{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "lever",
    "name": "Lever",
    "vendor": "Employ, Inc.",
    "vendorUrl": "https://www.lever.co",
    "kind": "http-api",
    "category": "recruiting",
    "summary": "Applicant tracking and candidate relationship system from Employ Inc. Its Data API reads and writes opportunities, postings, interviews, feedback and requisitions, and a separate Postings API serves published jobs.",
    "url": "https://www.anchorterminal.com/tools/lever",
    "markdownUrl": "https://www.anchorterminal.com/tools/lever.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/lever.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/lever.json",
    "repo": "https://github.com/lever/postings-api",
    "license": "Proprietary service under Lever's terms of service. The postings-api and integrator-resources repositories on GitHub hold documentation and example code",
    "transports": [
      "http"
    ],
    "remoteUrl": "https://api.lever.co/v1",
    "packages": [],
    "auth": "mixed",
    "authNotes": "Access is granted by a paying customer or by Lever's partner team. A Super Admin of a Lever account creates an API key in Settings, sent as the Basic auth username with a blank password. Keys are limited to chosen endpoints, and access to confidential data can be granted only when the key is created. Partner integrations must use OAuth 2.0 (authorisation code grant at https://auth.lever.co/authorize, with a required `audience`). Lever staff create the OAuth app after a partner application and a registration form, first on the sandbox and then for production after a QA call. About 50 scopes follow the pattern `opportunities:read:admin` and `opportunities:write:admin`, with at most 20 per app. Access tokens last 1 hour and refresh tokens 1 year or 90 days idle. A Super Admin authorises an app for the whole organisation and can revoke it in settings. The Postings API reads published jobs without a key and takes applications with a key in the `key` query parameter.",
    "pricing": "paid",
    "pricingNotes": "No public price. lever.co/pricing has a quote form and says pricing scales with team size and hiring needs, with no trial, free tier or self-serve signup found. Lever's partner FAQ says OAuth integrations work for all customers, while API key use needs the Data API feature, requisition endpoints need the TRM Enterprise package or Advanced HR, and the audit events endpoint is an add-on. A sandbox account is free to approved partners only, so an agent can't start without a customer contract or partner approval. Reading a company's published jobs through the Postings API needs no account (checked 2026-10-07).",
    "priceSummary": "Paid",
    "where": "hosted",
    "x402": {
      "level": "no",
      "evidence": "No x402, MPP or L402 in the developer documentation, the Postings API README or the pricing page (checked 2026-10-07).",
      "endpoints": []
    },
    "toolCount": null,
    "popularity": {
      "githubStars": null,
      "npmWeekly": null,
      "pypiWeekly": null,
      "asOf": "2026-10-07"
    },
    "docsUrl": "https://hire.lever.co/developer/documentation",
    "capabilities": [
      "recruiting.candidates",
      "recruiting.jobs",
      "recruiting.applications",
      "recruiting.interviews",
      "recruiting.offer-letters"
    ],
    "tags": [
      "hosted",
      "enterprise",
      "sales-led",
      "oauth",
      "api-key",
      "webhooks",
      "sandbox",
      "status-page",
      "sla",
      "soc2",
      "iso27001",
      "eu-region"
    ],
    "lastRelease": "2026-04-30",
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 53.6,
      "grade": "D",
      "agentReady": false,
      "rank": 541,
      "ranked": true,
      "rankOf": 722,
      "categoryRank": 7,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 65,
        "maintenance": 21,
        "payments": 5,
        "reliability": 73,
        "schema": 55,
        "security": 60,
        "transparency": 75
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 73,
          "points": 14.6,
          "reason": "Graded on the hosted lines for the Data API. Statuspage at status.lever.co with about 40 components, among them Integration API \u0026 Webhooks, Hire and Sandbox for the global and EU data centres (20). From 9 July to 7 October 2026 the page records six incidents, three marked critical. Offer letter sending failed platform-wide on 14 July, mitigated after about 1.5 hours and resolved after 9. A 14-minute outage on 12 August, caused by a support data query, raised API error rates per the postmortem. 500 errors on 21 August had a fix within 17 minutes. An offer document conversion outage on 7 August lasted most of a working day. None shows an hour of the API itself down, so we scored between minor-only and one major (10). 10 requests a second per key with bursts to 20, and 2 application POSTs a second (15). Exponential backoff is advised for 429 and 503, with no Retry-After header documented and no idempotency keys for writes (8). SLA of 99.9 per cent monthly uptime with service credits (10). The v1 API is generally available (10)."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 55,
