Levy Fleets
Talk to Levy
Levy Core On-PremIndependent assurance

Independent Assurance Review

Independent cross-model assurance covering architecture, release controls, installer confidentiality, certification, and documentation completeness.

Production readyLocally deployable · Third-party installable · Source-confidential delivery

The Levy Core On-Prem documentation and delivery model completed independent cross-model review covering the product architecture, engineering contract, release package, third-party installation procedure, clean-room certification protocol, and end-to-end traceability.

The review evaluated whether a qualified third party could install the complete application on customer-owned infrastructure without access to Levy's repositories or original server source, while preserving data residency, operational safety, financial integrity, evidence integrity, and customer control.

Review scope

The independent review covered these public contracts:

Assurance areas

Product completeness

The review traced the rider, operator, rental, vehicle, pricing, zone, wallet, payment, messaging, identity, IoT, GPS, storage, scheduled-job, reporting, backup, recovery, and support capabilities from architecture through packaged artifacts, installer actions, verification evidence, and final acceptance.

Local operation and data residency

The review confirmed that the production profile removes mandatory hosted Supabase, Vercel, Stripe, Twilio, Levy CRM, cloud monitoring, and Levy-operated runtime dependencies. Customer data, telemetry, logs, metrics, traces, objects, evidence, and backups stay within the signed customer boundary. Optional support AI remains separately isolated and controlled by an explicit egress policy.

Source-confidential installation

The review examined the separation between customer custodians, the installation controller, and the third-party installer. The final contract gives the installer a signed client and bounded controller identity without Kubernetes, registry, database, object-store, secret, node, shell, image-export, raw-log, or generic workload access.

It also verifies source-exclusion scans, minimal runtime images, immutable digest-pinned artifact custody, signed target policy, schema-bound requests, allowlisted controller verbs, typed redacted receipts, and exhaustive negative tests.

Authentication and authorization

The review validated the complete request envelope, immutable controller-created case identifiers, customer and environment binding, nonce and idempotency controls, approval references, detached signatures, request expiry, protocol compatibility, rate limits, concurrency rules, access revocation, and cross-environment denial behavior.

Release and supply-chain integrity

The review covered package signing, canonicalization, trust anchors, key transition, revocation, entitlement, SBOM, provenance, vulnerability receipts, license notices, compatibility matrices, offline encrypted media, private-registry import, custody evidence, and deterministic package validation.

Installation safety

The ordered installation path was reviewed from customer readiness and trusted-tool bootstrap through artifact custody, infrastructure preflight, configuration approval, recovery-point creation, deployment, provider and IoT conformance, backup/restore, security and residency testing, golden journeys, controlled rollout, test-data disposition, and operational handoff.

Money and mobility invariants

The review verified that payment and wallet operations are idempotent and reconcilable and that retries, timeouts, duplicate webhooks, captures, voids, refunds, settlement, and provider outages have deterministic behavior. It also verified that dependency or entitlement failure cannot prevent an active rider from ending a ride or the platform from completing required lock and reconciliation actions.

Recovery and operational ownership

The review covered clean install, N-1 upgrade where applicable, rollback, forward recovery, isolated restore, disaster recovery, certificate and key rotation, capacity monitoring, provider outages, IoT failover, support bundles, temporary support access, uninstall, data disposition, and final revocation of installer access.

Independent installability

The certification protocol requires two consecutive clean-room installations by independent teams using the same package and access a real third party receives. One run exercises online customer-custodian delivery and the other exercises offline encrypted media. Undocumented assistance, missing artifacts, unsafe ambiguity, or privileged access invalidates the run.

Incorporated review outcomes

The final documentation incorporates every accepted blocker, high-priority, medium-priority, and smaller-gap finding from the independent review. The incorporated controls include:

  • independently provisioned and verified installer tooling;
  • customer-owned trust anchors and signed bootstrap evidence;
  • immutable controller-created installation case IDs;
  • full signed request-envelope coverage rather than partial-field signatures;
  • explicit controller bootstrap, upgrade, rollback, and stored-version lifecycle;
  • exact release, API, schema, platform, cryptographic-profile, and machine-contract binding;
  • certification receipts with scope vectors for greenfield, offline, restore, rollback, adversarial denial, and handoff;
  • package-class separation between lab certification candidates and production customer handoffs;
  • clear classification of local CLI operations versus controller API operations;
  • bounded evidence-writing endpoints and fixture-disposition approvals;
  • complete Kubernetes denial and controller API negative-test matrices;
  • independent offline-custody and revocation validation;
  • verified access, media, cache, and workspace closure at handoff.

Assurance conclusion

The reviewed documentation forms one consistent production contract. Product capabilities map to owned components; components map to signed package artifacts; package artifacts map to installer phases; installer phases map to machine-generated evidence; and evidence maps to independent certification and customer acceptance.

The resulting handoff is complete, locally operable, source-confidential for the installer role, independently certifiable, and suitable for deployment by a qualified third party on customer-controlled infrastructure.

Part of the complete Levy Core On-Prem deployment and certification suite.Return to suite index →