Trust Centre

Aleverum™ is building trusted digital infrastructure for Digital Product Passports, product intelligence, supplier evidence, sustainability data, verification workflows and enterprise product governance.

Trust depends on more than making information available. It requires appropriate security, evidence integrity, transparent governance, controlled access, accountable use of artificial intelligence, standards aligned data structures and clear responsibilities between Aleverum™, its customers, suppliers and independent assurance providers.

This Trust Centre provides public information about Aleverum’s security, privacy, data-protection, responsible AI and Digital Product Passport governance approach. Detailed internal controls and customer-specific contractual documents are maintained separately.

Trust resources

Resource Public description Link
Security, Data Protection and AI Governance How Aleverum™ approaches platform security, data protection, software delivery, AI use and assurance boundaries. View Security Overview
Privacy Policy How Aleverum Global Pty Ltd collects, uses, stores, discloses and protects personal information. Read Privacy Policy
Platform Terms and Conditions Terms governing customer and authorised user access to the Aleverum™ platform. Read Platform Terms
Website Terms of Use Terms governing use of the Aleverum™ public website and its content. Read Terms of Use
Cookie and Tracking Notice Information about cookies, analytics and similar technologies used on the Aleverum™ website. Read Cookie Notice
Subprocessor List Third party service providers that may process customer information or personal information for Aleverum Global Pty Ltd. View Subprocessors
Data Retention and Deletion Overview Public principles for retention, deletion, backups and Digital Product Passport record persistence. View Retention Overview
Responsible Disclosure Policy How to report a suspected security vulnerability responsibly. Report a Security Issue

The Aleverum Trust Principles

Governance

Product and supplier information should be managed through controlled roles, approvals, accountability, audit trails and documented lifecycle processes.

Integrity

Claims and product records should be supported by appropriate evidence, provenance, version history and traceable changes.

Transparency

Users should be able to understand the source, status, purpose and verification state of information without implying assurance that has not been formally provided.

Standards Alignment and Data Exchange

Digital Product Passport information should use recognised identifiers, standards aligned structures and supported machine readable formats where applicable.

Assurance support

Technology should support independent review, verification and certification workflows while preserving a clear distinction between platform functionality and formal assurance decisions.

Compliance and standards alignment

Aleverum is developing its platform and governance approach with reference to recognised frameworks and requirements that may be relevant to its services and customers, including:

  • Australian Privacy Principles under the Privacy Act 1988 (Cth), where applicable;
  • Australian Cyber Security Centre Essential Eight maturity guidance;
  • NIST Cybersecurity Framework;
  • ISO/IEC 27001 information security management principles;
  • ISO/IEC 42001 artificial intelligence management principles;
  • GS1 identification and data-sharing standards, where applicable;
  • Regulation (EU) 2024/1781 establishing the Ecodesign for Sustainable Products Regulation framework and Digital Product Passports;
  • Product-specific delegated and implementing requirements as they are adopted and become applicable.

References to alignment, readiness or recognised frameworks do not mean that Aleverum has been independently certified, audited, approved or legally assessed against those frameworks unless expressly stated.

Infrastructure assurance statement

Aleverum uses Laravel Cloud infrastructure. Laravel states that Laravel Cloud has achieved SOC 2 Type 2 attestation for the Security, Confidentiality and Availability Trust Services Categories. That attestation applies to Laravel Cloud’s infrastructure and control environment; it does not constitute SOC 2 attestation or certification of Aleverum’s application, operations or organisation.

Contact

Security matters: legal@aleverum.com

Privacy matters: privacy@aleverum.com

General enquiries: Aleverum™ contact page

Effective date: August 6, 2026 | Last updated: August 6, 2026

Scroll to Top