          "points": 8.94,
          "reason": "No OpenAPI file found. A Postman collection in lever/integrator-resources is the only machine-readable description and its last commit is from February 2025 (5). No llms.txt, www.lever.co/llms.txt returns 404 (0). The reference explains each resource, how candidates, contacts and opportunities relate, and marks every deprecated endpoint with the replacement to call, but gives little guidance on when not to use an endpoint (14). Attribute tables give types and mark parameters required or optional, with few enumerated values or constraints stated in a form a machine can check (10). curl examples and sample responses on nearly every endpoint, nine status codes explained and one sample error body (11). Versioned path /v1, a promise not to rename or remove fields without a version bump, and a dated updates page running from 2021 to 30 April 2026 (15)."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 65,
          "points": 10.56,
          "reason": "`include` trims a response to named fields, `expand` inlines linked objects and `limit` caps a page at 100 (22). Opaque offset tokens with `next` and `hasNext` on every list, and filters by stage, posting, tag, email, contact and created, updated or archived time on opportunities (20). Errors carry a `code` and `message` such as ResourceNotFound, with no per-field validation detail or list of codes documented (12). No idempotency keys. Creating an opportunity with an email address is matched to an existing contact, which limits duplicate people but still creates a second opportunity on retry (5). Reads need no parameters, but most writes require `perform_as` with a user id, PUT on panels deletes missing fields, and there is no official SDK (6)."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 60,
          "points": 10.5,
          "reason": "OAuth 2.0 with around 50 scopes split by resource into read and write, one-hour access tokens and revocation by a Super Admin, plus API keys limited to chosen endpoints (30). The Postings API documents its key in the `key` query parameter for application POSTs (-10). Read-only scopes and a separate `confidential:access:admin` scope allow least privilege. Deletes of notes, files, feedback and requisitions need no confirmation (13). Resumes, notes and application answers are written by outside parties and no prompt-injection guidance was found (3). An audit events endpoint covers user provisioning, authentication and data export as a paid add-on, webhook deliveries have a history view, and `perform_as` attributes each write to a user (10). SOC 2 Type II, ISO/IEC 27001 and a vulnerability disclosure policy at security@employinc.com. No bug bounty and no security.txt (14)."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 5,
          "points": 0.63,
          "reason": "No x402, MPP or L402 (0). Pricing is by quote only (0). No free tier or trial found, and the sandbox goes only to approved partners (0). API keys and OAuth apps need a person, a customer contract or Lever's partner team. We gave 5 because the Postings API returns any customer's published jobs without a key or account (5)."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 21,
          "points": 1.84,
          "reason": "The newest dated API change is 30 April 2026, 160 days before the check (10). No entries in the last 90 days. The four in April 2026 followed a gap since 31 March 2025 (0). Closed service with a dated updates page, a help centre and an integrations support address. The public postings-api repository merged a README change on 23 April 2026 (8). No official SDKs and no Lever-published MCP server in the official registry (0). No packages to assess. The example repository has CodeQL and dependency review workflows and was last changed in February 2025 (3)."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 75,
          "points": 6.56,
          "note": "editorial 63, provenance 87",
          "reason": "Closed service with public terms of service (25 August 2023), an SLA and Developer Sandbox Terms. The terms bar access for benchmarking or competitive purposes (15). A DPA (updated 20 May 2025), a services privacy notice (25 September 2023) and a security page give retention and deletion periods. They disagree on one figure, with deletion starting 30 days after termination in the DPA and 90 days on the security page, both ending by day 45 (20). A deprecated section keeps the 2020 Candidates endpoints documented and working, and Lever promises no field removals without a version bump, but no notice period or removal dates are published (10). Sub-processor list effective 21 September 2025 with purposes and locations, and hosting regions named (18)."
