Privacy Policy
Last updated: 28/06/2026
This Privacy Policy explains how Velari Protocol Pty Ltd ("CoreID", "we", "us", or "our") collects, uses, stores, and protects information when you access or use the CoreID platform, including the Enterprise Portal and the Public CoreID Registry.
CoreID is designed as governance and verification infrastructure. Privacy, data minimization, and controlled disclosure are foundational to the platform.
Privacy Policy
Last updated: 28/06/2026
This Privacy Policy explains how Velari Protocol Pty Ltd ("CoreID", "we", "us", or "our") collects, uses, stores, and protects information when you access or use the CoreID platform, including the Enterprise Portal and the Public CoreID Registry.
CoreID is designed as governance and verification infrastructure. Privacy, data minimization, and controlled disclosure are foundational to the platform.
1. Scope of This Policy
This Privacy Policy applies to:
- the CoreID Enterprise Portal, used by organizations to manage AI system identity, governance, compliance, and disclosure; and
- the Public CoreID Registry, which displays limited, non-sensitive metadata only where disclosure has been explicitly enabled
This policy does not apply to third-party websites or services that may be linked from CoreID.
In most cases, CoreID acts as a data processor for information submitted by organizations through the Enterprise Portal, and as a data controller for account, billing, and platform administration information.
2. Information We Collect
2.1 Organization and Account Information
When an organization registers for CoreID, we collect information such as:
- organization name, domain, website, and region
- user account details, including name, email address, job title, and contact information
- role and permission assignments within the organization
This information is used to establish and manage organizational access and accountability.
2.2 Model and System Metadata
Within the Enterprise Portal, organizations provide structured metadata associated with CoreIDs, including:
- model or system names and identifiers
- version information
- declared risk tier
- jurisdictions of operation
- system status and descriptive context
This metadata forms part of the organization's private governance and compliance records.
2.3 Governance, Compliance, and Workflow Data
CoreID supports governance and compliance workflows. We collect information generated through these workflows, including:
- submissions, attestations, and reviews
- review outcomes and audit records
- internal governance notes and lifecycle history
This data is private by default and accessible only to authorized organizational users.
2.4 Uploaded Documents and Evidence
Organizations may upload documents and evidence into the platform, including materials linked to governance and compliance records.
Uploaded content is stored securely, associated with the relevant CoreID records, and accessible only according to role-based permissions. Documents and evidence are not publicly visible.
2.5 Organizational Verification Data
Where registry validation is available, CoreID may query publicly accessible corporate registries to confirm organizational registration status and corporate details necessary for verification. We collect and process information necessary to support organizational verification, including:
- verification status classifications (e.g., Attested, Registry Validated, Inherited)
- authority attestation confirmations, including timestamps and associated IP address logs for accountability and security purposes
- uploaded corporate registration or incorporation documentation
- registry validation results where automated cross-referencing is performed
- verification history and status changes
- activity monitoring signals used to detect abnormal or excessive platform behavior
This information is used to establish accountability, protect platform integrity, and enforce organizational verification rules.
Certain verification processes may involve automated systems that analyze registry data or activity patterns to support integrity and compliance monitoring. Such processes assist platform governance and do not independently determine legal rights or obligations without meaningful human review.
Registry validation queries are limited to publicly available corporate registry information and do not involve disclosure of confidential organizational data beyond what is strictly necessary to perform verification.
2.6 Public CoreID Registry Data
Where an organization explicitly enables public disclosure, limited non-sensitive metadata may appear in the Public CoreID Registry, including:
- CoreID reference
- model or system name
- organization name
- version identifier
- declared risk tier
- jurisdiction(s)
- status
No internal governance records, documents, or operational data are exposed in the registry.
2.7 Integrity Hashes and Audit Logs
CoreID uses cryptographic hashing and signed tokens to protect authentication and verification, and maintains audit logs to support traceability and security.
- Hashes are designed to verify integrity and detect changes
- Hashes are non-reversible representations and do not expose underlying content
- Audit logs may record actions such as creation, modification, submission, review, disclosure, and access events
2.8 Usage and Technical Information
We may collect limited technical information necessary to operate and secure the platform, such as:
- IP addresses
- device and browser information
- session identifiers
- timestamps of access
We may also collect and analyze usage patterns and activity frequency (including submission, invitation, and organizational structuring behavior) for the purpose of maintaining platform security, detecting automated misuse, and preventing abuse or security risks.
