Security, Data Protection & AI Governance Overview

Aleverum™ is a Digital Product Passport and trusted product intelligence platform designed to support evidence backed product information, supplier data, sustainability information, certification records, review workflows and trusted digital records across product lifecycles.

Security, privacy, data integrity and controlled platform operations are central to how Aleverum™ is developed and operated.

This page provides a public overview of Aleverum™’s approach. Detailed internal security procedures, technical architecture, credentials, incident response materials, risk registers and customer specific contractual controls are maintained separately.

1. Scope

This overview applies to the Aleverum™ public website, platform, client services and related systems used to support:

  • Product records and identifiers
  • Supplier and manufacturer information
  • Supporting evidence
  • Sustainability information
  • Digital Product Passport workflows
  • Compliance documentation
  • Review and assurance workflows
  • Platform accounts and communications

Personal information is handled in accordance with the Aleverum™ Privacy Policy.

Platform access and customer use are also governed by the applicable Platform Terms and Conditions, Order Form, statement of work or other written agreement.

2. Information Managed Through Aleverum™

Aleverum™ may manage or support the following information types:

  • Product records, identifiers and lifecycle information
  • Supplier, manufacturer and facility information
  • Sustainability claims and supporting evidence
  • Certificates, test reports and compliance documents
  • Review notes, approval records and workflow events
  • Digital Product Passport information and related metadata
  • User accounts, permissions, authentication and activity records
  • Customer, supplier, partner and support communications

Customers remain responsible for the accuracy, completeness, legality and evidentiary basis of information they provide, approve, disclose or publish through Aleverum™.

3. Platform Security

Aleverum™ applies a risk based approach intended to protect the confidentiality, integrity and availability of information and platform functions.

Depending on the service configuration and agreed scope, security and governance measures may include:

  • Role based access controls and managed user permissions
  • Authentication and account management workflows
  • Administrative access restricted to authorised personnel
  • Activity records for material platform and workflow events
  • Evidence and document governance
  • Separation of customer, supplier and reviewer responsibilities
  • Controlled access to sensitive product, supplier and compliance records
  • Encryption and secure transmission measures where appropriate
  • Logging, monitoring and vulnerability management processes
  • Backup, recovery and continuity arrangements appropriate to the service
  • Service provider assessment
  • Review and testing before material production changes

No internet connected system can be guaranteed to be completely secure or continuously available.

Aleverum Global Pty Ltd does not warrant that unauthorised access, disruption, data loss or security incidents can never occur.

4. Infrastructure and Hosting

Aleverum™ uses Laravel Cloud infrastructure to support managed application hosting and platform operations.

Laravel describes Laravel Cloud as a managed infrastructure platform that can provide compute, databases, key value storage, object storage, deployment and scaling capabilities.

Laravel states that Laravel Cloud has achieved SOC 2 Type 2 attestation for Security, Confidentiality and Availability.

This is infrastructure level assurance relating to Laravel Cloud and its control environment. It does not mean that Aleverum Global Pty Ltd, the Aleverum™ application or Aleverum™ operations are independently SOC 2 attested or ISO/IEC 27001 certified.

Specific hosting regions, data residency arrangements and service configurations may depend on customer requirements and the applicable written agreement. Aleverum™ does not claim that all information is hosted or processed only in Australia.

5. Software Delivery and Change Control

Aleverum™ uses controlled development and deployment practices intended to support traceability, consistency and review.

Depending on the applicable workflow, these practices may include:

  • Version controlled source code
  • Structured development workflows
  • Controlled deployment processes
  • Release review
  • Testing before production changes
  • Deployment records
  • Restricted development and administrative access
  • Rollback and recovery processes

Development and deployment controls may evolve as the platform, infrastructure and service requirements change.

6. Privacy and Data Protection

Much of the information managed through Aleverum™ concerns products, materials, suppliers, evidence and compliance records rather than individuals.

Personal information may nevertheless be included in:

  • User accounts
  • Business contact records
  • Supplier information
  • Supporting evidence
  • Communications
  • Activity records
  • Uploaded documents
  • Review and approval records

Where personal information is processed, Aleverum™ seeks to apply privacy aware practices including:

  • Purpose based collection
  • Data minimisation where appropriate
  • Controlled access
  • Secure storage and transmission
  • Transparency
  • Appropriate retention
  • Support for access and correction requests where required

Aleverum Global Pty Ltd does not sell customer product information, supplier evidence or confidential compliance materials.

Personal information handling is governed by the Aleverum™ Privacy Policy and applicable customer agreements.

Material service providers that may process Customer Data or personal information are identified in the Aleverum™ Subprocessor List.

7. Digital Product Passport and Evidence Governance

Aleverum™ is built around the principle that product information should be structured, evidence backed and traceable.

Depending on the service configuration, the platform may support:

  • Product level evidence records
  • Supplier submitted documents
  • Certification records
  • Sustainability and compliance claims
  • Document association
  • Review status
  • Approval workflows
  • Version information
  • Workflow activity records
  • Controlled Digital Product Passport outputs

Aleverum™ provides technology and workflow support.