        }
      ],
      "assessment": {
        "date": "2026-10-07",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "`include` trims a response to named fields, `expand` inlines linked objects and `limit` caps a page at 100 (22). Opaque offset tokens with `next` and `hasNext` on every list, and filters by stage, posting, tag, email, contact and created, updated or archived time on opportunities (20). Errors carry a `code` and `message` such as ResourceNotFound, with no per-field validation detail or list of codes documented (12). No idempotency keys. Creating an opportunity with an email address is matched to an existing contact, which limits duplicate people but still creates a second opportunity on retry (5). Reads need no parameters, but most writes require `perform_as` with a user id, PUT on panels deletes missing fields, and there is no official SDK (6).",
          "maintenance": "The newest dated API change is 30 April 2026, 160 days before the check (10). No entries in the last 90 days. The four in April 2026 followed a gap since 31 March 2025 (0). Closed service with a dated updates page, a help centre and an integrations support address. The public postings-api repository merged a README change on 23 April 2026 (8). No official SDKs and no Lever-published MCP server in the official registry (0). No packages to assess. The example repository has CodeQL and dependency review workflows and was last changed in February 2025 (3).",
          "payments": "No x402, MPP or L402 (0). Pricing is by quote only (0). No free tier or trial found, and the sandbox goes only to approved partners (0). API keys and OAuth apps need a person, a customer contract or Lever's partner team. We gave 5 because the Postings API returns any customer's published jobs without a key or account (5).",
          "reliability": "Graded on the hosted lines for the Data API. Statuspage at status.lever.co with about 40 components, among them Integration API \u0026 Webhooks, Hire and Sandbox for the global and EU data centres (20). From 9 July to 7 October 2026 the page records six incidents, three marked critical. Offer letter sending failed platform-wide on 14 July, mitigated after about 1.5 hours and resolved after 9. A 14-minute outage on 12 August, caused by a support data query, raised API error rates per the postmortem. 500 errors on 21 August had a fix within 17 minutes. An offer document conversion outage on 7 August lasted most of a working day. None shows an hour of the API itself down, so we scored between minor-only and one major (10). 10 requests a second per key with bursts to 20, and 2 application POSTs a second (15). Exponential backoff is advised for 429 and 503, with no Retry-After header documented and no idempotency keys for writes (8). SLA of 99.9 per cent monthly uptime with service credits (10). The v1 API is generally available (10).",
          "schema": "No OpenAPI file found. A Postman collection in lever/integrator-resources is the only machine-readable description and its last commit is from February 2025 (5). No llms.txt, www.lever.co/llms.txt returns 404 (0). The reference explains each resource, how candidates, contacts and opportunities relate, and marks every deprecated endpoint with the replacement to call, but gives little guidance on when not to use an endpoint (14). Attribute tables give types and mark parameters required or optional, with few enumerated values or constraints stated in a form a machine can check (10). curl examples and sample responses on nearly every endpoint, nine status codes explained and one sample error body (11). Versioned path /v1, a promise not to rename or remove fields without a version bump, and a dated updates page running from 2021 to 30 April 2026 (15).",
          "security": "OAuth 2.0 with around 50 scopes split by resource into read and write, one-hour access tokens and revocation by a Super Admin, plus API keys limited to chosen endpoints (30). The Postings API documents its key in the `key` query parameter for application POSTs (-10). Read-only scopes and a separate `confidential:access:admin` scope allow least privilege. Deletes of notes, files, feedback and requisitions need no confirmation (13). Resumes, notes and application answers are written by outside parties and no prompt-injection guidance was found (3). An audit events endpoint covers user provisioning, authentication and data export as a paid add-on, webhook deliveries have a history view, and `perform_as` attributes each write to a user (10). SOC 2 Type II, ISO/IEC 27001 and a vulnerability disclosure policy at security@employinc.com. No bug bounty and no security.txt (14).",
          "transparency": "Closed service with public terms of service (25 August 2023), an SLA and Developer Sandbox Terms. The terms bar access for benchmarking or competitive purposes (15). A DPA (updated 20 May 2025), a services privacy notice (25 September 2023) and a security page give retention and deletion periods. They disagree on one figure, with deletion starting 30 days after termination in the DPA and 90 days on the security page, both ending by day 45 (20). A deprecated section keeps the 2020 Candidates endpoints documented and working, and Lever promises no field removals without a version bump, but no notice period or removal dates are published (10). Sub-processor list effective 21 September 2025 with purposes and locations, and hosting regions named (18)."
