Trust centre
Control posture, source licensing and privacy handling.
This page is maintained by Veritrace Data to answer common security and privacy questions. It describes the current programme, not an independent certification.
Compliance and governance
Programme posture, stated plainly
Veritrace publishes the state of its control programme rather than badges. Where a certification is not yet held, the page says so.
Information security programme aligned to ISO 27001
Controls, access management and incident response are documented against the standard and reviewed on a fixed cycle.
SOC 2 readiness
A readiness assessment governs control design across security, availability and confidentiality ahead of formal examination.
GDPR and Australian Privacy Act compliant processing
Lawful basis is recorded per processing activity, with data subject request handling inside statutory timeframes.
Source licensing documented per jurisdiction
Every feed carries a recorded licence in the coverage registry, and redistribution rights follow that licence.
Data governance
What a procurement team needs to see
Provenance
Records originate from primary planning and building control registers, national and state interfaces, and licensed portal feeds. The source is named on the jurisdiction object.
Licensing
Each feed is ingested under a stated licence: open government, open data, licensed or negotiated. Redistribution rights follow the licence recorded for that jurisdiction.
Retention
Project records are retained for the life of the registry. Contact records are retained while the role remains current and are removed once superseded.
Removal rights
Data subjects may request access, correction or removal of personal data held against a role. Requests are handled inside statutory timeframes and logged.
Global presence
- Gold Coast, AustraliaPrimary entity
- Sydney, Australia
- London, United Kingdom
- Singapore, Singapore