The standards every person working for or with Averro is held to. Published in full, because a code nobody outside the company can read is a memo, not a commitment.
This Code sets out how Advit Pty Ltd (ACN 682 221 638), trading as Averro Technologies (Averro), does business. It applies to every director, employee, contractor, subcontractor and work-experience participant of Averro, and to any supplier or delivery partner acting on our behalf.
It is not a summary of the law. Complying with the law is the floor, not the standard. Where this Code sets a higher expectation than the law requires, the higher expectation applies. Where a client’s own policy is stricter than this Code, we work to the client’s policy.
Averro holds privileged administrative access to other organisations’ systems, advises those organisations on what to buy, and builds automations that act on their behalf. Almost everything that could go seriously wrong at a firm like ours traces back to one of those three facts. That is why clauses 3, 4, 5 and 9 are the longest ones here.
The rest of this document is the detail. If you remember nothing else, remember these.
Client information is confidential by default, whether or not it is marked, whether or not a non-disclosure agreement is in place, and whether or not the engagement has ended.
Administrative access is the most dangerous thing we hold. It is granted for a purpose and it is used for that purpose only.
Having the technical ability to read a mailbox, a file share, a database or a message history is not permission to read it. Looking at client data because you can, rather than because the work requires it, is a serious breach of this Code and may also be a criminal offence.
Clients pay us for judgement. Judgement is worthless if it is for sale.
A conflict is not misconduct. Concealing one is.
You must declare, in writing, any circumstance where your personal interest could reasonably be seen to influence your work. That includes a financial interest in a supplier or competitor, a close personal relationship with a client contact or a decision-maker in a procurement, outside employment or consulting in our industry, a directorship, and any gift or hospitality above a nominal value.
Declare it as soon as you become aware of it, not at the next review. We will then decide together how to manage it — which may mean recusing yourself, adding a second reviewer, disclosing it to the client, or declining the work.
We may work for organisations that compete with each other. Where we do, we tell both, we keep the delivery teams and the information separate, and we will decline an engagement where those separations cannot be made real.
We do not offer, give, request or accept a bribe, a secret commission, or any improper benefit intended to influence a decision, in any country, under any circumstances, including where it is described as customary. This includes facilitation payments.
Modest, occasional business hospitality is acceptable — a working lunch, a vendor briefing, a conference ticket. It is not acceptable if it is frequent, extravagant, in cash or a cash equivalent, offered around a live tender or procurement decision, or something you would not want disclosed to the client or published.
Anything of more than nominal value must be declared. If you are unsure whether something is nominal, it is not; declare it.
Bribery of a Commonwealth or foreign public official is a criminal offence under the Criminal Code Act 1995 (Cth), carrying penalties for individuals as well as companies. Averro will not indemnify anyone for conduct of that kind.
Since 8 March 2024 a company can also be liable under s 70.5A of the Criminal Code for failing to prevent foreign bribery by an associate — an employee, contractor, agent or subsidiary — even where the company did not know. The only defence is proving the company had adequate procedures in place.
This Code, the declarations required by clause 6, the written recommendation required by clause 5 and the records required by clause 15 are the beginning of those procedures, not the whole of them. They are maintained deliberately and are reviewed against the Attorney-General’s Guidance on adequate procedures to prevent the commission of foreign bribery.
We compete on the quality of our work.
We build systems that act on our clients’ behalf. That has to come with rules, and these are ours.
Where a client’s use case is subject to a specific regime — privacy, anti-discrimination, consumer credit, health records — we say so and recommend they take advice. We are technology professionals, not their lawyers.
We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles, and in accordance with our Privacy Policy.
When we handle personal information on a client’s behalf we do so only on their instructions and only for the purpose of the engagement. We collect the minimum we need, we do not keep it longer than the engagement requires, and we do not use it for our own purposes.
If we become aware of unauthorised access to, or disclosure or loss of, personal information — ours or a client’s — we escalate immediately under clause 16 and assist the client to meet their obligations under the Notifiable Data Breaches scheme. We do not wait to be certain before raising it.
Since 10 June 2025 an individual can sue directly for a serious invasion of privacy under Schedule 2 to the Privacy Act 1988 (Cth). That action does not depend on the Australian Privacy Principles and it does not depend on the company being caught by the Privacy Act at all.
For a firm holding administrative access to other people’s systems this matters more than it does for most: reading a mailbox out of curiosity is not only a breach of clause 4 of this Code, it is now something the person whose mailbox it was can bring proceedings over.
Everyone working with Averro is entitled to a workplace free from discrimination, harassment, sexual harassment, bullying and victimisation. That applies on client sites, at industry events, in chat channels and online, not only in an office.
The law here is no longer about responding to complaints. Since December 2023, s 47C of the Sex Discrimination Act 1984 (Cth) has placed a positive duty on every employer — of any size, including sole traders — to take reasonable and proportionate measures to eliminate sexual harassment, sex discrimination, hostile workplace environments and victimisation as far as possible. It is enforceable by the Australian Human Rights Commission.
Victoria has had the same obligation for longer: s 15 of the Equal Opportunity Act 2010 (Vic) requires organisations to take positive action to eliminate discrimination, sexual harassment and victimisation, whether or not anyone has complained.
Waiting to be told is not compliance. Neither is a policy nobody has read.
Those seven lines are the AHRC’s standards for meeting the positive duty, written as what we do rather than as a summary of a guideline.