        },
        "sources": [
          {
            "what": "Data API reference (auth, scopes, rate limits, errors, pagination, webhooks, endpoints)",
            "url": "https://hire.lever.co/developer/documentation",
            "seen": "2026-10-07"
          },
          {
            "what": "OAuth registration and sandbox",
            "url": "https://hire.lever.co/developer/oauth",
            "seen": "2026-10-07"
          },
          {
            "what": "partner integration process and FAQ",
            "url": "https://hire.lever.co/developer/partner",
            "seen": "2026-10-07"
          },
          {
            "what": "API updates page",
            "url": "https://hire.lever.co/developer/updates",
            "seen": "2026-10-07"
          },
          {
            "what": "deprecated Candidates endpoints",
            "url": "https://hire.lever.co/developer/deprecated",
            "seen": "2026-10-07"
          },
          {
            "what": "Postings API README and SECURITY.md",
            "url": "https://github.com/lever/postings-api",
            "seen": "2026-10-07"
          },
          {
            "what": "Postman collection and example OAuth app",
            "url": "https://github.com/lever/integrator-resources",
            "seen": "2026-10-07"
          },
          {
            "what": "status incidents (JSON)",
            "url": "https://status.lever.co/api/v2/incidents.json",
            "seen": "2026-10-07"
          },
          {
            "what": "pricing page",
            "url": "https://www.lever.co/pricing",
            "seen": "2026-10-07"
          },
          {
            "what": "security page",
            "url": "https://www.lever.co/security",
            "seen": "2026-10-07"
          },
          {
            "what": "terms of service",
            "url": "https://www.lever.co/legal/terms-of-service",
            "seen": "2026-10-07"
          },
          {
            "what": "SLA",
            "url": "https://www.employinc.com/lever-sla/",
            "seen": "2026-10-07"
          },
          {
            "what": "DPA",
            "url": "https://www.employinc.com/dpa/",
            "seen": "2026-10-07"
          },
          {
            "what": "sub-processor list",
            "url": "https://www.employinc.com/sub-processors/",
            "seen": "2026-10-07"
          },
          {
            "what": "services privacy notice",
            "url": "https://www.employinc.com/privacy-notice-services/",
            "seen": "2026-10-07"
          },
          {
            "what": "Developer Sandbox Terms",
            "url": "https://www.employinc.com/lever-developer-sandbox-terms/",
            "seen": "2026-10-07"
          },
          {
            "what": "official MCP registry search",
            "url": "https://registry.modelcontextprotocol.io/v0.1/servers?search=lever",
            "seen": "2026-10-07"
          },
          {
            "what": "RDAP for lever.co",
            "url": "https://rdap.registry.co/co/domain/lever.co",
            "seen": "2026-10-07"
          }
        ],
        "openQuestions": [
          "unchecked: the developer FAQ and use-case tabs (https://hire.lever.co/developer/faq and /use-cases), which redirected to a login",
          "unchecked: the help centre article on API key permissions, so the per-endpoint key limits are taken from the Data API reference and its 403 text",
          "Whether 429 responses carry a Retry-After header. The documentation doesn't say and we made no authenticated calls",
          "Whether the Data API feature for API keys is included in every current plan. The partner FAQ says older API key integrations need it, and no plan table is public",
          "Which legal entity contracts today. The 2023 terms name Lever, Inc. and the 2025 DPA names Employ, Inc.",
          "How long partner approval takes and whether Lever accepts agent builders that aren't selling a product integration",
          "Root cause analyses for the 21 and 25 August 2026 incidents weren't on the status page when checked"
        ]
      },
      "negative": 0,
      "verdict": "The Data API covers about 100 operations with read and write OAuth scopes per resource, field selection and a 99.9 per cent uptime commitment. Access depends on a paying customer or partner approval, with no public price, no OpenAPI file and no official SDK. The status page records three critical incidents between 14 July and 21 August 2026.",
      "bestFor": "An agent working inside a company that already runs Lever, for reading the pipeline, adding candidates, moving stages, writing notes and feedback and scheduling externally managed interviews.",
      "strengths": [
