We Run Our Compliance on Our Own Platform¶
Case studies are usually about customers. This one is about us, and that's why we can publish it without asking anyone's permission: Sustalium's own compliance runs on Sustalium. Our public Trust Hex is live at the same address our customers use, holding the same kind of assets we sell. Seven of them, from GDPR to the EU AI Act to our accessibility statement.
What's on our Trust Hex¶
The stack looks like this: our GDPR compliance record and data processing agreement, our NIS2 alignment, our EU AI Act declaration, our WCAG 2.1 AA accessibility statement, and the policies that support them. Same platform, same page structure, same hashcode verification we sell to everyone else.
You can look at it right now — the live Trust Hex is public, and it's the same URL we send to banks, to partners, to anyone who asks how a compliance platform handles its own compliance.
What building it taught us¶
Three things, in order of how much they surprised us:
The hard part wasn't the content. We already had policies and records scattered across internal docs. Structuring them took days, not months, because the frameworks were pre-structured and the data entry was the work, not the formatting.
Updates were the real test. Since we published, our policies have changed, our AI Act posture has been revised, and one certificate renewed. Each change was an edit behind the same URL — no re-sending, no "which version is current" emails, no broken links in old proposals. Living documents stopped being a slogan and became the thing that made the pages worth having.
Buyers notice before you tell them. We've had partners quote a line from our Trust Hex in a meeting without us mentioning it. That's the moment the whole trust-center idea stops being theory: the evidence works while you sleep, and the conversation starts further along than it otherwise would.
Why we're telling you¶
Because "trust us" is not a compliance argument, and this is the strongest evidence we have: we publish our own compliance with the product we sell, at the same price, with the same constraints. When we tell a customer that a compliance page should live at a permanent URL and update in place, we mean it — our own pages do exactly that, and you can check them.
We've written about what a trust center is and how to build one. This post is the proof it works.
How Sustalium Helps You Do the Same¶
- The same structure we use — company-level pages under one Trust Hex, each with a permanent URL and hashcode verification.
- Living documents — policy changes and certificate renewals are edits behind the same addresses.
- A public example to copy — our own Trust Hex shows exactly what a published compliance stack looks like.
See the Product in Production. It's Us.
Browse our live Trust Hex, then build yours with the same structure. Start with a free draft: no card needed, publish the verifiable version when you are ready.
[View Our Live Trust Hex →](https://app.sustalium.com/company/sustalium){ .md-button .md-button--primary }
Frequently Asked Questions¶
Is your Trust Hex really public?
Yes — app.sustalium.com/company/sustalium is a live public page, the same URL we send to partners and lenders.
Do you pay the same price as customers?
Same platform, same document model as everyone else. We use the product we sell, without a special path.
What changed most since you published?
The update discipline. Every policy change is now an edit behind a permanent URL, which removed the version-chasing emails entirely.
Related Articles¶
- What Is a Compliance Trust Center? — the concept behind the Hex
- How to Build a Compliance Trust Center — the step-by-step version
- Mad Fibers: Digital Product Passport Case Study — a customer example on the product side
Last updated: September 2, 2026
Global Digital Trust & Compliance
Sustalium is the digital-first platform for managing complex business certificates and sustainability declarations across global supply chains.
- Digital Product Passport (DPP)
- Carbon & Water Footprint
- Circularity & Reuse (ISO 14021)
- De-Forestation Free
- FSMA 204 (FDA Traceability)
- REACH & RoHS Compliance
- PFAS-Free & VOC Declarations
- Prop 65 & TSCA Title VI
- ISO 26000 Responsibility
- Modern Slavery Statements
- UFLPA Forced Labor Traceability
- Ethical Labor Declarations
- Swiss Made & Origin Claims
- GDPR & AI Ethics (EU AI Act)
- CE Marking & UKCA Conformity
- Bill S-211 (Canada) Reporting
Have questions about a specific standard?
Contact our compliance team at compliance@sustalium.com