3. How We Use Information
We use collected information to:
- provide and operate the CoreID platform
- manage organizational accounts and access
- maintain governance, compliance, and lifecycle records
- support review, audit, and disclosure workflows
- verify integrity and detect unauthorized changes
- respond to support requests and inquiries
- maintain platform security and reliability
We do not sell personal data.
We process personal information where necessary to perform our contract with customers, to comply with legal obligations, and where required for legitimate interests related to platform security, integrity, and compliance.
This includes processing necessary to verify organizational identity, detect misuse or abuse, maintain platform integrity, and enforce verification and governance requirements.
For organizations requiring a Data Processing Agreement (DPA), please contact support@coreidregistry.org.
4. Public Registry and Disclosure
All data in CoreID is private by default.
Public disclosure occurs only when an organization explicitly enables it. Disclosure is binary (enabled or disabled) and may be revoked at any time. Revoking disclosure removes the CoreID entry from public view but does not affect internal records.
5. AI-Assisted Features
CoreID may provide optional AI-assisted features, powered by Anthropic's Claude AI, to support governance and compliance workflows, such as analysis, comparison, or summarization of user-provided content.
- AI features are optional and may be enabled or disabled by the organization
- AI processing is limited to the organization's own data and context
- Data processed by AI is not shared across organizations
- Data processed by AI is not used to train shared or general AI models by default
AI features operate to assist users and do not replace human review, accountability, or decision-making.
6. How We Share Information
We may share information only in the following circumstances:
- Service providers: with trusted vendors who process data strictly on our behalf under contractual confidentiality and security obligations. Our current service providers include: Amazon Web Services (AWS) for data storage, authentication, and secure file storage; Vercel for application hosting, content delivery, and cookieless website analytics; Stripe for payment processing; Resend for transactional email delivery; Anthropic for AI-assisted features where enabled by the organization; and Sentry for application error monitoring and diagnostics.
- Legal requirements: where required by law, regulation, or lawful request
- Business transfers: in connection with a merger, acquisition, or asset transfer, subject to confidentiality protections
We do not permit service providers to use CoreID data for their own independent purposes.
7. International Data Transfers
CoreID stores information primarily within Amazon Web Services (AWS) in the European Union (Frankfurt region). Certain providers - including our application host (Vercel), our AI provider (Anthropic), and our error-monitoring provider (Sentry) - may process limited data outside the European Union, including in the United States.
Where required, we implement appropriate safeguards to support international data transfers in accordance with applicable laws.
8. Data Retention
We retain information only for as long as necessary to:
- provide the platform
- maintain governance, integrity, and audit trails
- comply with legal and regulatory obligations
Account deactivation limits access but does not necessarily result in immediate deletion of CoreID records, audit logs, or compliance history, which may need to be retained for integrity and legal purposes.
Verification documentation, attestation records, registry validation logs, and audit history may be retained beyond account deactivation where necessary to preserve integrity, prevent fraud, comply with legal obligations, or support dispute resolution.
9. Security
We implement administrative, technical, and organizational measures designed to protect information, including:
- encryption in transit and at rest
- access controls and role-based permissions
- audit logging and monitoring
- separation between public and private environments
No system is completely secure, but we take reasonable steps to protect data against unauthorized access, loss, or misuse.
10. Your Rights and Choices
Depending on your jurisdiction, you may have rights to:
- access personal information
- request correction of inaccurate data
- request deletion or restriction of processing
- object to certain processing activities
Requests may be submitted to support@coreidregistry.org. We may verify identity before responding.
Some rights may be subject to limitations or exemptions under applicable law.
11. Cookies and Tracking
CoreID uses essential cookies necessary for authentication, session management, and platform security.
We do not use third-party analytics cookies. We use Vercel Web Analytics, a cookieless, privacy-friendly service, to measure aggregate site traffic; it sets no cookies, stores nothing on your device, and collects no personal data. You can opt out at any time using the "Decline analytics" option in our cookie notice.
We use an error-monitoring and diagnostics service (Sentry) to detect and fix technical problems. It may collect technical and diagnostic information. This is used solely to operate and improve the platform, not for advertising.
For more information, please refer to the Cookie Policy.
12. Children
CoreID is not intended for use by children and does not knowingly collect personal information from individuals under the age of 16.
13. Changes to This Policy
We may update this Privacy Policy from time to time. Updates will be posted on this page with a revised "Last updated" date.
14. Contact Us
For privacy-related questions or requests, please contact: