Trust Centre
Aleverum™ is building trusted digital infrastructure for Digital Product Passports, product intelligence, supplier evidence, sustainability data, verification workflows and enterprise product governance.
Trust depends on more than making information available. It requires appropriate security, evidence integrity, transparent governance, controlled access, accountable use of artificial intelligence, standards aligned data structures and clear responsibilities between Aleverum™, its customers, suppliers and independent assurance providers.
This Trust Centre provides public information about Aleverum’s security, privacy, data-protection, responsible AI and Digital Product Passport governance approach. Detailed internal controls and customer-specific contractual documents are maintained separately.
Trust resources
| Resource | Public description | Link |
|---|---|---|
| Security, Data Protection and AI Governance | How Aleverum™ approaches platform security, data protection, software delivery, AI use and assurance boundaries. | View Security Overview |
| Privacy Policy | How Aleverum Global Pty Ltd collects, uses, stores, discloses and protects personal information. | Read Privacy Policy |
| Platform Terms and Conditions | Terms governing customer and authorised user access to the Aleverum™ platform. | Read Platform Terms |
| Website Terms of Use | Terms governing use of the Aleverum™ public website and its content. | Read Terms of Use |
| Cookie and Tracking Notice | Information about cookies, analytics and similar technologies used on the Aleverum™ website. | Read Cookie Notice |
| Subprocessor List | Third party service providers that may process customer information or personal information for Aleverum Global Pty Ltd. | View Subprocessors |
| Data Retention and Deletion Overview | Public principles for retention, deletion, backups and Digital Product Passport record persistence. | View Retention Overview |
| Responsible Disclosure Policy | How to report a suspected security vulnerability responsibly. | Report a Security Issue |
The Aleverum Trust Principles
Governance
Product and supplier information should be managed through controlled roles, approvals, accountability, audit trails and documented lifecycle processes.
Integrity
Claims and product records should be supported by appropriate evidence, provenance, version history and traceable changes.
Transparency
Users should be able to understand the source, status, purpose and verification state of information without implying assurance that has not been formally provided.
Standards Alignment and Data Exchange
Digital Product Passport information should use recognised identifiers, standards aligned structures and supported machine readable formats where applicable.
Assurance support
Technology should support independent review, verification and certification workflows while preserving a clear distinction between platform functionality and formal assurance decisions.
Compliance and standards alignment
Aleverum is developing its platform and governance approach with reference to recognised frameworks and requirements that may be relevant to its services and customers, including:
- Australian Privacy Principles under the Privacy Act 1988 (Cth), where applicable;
- Australian Cyber Security Centre Essential Eight maturity guidance;
- NIST Cybersecurity Framework;
- ISO/IEC 27001 information security management principles;
- ISO/IEC 42001 artificial intelligence management principles;
- GS1 identification and data-sharing standards, where applicable;
- Regulation (EU) 2024/1781 establishing the Ecodesign for Sustainable Products Regulation framework and Digital Product Passports;
- Product-specific delegated and implementing requirements as they are adopted and become applicable.
References to alignment, readiness or recognised frameworks do not mean that Aleverum has been independently certified, audited, approved or legally assessed against those frameworks unless expressly stated.
Infrastructure assurance statement
Aleverum uses Laravel Cloud infrastructure. Laravel states that Laravel Cloud has achieved SOC 2 Type 2 attestation for the Security, Confidentiality and Availability Trust Services Categories. That attestation applies to Laravel Cloud’s infrastructure and control environment; it does not constitute SOC 2 attestation or certification of Aleverum’s application, operations or organisation.
Contact
Security matters: legal@aleverum.com
Privacy matters: privacy@aleverum.com
General enquiries: Aleverum™ contact page
Effective date: August 6, 2026 | Last updated: August 6, 2026