Security & Trust Centre

Clear controls. Clear responsibility.

Security depends on technology, configuration and daily operations. This page states what applies to the production LevelSync service — as facts you can question, not badges. We avoid claims we cannot support.

Security controls

  • Identity and authentication

    Two-factor authentication, password policies, lockout thresholds and session controls. Directory integration via Active Directory / Microsoft Entra ID.

  • Authorisation and sharing

    Per-user and per-group permissions. External sharing through controlled links with passwords, expiry dates and download history.

  • Encryption

    Data is encrypted in transit (TLS) and at rest. Further technical details about encryption and key arrangements are available from POISE as part of the security review process.

  • Logging and monitoring

    Audit logs record logins, file actions and link activity with timestamps and user details, and can be exported for compliance reporting.

  • File recovery and continuity

    Version history on stored files with administrator-driven restore, subject to the configured retention policy — the recovery path for both everyday mistakes and ransomware incidents.

  • Infrastructure and operations

    POISE AB operates the customer-facing service and infrastructure in Stockholm, applies platform updates, and provides support during Swedish business hours.

Service boundary

Know where the service runs

We do not hide the platform or the processing chain. LevelSync uses platform technology from RushFiles, while POISE operates the customer-facing service and infrastructure. The table below is the current documented state; rows marked being documented are being verified and will be published here.

Legal operatorPOISE AB, Brunnsgatan 9, 172 68 Sundbyberg, Sweden — VAT SE556773092301
Primary service locationData center in Stockholm, Sweden
Platform technologyRushFiles A/S (Denmark)
Customer file storagePOISE-operated infrastructure, Stockholm
BackupsBeing documented
Monitoring & email infrastructureEU-based, POISE-controlled — details being documented
SupportPOISE AB, Sweden — Swedish business hours
Microsoft 365 co-editingOptional. When used, the document is processed by Microsoft's online service for the editing session.
Mobile push notificationsDelivered via Apple and Google notification services, as for all mobile apps

Last reviewed: 21 August 2026. Rows change only through a reviewed update.

Suppliers

Subprocessors and platform suppliers

RushFiles A/SPlatform software supplier (Denmark, EU)
Data center providerStockholm, Sweden — name being documented
LettermintTransactional email delivery for website form notifications (EU)

The complete supplier list with roles and agreements is maintained by POISE and published here as verification completes.

Sign-in safety

Legitimate LevelSync domains

To protect you from phishing, these are the only domains we operate for this service:

levelsync.comThis website — product information and contact
filesync.seThe official sign-in for the LevelSync service

We will never ask for your password by e-mail or phone. If you receive a suspicious message that appears to come from LevelSync or POISE, forward it to us via the address below.

Contact

Report a security issue

Found a vulnerability on this website or in the service? Email us directly at info@poise.se — no form, no registration. A machine-readable disclosure contact is published at /.well-known/security.txt (RFC 9116). Security reports are read with priority during Swedish business hours.

We appreciate responsible disclosure and will acknowledge legitimate reports. Please do not test against production systems containing customer data.

Questions about your requirements?

Data location, integrations, onboarding — ask us directly.