        "About 100 documented operations on https://api.lever.co/v1, with writes for opportunities, stages, notes, feedback, interviews, postings and requisitions",
        "OAuth 2.0 authorisation code grant with around 50 scopes split into read and write per resource, and a separate scope for confidential data",
        "Every list endpoint takes `limit` (1 to 100), an opaque `offset` token, `include` for field selection and `expand` for linked objects",
        "Published SLA commits to 99.9 per cent monthly uptime with automatic service credits",
        "Sub-processor list dated 21 September 2025 names each vendor, purpose and location"
      ],
      "weaknesses": [
        "No public price, free tier or self-serve signup. OAuth apps and sandbox accounts are issued by Lever staff after a partner application",
        "No OpenAPI file, llms.txt or official SDK. The reference is one HTML page and a Postman collection last changed in February 2025",
        "Three incidents marked critical on status.lever.co between 14 July and 21 August 2026, one with elevated API error rates for 14 minutes",
        "No idempotency keys, and 429 responses are documented without a Retry-After header",
        "The Postings API takes its key in the URL query string for application submissions",
        "Offer records are read-only, and interviews can be written only on panels marked `externallyManaged`"
      ],
      "agentNotes": [
        "Send `perform_as` with a Lever user id on creates and most updates. Opportunity, note, feedback, panel and interview writes reject requests without it",
        "Use the Opportunities endpoints. The Candidates endpoints were deprecated in 2020 and the old candidate id works as the opportunity id",
        "Stay under 10 requests a second per key and back off exponentially on 429 and 503. Application POSTs are limited to 2 a second",
        "Create interviews on a panel with `externallyManaged` true. Panels made in the Lever app can't be changed through the API",
        "Pass `include` to trim fields and follow `next` while `hasNext` is true. An `offset` must come from a previous response",
        "Send a full object on PUT to panels and interviews. Missing fields are deleted"
      ],
      "metrics": {
        "kind": "remote",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "D",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 53.6
        }
      ],
      "editorialScores": {
        "ergonomics": 65,
        "maintenance": 21,
        "payments": 5,
        "reliability": 73,
        "schema": 55,
        "security": 60,
        "transparency": 63
      },
      "provenanceScore": 87
    },
    "connect": {
      "http": "curl -u \"$LEVER_API_KEY:\" \"https://api.lever.co/v1/opportunities?limit=10\u0026include=name\u0026include=stage\""
    },
    "letme": {
      "capability": "https://letme.dev/recruiting.candidates",
      "tool": "https://letme.dev/lever"
    },
    "notable": [
      "The Data API at https://api.lever.co/v1 documents about 100 operations across opportunities, postings, interviews, panels, feedback, notes, files, requisitions, users and webhooks (https://hire.lever.co/developer/documentation)",
      "API keys are for a customer's own workflows. Partner integrations must use OAuth, and Lever staff create each OAuth app after a registration form and a partner application (https://hire.lever.co/developer/partner)",
      "The Postings API returns a company's published jobs without a key, for example https://api.lever.co/v0/postings/leverdemo?mode=json, and takes applications with an API key in the query string (https://github.com/lever/postings-api)",
      "Rate limit is a token bucket of 10 requests a second per key with bursts to 20, and Lever says the defaults aren't guaranteed (https://hire.lever.co/developer/documentation#rate-limits)",
      "The SLA commits to 99.9 per cent monthly uptime with service credits of 10 times the fees for the downtime (https://www.employinc.com/lever-sla/)",
      "The terms of service prohibit access for benchmarking or competitive purposes (https://www.lever.co/legal/terms-of-service)",
      "The newest entry on the API updates page is dated 30 April 2026, the fourth that month after a gap since 31 March 2025 (https://hire.lever.co/developer/updates)",
      "No Lever-published MCP server was found. The official MCP registry lists only third-party servers that read public job boards (https://registry.modelcontextprotocol.io/v0.1/servers?search=lever)"
    ],
    "area": "business",
    "details": [
      {
        "label": "Surface graded",
        "value": "The Data API v1 at https://api.lever.co/v1 (the Postings API README gives https://api.eu.lever.co/v0/postings/ for EU accounts), plus the Postings API v0 for published jobs. No official MCP server found"