Unless expressly agreed in writing, Aleverum Global Pty Ltd does not:

  • Independently certify products
  • Provide legal or regulatory approval
  • Act as a market surveillance authority
  • Act as a customs authority
  • Act as a certification body
  • Act as a conformity assessment body
  • Guarantee that customer supplied information establishes compliance

Independent assurance, certification or conformity assessment remains the responsibility of the relevant authorised verifier, auditor, certification body or competent authority.

8. EU Digital Product Passport Registry

The EU Digital Product Passport Registry is distinct from the complete Digital Product Passport information source or repository.

Aleverum™ may support customers in preparing identifiers, metadata, evidence structures and technical workflows relevant to Digital Product Passport implementation.

Aleverum™ does not currently represent that it is connected to, enrolled in, accepted by, certified by or approved by the EU Digital Product Passport Registry.

Aleverum™ also does not represent that customer information has been accepted, registered, certified or approved by:

  • The European Commission
  • An EU market surveillance authority
  • A customs authority
  • A certification body
  • A conformity assessment body

Registry preparation, technical submission or Digital Product Passport publication must not be treated as proof of legal compliance.

9. Responsible AI Governance

Aleverum™ may use artificial intelligence to assist authorised review and workflow activities.

AI supports review. Humans govern decisions.

AI assisted activities may include:

  • Document classification
  • Product data extraction
  • Claim to evidence matching
  • Missing evidence detection
  • Inconsistency detection
  • Expiry monitoring
  • Standards mapping
  • Evidence quality review
  • Drafting and summarisation
  • Workflow assistance

AI assisted outputs are not a substitute for:

  • Human review
  • Professional advice
  • Legal or regulatory interpretation
  • Independent verification
  • Audit
  • Certification
  • Conformity assessment
  • Decisions made by a competent authority

Authorised users remain responsible for reviewing, approving and publishing product information and claims.

Where external AI providers are used, data handling depends on the approved feature, provider terms, account configuration and applicable customer agreement.

Provider specific information may be described in platform documentation, the Aleverum™ Subprocessor List or an applicable Order Form.

No zero retention or no training guarantee should be inferred unless it is expressly stated in an applicable written agreement.

10. Customer Responsibilities

Customers and authorised users are responsible for:

  • Providing accurate, complete and lawful information
  • Holding the necessary rights and permissions to upload, process and disclose information
  • Reviewing product, environmental, sustainability and compliance claims before publication or external use
  • Managing user roles and access permissions appropriately
  • Protecting account credentials
  • Promptly removing access when it is no longer required
  • Notifying Aleverum™ of suspected misuse, security incidents or unauthorised access
  • Obtaining appropriate legal, regulatory, technical, audit, certification or conformity assessment advice

11. Incident Management

Where a suspected security or data incident occurs, Aleverum Global Pty Ltd assesses the circumstances and takes response measures appropriate to the nature and scope of the incident.

Response activities may include:

  • Initial assessment
  • Containment
  • Investigation
  • Remediation
  • Recovery
  • Contractual communication
  • Assessment of legal notification requirements

Where an incident involves personal information, Customer Data or confidential information, Aleverum Global Pty Ltd will assess its responsibilities under applicable law and contract.

Where the Australian Notifiable Data Breaches scheme applies, covered organisations may be required to notify affected individuals and the Office of the Australian Information Commissioner if an eligible data breach is likely to result in serious harm.

12. Compliance Alignment and Limitations

Aleverum™ may use recognised frameworks and requirements to inform its security, privacy, artificial intelligence and governance approach.

These may include:

  • Australian Privacy Principles, where applicable
  • Australian Cyber Security Centre Essential Eight guidance
  • NIST Cybersecurity Framework
  • ISO/IEC 27001 information security management principles
  • ISO/IEC 42001 artificial intelligence management principles
  • Applicable Digital Product Passport requirements
  • Relevant GS1 identification and data sharing principles

References to these frameworks do not mean Aleverum Global Pty Ltd or Aleverum™ has been independently certified, audited, approved or legally assessed against them unless expressly stated.

Aleverum Global Pty Ltd does not claim that Aleverum™ is:

  • Independently certified under ISO/IEC 27001
  • Independently certified under ISO/IEC 42001
  • SOC 2 attested
  • Independently certified under ISO 9001
  • Certified or formally approved under GDPR or CCPA
  • Certified under the ACSC Essential Eight
  • Certified or approved under any Digital Product Passport regulatory regime

GDPR and CCPA are legal frameworks, and the ACSC Essential Eight is security guidance. References to them do not represent certification or formal approval.

13. Responsible Disclosure and Contacts

Suspected security vulnerabilities should be reported in accordance with the Aleverum™ Responsible Disclosure Policy.

Please provide sufficient information to allow Aleverum Global Pty Ltd to assess the matter. Do not publicly disclose a suspected vulnerability before Aleverum Global Pty Ltd has had a reasonable opportunity to investigate and respond.

Security reports: legal@aleverum.com
Privacy enquiries: privacy@aleverum.com
General enquiries: Contact Aleverum™


Effective date: 6 August 2026
Last updated: 6 August 2026

Scroll to Top