We comply with occupational health and safety law in every jurisdiction we operate in, and with the site rules of any client premises we attend.
Victoria is not part of the harmonised WHS scheme. The obligations here are the Occupational Health and Safety Act 2004 (Vic) and the OHS Regulations 2017, regulated by WorkSafe Victoria — not the model Work Health and Safety Act that applies in most other States. A policy copied from a NSW or Queensland template cites the wrong statute.
The Occupational Health and Safety (Psychological Health) Regulations 2025 (Vic) commenced on 1 December 2025. They require Victorian employers to identify psychosocial hazards and eliminate or reduce the resulting risks so far as is reasonably practicable — hazards including bullying, sexual harassment, aggression or violence, high job demands, low job control, poor support, and exposure to traumatic content.
Several of those are ordinary features of this work if it is run badly. We name the ones that apply to us:
These are assessed and controlled like any other hazard: identified, recorded, given a control, and reviewed. Someone who has worked an incident overnight is stood down the following day; that is a control, not a courtesy.
Since 26 August 2025, employees of small business employers have had a workplace right under s 333M of the Fair Work Act 2009 (Cth) to refuse to monitor, read or respond to contact outside their working hours unless that refusal is unreasonable. Larger employers have had it since 26 August 2024.
A 24/7 service does not override that right. What makes an out-of-hours roster lawful is that the person is rostered on call and paid for it, and knows in advance that they are. So: if you are not on the roster, you are not expected to answer, and nobody may treat you badly for not answering. If you are on the roster, you are paid for it.
Contacting someone off-roster because it is easier than checking who is on is a breach of this Code, whatever the hour.
We advertise work in government, defence, utilities and energy, telecommunications, banking and insurance. Each of those carries obligations that do not apply to ordinary commercial work, and they attach to us as a supplier as well as to the client.
The Security of Critical Infrastructure Act 2018 (Cth) imposes reporting, register and risk-management-programme obligations on responsible entities for critical infrastructure assets, and expressly reaches the supply chain hazard — which is us.
If a client asks us to do something their own regulatory obligations do not permit, we say so and decline. "The client asked for it" has never been a defence for anybody.
We do not tolerate forced labour, child labour, debt bondage, human trafficking or deceptive recruitment in our operations or in our supply chain.
Technology supply chains carry real exposure — hardware manufacturing, electronics assembly, mineral extraction, offshore data-labelling and outsourced support. We take that seriously rather than assuming a services business is unaffected.
Averro is not currently a reporting entity under the Modern Slavery Act 2018 (Cth). The obligations in this clause are ones we take on regardless.
Averro assets — devices, accounts, licences, tooling and intellectual property — are provided for work. Incidental personal use is fine; use that creates legal, security or reputational risk is not.
Client-owned assets stay client-owned. Every tenancy, domain, subscription and cloud account we set up is registered in the client’s name with their billing, and we hand over cleanly when an engagement ends, including documentation and administrative access.
If you see something that breaches this Code, the law, or your own sense of what is right, raise it. That includes something you are unsure about, and something you may have done yourself.
Nobody who raises a concern in good faith will be dismissed, demoted, disciplined, excluded from work or treated detrimentally for having raised it — and that protection applies even if the concern turns out to be mistaken.
Retaliating against someone for speaking up is itself a serious breach of this Code.
Certain disclosures about a company’s affairs attract statutory protection under Part 9.4AAA of the Corporations Act 2001 (Cth), including protection of your identity and immunity from civil, criminal and administrative liability for making the disclosure. Those protections apply by law and nothing in this Code limits them. Victimising a discloser, or revealing their identity without consent, is itself an offence.
A public company or large proprietary company must maintain a compliant whistleblower policy under s 1317AI. Averro maintains one whether or not it currently meets that threshold, because the point of the protection is that it exists before somebody needs it.
You can also report directly to a regulator — the Office of the Australian Information Commissioner, the Australian Securities and Investments Commission, the Fair Work Ombudsman, the Australian Cyber Security Centre or a State work health and safety regulator — and you do not need our permission to do so.
A breach is dealt with proportionately, on the facts, after the person concerned has had a fair opportunity to respond.
Outcomes range from a conversation and additional training through to a formal warning, removal from an engagement, termination of employment or contract, and referral to a regulator or to the police. Deliberate misuse of client access, concealment of an incident, and retaliation against someone who spoke up are treated as the most serious categories.
Where a supplier or delivery partner breaches this Code, we will require remediation and may terminate the relationship.
This Code is reviewed at least annually and whenever our services, obligations or risk profile change materially. The date at the top of this page records the last change.
A code only works if people can ask about it without it being a formal event. If you are unsure whether something is allowed, ask first — asking is always cheaper than explaining.
This Code sets standards of conduct. It is not a contract of employment, it does not create contractual entitlements, and it does not replace the specific terms of any engagement agreement, employment contract or supplier agreement.
Averro Technologies is a registered business name of Advit Pty Ltd (ACN 682 221 638, ABN 37 682 221 638), an Australian private company whose principal place of business is in Victoria. This Code binds that company.
It therefore names Victorian instruments where they differ from the rest of the country — the Occupational Health and Safety Act 2004 rather than a harmonised WHS Act, the Equal Opportunity Act 2010, the Wage Theft Act 2020. Where we place people in another State or Territory, the local equivalents apply to that work as well; the Commonwealth obligations in this Code apply everywhere regardless.