      },
      {
        "label": "Access",
        "value": "API key from Settings, Integrations and API, created by a Super Admin of a paying account, or a partner OAuth app issued by Lever staff. Lever's partner FAQ says older API key integrations need the customer to have the Data API feature"
      },
      {
        "label": "Sandbox",
        "value": "https://api.sandbox.lever.co/v1, given to approved partners under the Developer Sandbox Terms. Email is switched off, only test data is allowed and Lever may delete data without notice"
      },
      {
        "label": "OAuth",
        "value": "Authorisation code grant at https://auth.lever.co/authorize with a required `audience`. Access tokens last 1 hour, refresh tokens 1 year or 90 days idle. At most 20 scopes per app, and a write scope includes the matching read scope"
      },
      {
        "label": "Rate limits",
        "value": "10 requests a second per API key steady, bursts to 20, no per-endpoint limits. Postings API application POSTs 2 a second"
      },
      {
        "label": "Pagination",
        "value": "`limit` 1 to 100 (default 100), opaque `offset` token, `next` and `hasNext` in every list response. Deleted-record and file-action endpoints use keyset pagination with a time window of at most 30 days"
      },
      {
        "label": "Response sizing",
        "value": "`include` returns only the named fields. `expand` inlines linked objects such as applications, stage, owner and followers"
      },
      {
        "label": "Errors",
        "value": "400, 401, 403, 404, 429, 500 and 503 with a JSON body of `code` and `message`, such as ResourceNotFound"
      },
      {
        "label": "Webhooks",
        "value": "applicationCreated, candidateHired, candidateStageChange, candidateArchiveChange, candidateDeleted, interviewCreated, interviewUpdated, interviewDeleted, contactCreated and contactUpdated. HTTPS only, HMAC-SHA256 signature in the body, five retries, delivery history in settings"
      },
      {
        "label": "Write limits",
        "value": "Offer records are read-only. Interviews and panels can be written only when `externallyManaged` is true. Confidential postings can't be modified through the API"
      },
      {
        "label": "Audit",
        "value": "GET /audit_events lists user provisioning, authentication and data export events. It is a paid add-on"
      },
      {
        "label": "SLA",
        "value": "99.9 per cent monthly uptime for all customers, credits of 10 times the fees for the downtime, exhibit last updated 14 April 2022"
      },
      {
        "label": "Certifications",
        "value": "SOC 2 Type II and ISO/IEC 27001 (certificate issued by Schellman) per lever.co/security. Reports on request to customers. No bug bounty"
      },
      {
        "label": "Hosting",
        "value": "AWS us-west-2 and eu-central-1, with separate global and EU data centres"
      },
      {
        "label": "Sub-processors",
        "value": "List effective 21 September 2025 with purpose and location, among them AWS, Google Cloud, Mailgun, Snowflake, Textkernel, Twilio Segment and Zendesk. AI Companions add Anthropic, OpenAI, AssemblyAI, IBM watsonx and Recall"
      }
    ],
    "provenance": {
      "legalEntity": "Employ, Inc.",
      "domain": "lever.co",
      "domainRegistered": "2010-07-20",
      "endpointOnVendorDomain": true,
      "terms": "https://www.lever.co/legal/terms-of-service",
      "privacy": "https://www.employinc.com/privacy-notice-services/",
      "statusPage": "https://status.lever.co",
      "changelog": "https://hire.lever.co/developer/updates",
      "securityTxt": "none",
      "checked": "2026-10-07",
      "notes": [
        "The terms of service (last updated 25 August 2023) and the Developer Sandbox Terms (21 September 2020) name Lever, Inc. The DPA (last updated 20 May 2025) and the sub-processor list name Employ, Inc., 20 North Meridian Street, Suite 300, Indianapolis, IN 46204, and page footers read Employ Inc.",
        "API endpoints answer at api.lever.co, with auth.lever.co for OAuth. An unauthenticated GET to https://api.lever.co/v1/opportunities returned 401 with `server: lever-data-api` on 7 October 2026.",
        "www.lever.co/.well-known/security.txt and www.employinc.com/.well-known/security.txt both return 404. A vulnerability disclosure policy with security@employinc.com is in SECURITY.md in Lever's GitHub repositories and says there is no bug bounty.",
        "RDAP at rdap.registry.co gives a registration date of 2010-07-20 for lever.co and NameCheap, Inc. as registrar.",
        "The SLA and DPA are published on employinc.com (https://www.employinc.com/lever-sla/ and https://www.employinc.com/dpa/)."
