Security · Data protection · Architecture

Trust is not a footnote here. It is the architecture.

Levve processes site, consumption and business data. That is why the system is built from the ground up so that auditors, banks and data protection officers can trace every decision.

Principle 1 · Traceability

Deterministic core calculation. The AI does not invent numbers.

Climate risk is calculated in the CLIMADA engine: physical damage functions from IPCC AR6 and JRC, without LLM inference. The same portfolio produces the same result on every run.

Reproducible

Every figure of the core calculation can be reproduced exactly with identical inputs. That is the precondition for any audit, whether by accountants, banks or supervisors.

Documented sources

Emission factors, scenario paths and damage functions carry their sources: IPCC AR6, JRC, NGFS Phase V, UBA, DEFRA, IEA. Every statement is traceable to its origin.

Human approval

Before every calculation step, the system asks for the user’s approval. The AI guides the intake and explains results. It does not make decisions.

TCFD ESRS E1 GHG Protocol PCAF SBTi IFRS S2 EU Taxonomy NGFS

EU AI Act classification: limited risk (Art. 50).

Principle 2 · Data sovereignty

EU-sovereign stack. No US cloud service in the processing path.

Every component that touches your data operates under European jurisdiction. For regulated customers this is a hard selection criterion that US providers structurally cannot meet because of the CLOUD Act.

Cloud infrastructure

Scaleway SAS

France / EU

Language models

Mistral AI SAS

France / EU

Vector database

Qdrant

EU operations

E-mail, domain, website hosting

Strato AG

Germany

Data processing agreements under Art. 28 GDPR are in place with all processors. For managing our marketing contacts we additionally use Brevo (Sendinblue GmbH, Berlin, for Brevo SAS, Paris); it holds only contact details from our climate self-check, no customer data from the platform. All four providers are based in the EU. Competent supervisory authority: LDI North Rhine-Westphalia.

Principle 3 · Data minimisation

Data minimisation in the product, not just in the brochure.

The platform holds site, consumption and business data. How that data is handled is part of the software, not part of a statement of intent.

Tenant-separated data: every data intake lives in its own tenant of the platform. Access across tenant boundaries is ruled out and treated as a critical vulnerability, not as a convenience feature.
Only what enters the calculation: we collect the sites, consumption figures and business data that feed the inventory or the risk model. No employee or customer data, no collecting data just in case.
Documents stay inside the tenant: energy bills and invoices are read for data capture and stored in the tenant, not passed on to third parties. Every processor in the path is covered by an Art. 28 GDPR agreement.
Export and deletion on request: input data and analysis results can be exported, and on request we delete a tenant’s data in full. The annual licence keeps the data only as long as you want to keep updating it.
Data sovereignty with the company: in the platform, the company decides who sees results. Sharing with third parties, such as an institution, requires its explicit consent.
For this website in addition: no cookies, no tracking, nothing loaded from third-party servers. Report vulnerabilities to contact@levve.eu; we acknowledge receipt promptly. Read the full privacy policy →
FAQ

Frequently asked questions on security

Does the AI end up inventing numbers after all?

No, and that is an architecture decision, not a promise. The risk calculation runs deterministically in the CLIMADA engine, without LLM inference, using physical damage functions from IPCC AR6 and JRC. The AI guides the data intake and explains results; every figure of the core calculation is reproducible.

Why is avoiding US cloud services more than symbolism?

The US CLOUD Act obliges US providers to hand over data even when it is stored in Europe. For banks, development finance institutions and data-sensitive industrial companies, that is a hard selection criterion. The Levve stack (Scaleway, Mistral AI, Qdrant, Strato) sits entirely outside that jurisdiction.

How is Levve classified under the EU AI Act?

As a limited-risk system under Art. 50 EU AI Act, with the corresponding transparency obligations. The deterministic core calculation supports this classification: credit-relevant figures are produced without generative AI.

Does this website set cookies or trackers?

No. This website sets no cookies, loads nothing from third-party servers and uses no analytics or marketing tools. Even the font is served from our own server.

Your data protection or IT team has questions?

We answer security questionnaires, disclose the architecture and document the chain of data processing agreements. Talk to us directly.