Trust & Compliance
Trust Centre
Aleverum™ provides governed infrastructure for product, asset, supply-chain and Digital Product Passport information.
Trust depends on more than making information available. It requires appropriate security, evidence integrity, controlled access, accountable use of artificial intelligence, standards-aware data structures, transparent responsibilities and reliable information governance.
This Trust Centre provides public information about Aleverum™ security, privacy, data protection, responsible AI, information governance and Digital Product Passport governance. Detailed internal controls and customer-specific contractual documents are maintained separately.
Trust Resources
| Resource | Public description | Link |
|---|---|---|
| Security, Data Protection and AI Governance | How Aleverum™ approaches platform security, data protection, software delivery, AI use and assurance boundaries. | View Security Overview |
| Privacy Policy | How Aleverum Global Pty Ltd collects, uses, stores, discloses and protects personal information. | Read Privacy Policy |
| Platform Terms and Conditions | Terms governing customer and authorised user access to the Aleverum™ platform. | Read Platform Terms |
| Website Terms of Use | Terms governing use of the Aleverum™ public website and its content. | Read Terms of Use |
| Cookie and Tracking Notice | Information about cookies, analytics and similar technologies used on the Aleverum™ website. | Read Cookie Notice |
| Subprocessor List | Third party service providers that may process customer information or personal information for Aleverum Global Pty Ltd. | View Subprocessors |
| Data Retention and Deletion Overview | Public principles for retention, deletion, backups, product, asset, and Digital Product Passport record persistence. | View Retention Overview |
| Responsible Disclosure Policy | How to report a suspected security vulnerability responsibly. | Report a Security Issue |
The Aleverum™ Trust Principles
Governance
Product, asset and supplier information should be managed through controlled roles, approvals, accountability, audit trails and documented lifecycle processes.
Integrity
Claims and governed records should be supported by appropriate evidence, provenance, version history and traceable changes.
Transparency
Users should be able to understand the source, status, purpose and verification state of information without implying assurance that has not been formally provided.
Standards Alignment and Data Exchange
Product, asset and Digital Product Passport information should support recognised identifiers, standards-aware structures and machine-readable exchange where applicable.
Assurance Support
Technology should support independent review, verification and certification workflows while preserving a clear distinction between platform functionality and formal assurance decisions.
Jurisdiction and Controlled Disclosure
Product, supplier and supporting evidence information may be subject to different access, disclosure, contractual and regulatory requirements across markets and jurisdictions.
Aleverum™ supports controlled information governance, permissions and disclosure workflows while customers remain responsible for determining the legal requirements applicable to their information, products and markets.
Compliance and standards alignment
Aleverum™ develops its platform and governance approach with reference to recognised requirements, regulations, standards and frameworks that may be relevant to its services and customers, including:
- Australian Privacy Principles under the Privacy Act 1988 (Cth), where applicable
- Regulation (EU) 2016/679 (GDPR), where Aleverum™ processes personal data subject to EU data-protection law
- Regulation (EU) 2024/1781 (ESPR) and Digital Product Passport requirements
- Commission Implementing Regulation (EU) 2026/1778 concerning the EU Digital Product Passport Registry
- Regulation (EU) 2023/1542 concerning batteries and waste batteries, where applicable
- Regulation (EU) 2023/2854 (Data Act), where applicable to data-processing-service switching, export and portability
- Regulation (EU) 2024/1689 (AI Act), according to the actual role and use case
- GS1 identifiers, GS1 Digital Link and EPCIS/CBV where applicable to supported workflows
- ISO/IEC 27001, ISO/IEC 42001, NIST Cybersecurity Framework and Australian Essential Eight as reference frameworks where applicable
References to alignment, readiness or recognised frameworks do not mean that Aleverum™ has been independently certified, audited, approved or legally assessed against those frameworks unless expressly stated.
Infrastructure assurance statement
Aleverum™ uses Laravel Cloud infrastructure.
Laravel states that Laravel Cloud has achieved SOC 2 Type 2 attestation for the Security, Confidentiality and Availability Trust Services Categories.
That attestation applies to Laravel Cloud’s infrastructure and control environment. It does not constitute SOC 2 attestation or certification of Aleverum™ application, operations or organisation.
Contact
Security matters: legal@aleverum.com
Privacy matters: privacy@aleverum.com
General enquiries: Aleverum™ contact page
Effective date: September 11, 2026 | Last updated: September 11, 2026