      ],
      "score": 87,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "Employ, Inc.",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "lever.co, registered 2010-07-20 (16 years)",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": "api.lever.co",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Terms of service",
          "value": "read, states 7 of the 7 things a reader expects, and has 1 clause that costs points",
          "points": 8,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Privacy policy",
          "value": "read, states 7 of the 8 things a reader expects",
          "points": 9.3,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Status page",
          "value": "status.lever.co",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Changelog",
          "value": "published",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "security.txt",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        }
      ],
      "policies": [
        {
          "kind": "terms",
          "url": "https://www.lever.co/legal/terms-of-service",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2023-08-25",
          "words": 5622,
          "points": 8,
          "max": 10,
          "expected": [
            {
              "key": "terms.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Last updated August 25, 2023",
              "says": "Last updated 2023-08-25"
            },
            {
              "key": "terms.law",
              "label": "Names the governing law or courts",
              "found": true,
              "quote": "This Agreement is governed by and construed in accordance with the internal laws of the State of California without giving effect to any choice or conflict of law.",
              "says": "The law of the State of California"
            },
            {
              "key": "terms.liability",
              "label": "States a limit on its liability",
              "found": true,
              "quote": "…liability arising out of a party's indemnity obligations, gross negligence, fraud or willful misconduct, in no event will either party or their respective directors, officers, agents, or employees, be liable to the other party for any reason, whether in contract or in tort, for any claims, suits, liability or damages…",
              "says": "Capped at the fees paid in the 12 months before the claim"
            },
            {
              "key": "terms.termination",
              "label": "Says how the agreement or account can be ended",
              "found": true,
              "quote": "Notwithstanding anything to the contrary in this Agreement, Lever may impose limitations on bandwidth usage, and/or temporarily suspend Customer's and any user authorized by Customer to access to any portion or all of the Services if Lever reasonably determines that (i) there is a threat to or attack on any of the Ser…"
            },
            {
              "key": "terms.changes",
              "label": "Says how changes to the terms are announced",
              "found": true,
              "quote": "Lever reserves the right to periodically modify these Terms of Service upon written notice to Customer, and such modification will become effective in the next service term.",
              "says": "Says it gives notice of a change"
            },
            {
              "key": "terms.use",
              "label": "Lists what users may not do",
              "found": true,
              "quote": "Customer will not, and will not permit any third party to: reverse engineer, decompile, disassemble or otherwise attempt to discover the source code, object code or underlying structure, ideas or algorithms of the Services, Documentation or data related to the Services (provided that reverse engineering is prohibited…"
            },
            {
              "key": "terms.sla",
              "label": "Refers to a service level or uptime commitment",
              "found": true,
              "quote": "Lever will provide the Services in accordance with the service level agreement exhibit identified at www.lever.co/agreements/sla."
            }
          ],
          "toKnow": [
            {
              "key": "terms.benchmark",
              "label": "Restricts benchmarking or competitive use",
              "found": true,
              "quote": "In addition, the software and services may not be accessed for the exclusive purpose of monitoring performance, or functionality, or for any other benchmarking or competitive purposes.",
              "costsPoints": true
            },
            {
              "key": "terms.arbitration",
              "label": "Requires arbitration or waives class actions",
              "found": true,
              "quote": "If the parties do not reach such solution within a period of sixty (60) days, then, upon notice by either party to the other, all disputes shall be finally settled by binding arbitration taking place in San Francisco, California."
            },
            {
              "key": "old",
              "label": "Has not been updated for three years or more",
              "found": true,
              "quote": "Last updated August 25, 2023"
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "The agreement renews automatically for further one-year periods unless either party asks in writing to end it at least 30 days before the term ends.",
              "quote": "will automatically renew for additional one year periods (together with each “Renewal Service Term,” the “Term”) subject to section 3.2 of the Agreement, unless either party requests termination in writing at least thirty (30) days prior to the end of the then-current Term."
            },
            {
              "date": "2026-10-08",
              "text": "Renewal fees may rise by up to the change in the US Consumer Price Index over the latest twelve months plus five per cent.",
              "quote": "price increase to be made effective upon the effective date of the Renewal Service Term not to exceed the change in the U.S. Department of Labor's Bureau of Labor Statistics Consumer Price Index – All Urban Consumers (“CPI”) during the most recent twelve (12) month period plus five percent (5%)."
            },
            {
              "date": "2026-10-08",
              "text": "After the term expires, customer data is no longer accessible and is deleted under Lever's data retention policy.",
              "quote": "After the expiration of the Term, Customer Data will no longer be accessible and will be promptly deleted in accordance with Lever's data retention policy."
            }
          ]
        },
        {
          "kind": "privacy",
          "url": "https://www.employinc.com/privacy-notice-services/",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2023-09-25",
          "words": 3281,
          "points": 9.3,
          "max": 10,
          "expected": [
            {
              "key": "privacy.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Effective as of September 25, 2023",
              "says": "Last updated 2023-09-25"
            },
            {
              "key": "privacy.collected",
              "label": "Says what personal data is collected",
              "found": true,
              "quote": "Employ may combine the foregoing types of data with data Employ already has or data provided by third parties, including third parties from whom Employ has purchased Personal Data."
