of the Data Processing Agreement.
Security awareness: Level Up Labs provides data protection and security awareness training to personnel with access to personal data on a periodic basis commensurate with risk, consistent with the security measures described in the Data Processing Agreement. -
9. Secure Development Lifecycle (SDLC)
Level Up Labs is developing secure software development practices, including separation between production and non-production environments and pre-deployment review processes, appropriate to the current stage of the Service.
10. Data Minimization and Retention
Data minimization principle: Only personal data necessary for the provision of the Service is collected and processed.
Data deletion: Data is deleted per customer request or account termination as set forth in the DPA
Anonymization process: Level Up Labs employs a two-path data architecture, referred to consistently across our Privacy Policy, DPA, and AI & Machine Learning Data Use Policy as Path 1 and Path 2. Under Path 1, Customer Data used to provide and display the Service to the originating Customer (including Session Results) is retained and processed on a per-Customer basis; this data is NOT anonymized and is treated as personal data, governed by the Privacy Policy and DPA. Under Path 2, before any data is used for AI/ML training, testing, or cross-Customer analysis, it passes through a separate, one-way anonymization process: direct identifiers (including author names, email addresses, usernames, and IP addresses) and any free-text content that could contain identifying information (including commit messages, code comments, and file contents) are removed and are not retained in the resulting data set. In their place, Level Up Labs extracts derived, non-identifying signals — such as commit frequency, code churn, file and module change patterns, and review turnaround time — and aggregates these signals across Customers and time periods sufficient to prevent attribution to any individual. No key, mapping table, or other means by which the anonymized data set could be re-associated with an identified or identifiable individual is generated or retained by Level Up Labs as part of this process. Level Up Labs periodically reviews its anonymization methodology against evolving regulatory guidance.
Factimonious — Technical and Organizational Security Measures | Level Up Technology LLC d/b/a Level Up Labs | Confidential
Contact: factimoniousprivacy@factimonious.ai