            },
            {
              "key": "privacy.retention",
              "label": "Says how long data is kept",
              "found": true,
              "quote": "Employ may retain your Personal Data for a period of time consistent with the original purpose of collection (see the “Our Purposes for Processing Personal Data” section above)."
            },
            {
              "key": "privacy.processors",
              "label": "Says who else receives the data",
              "found": true,
              "quote": "With Employ service providers, who provide services such as IT and system administration and hosting, credit card processing, research and analytics, marketing, customer support and data enrichment for the purposes and pursuant to the legal bases described above;"
            },
            {
              "key": "privacy.sale",
              "label": "Says whether personal data is sold or shared for advertising",
              "found": false
            },
            {
              "key": "privacy.rights",
              "label": "Says what rights people have over their data",
              "found": true,
              "quote": "Where Employ processes your Personal Data for direct marketing purposes or share it with third parties for their own direct marketing purposes, you can exercise your right to object at any time to such processing without having to provide any specific reason for such objection;"
            },
            {
              "key": "privacy.contact",
              "label": "Gives a privacy contact",
              "found": true,
              "quote": "…has provided Employ with Personal Data without their consent, he or she should contact Employ at privacy@employinc.com ever become aware that a child under 18 has provided Employ with Personal Data, Employ will take steps to delete such information from Employ’s files.",
              "says": "privacy@employinc.com"
            },
            {
              "key": "privacy.transfers",
              "label": "Says where data is transferred or stored",
              "found": true,
              "quote": "…adequate level of protection, for instance by entering into the appropriate agreements and, if required, standard contractual clauses for the transfer of data as approved by the European Commission (Art.",
              "says": "Relies on standard contractual clauses"
            }
          ],
          "toKnow": [
            {
              "key": "old",
              "label": "Has not been updated for three years or more",
              "found": true,
              "quote": "Effective as of September 25, 2023"
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "Employ may use personal data collected through the services to build models and to personalise content for customers.",
              "quote": "Employ may use Personal Data to analyze trends and usage, assess capacity requirements, identify Customer opportunities and conduct surveys, build models to allow Employ to better serve Customers and personalize content and features for Customers"
            },
            {
              "date": "2026-10-08",
              "text": "Employ may combine the data it collects with personal data bought from third parties.",
              "quote": "Employ may combine the foregoing types of data with data Employ already has or data provided by third parties, including third parties from whom Employ has purchased Personal Data."
            }
          ]
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/lever.json",
    "live": {
      "slug": "lever",
      "probe": {
        "target": "https://api.lever.co/v1",
        "method": "get",
        "lastAt": "2026-10-08T19:52:54.348354916Z",
        "lastOk": true,
        "lastStatus": 401,
        "lastMs": 608,
        "lastNote": "asks for credentials",
        "authRequired": true,
        "uptime24h": 100,
        "uptime30d": 100,
        "p50ms24h": 604,
        "p95ms24h": 679,
        "samples24h": 50,
        "samples30d": 50,
        "days": [
          {
            "date": "2026-10-08",
            "probes": 50,
            "ok": 50
          }
        ]
      },
      "vendorStatus": {
        "page": "https://status.lever.co",
        "indicator": "none",
        "summary": "All Systems Operational",
        "checkedAt": "2026-10-08T19:50:48.019121858Z"
      },
      "githubStars": 200,
      "securityTxt": {
        "url": "https://lever.co/.well-known/security.txt",
        "state": "none",
        "checkedAt": "2026-10-08T15:38:47.673975745Z"
      },
      "pages": [
        {
          "url": "https://hire.lever.co/developer/updates",
          "kind": "changelog",
          "status": 200,
          "checkedAt": "2026-10-08T18:20:52.275745136Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "721e91eb9091"
        },
        {
          "url": "https://www.employinc.com/privacy-notice-services/",
          "kind": "privacy",
          "status": 200,
          "checkedAt": "2026-10-08T18:27:36.644757071Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "8a719a587b02"
        },
        {
          "url": "https://www.lever.co/legal/terms-of-service",
          "kind": "terms",
          "status": 200,
          "checkedAt": "2026-10-08T18:28:40.54053301Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "1e3f81b481ff"
        }
      ],
      "updatedAt": "2026-10-08T19:52:54.348354916Z"
    }
  }
}
