AttestLayer

Careers

Build the record-only evidence rail.

AttestLayer is a small, focused team. We are interested in operators, engineers, and partner-facing reviewers who care about evidence integrity, verifier ergonomics, and clear boundaries.

Remote-friendlySmall teamPartner-driven

Job posts here describe scope only. Compensation and benefits are discussed with candidates directly.

What we look for

Engineering

Backends, evidence pipelines, signing, JWKS, and verifier ergonomics.

Partner reviewers

Operators who can review packet submissions, write blocker reports, and keep partner workflows moving.

Technical writing

Reviewer-facing documentation, FES-1.0, and partner-facing playbooks.

Founding customer success

Working with founding customers and partners on packet rollout, qualification, and renewal.

How to apply

Email careers@attestlayer.com with a short note describing what you have built or operated and how it relates to evidence packaging, verification, or partner delivery.

What we do not promise

  • does not promise specific equity, compensation, or title outcomes outside a written offer
  • does not guarantee timing of role openings
  • does not replace standard reference, background, or work-eligibility checks

The AttestLayer trust model

AttestLayer’s trust model is intentionally narrow. It records what was submitted, what was accepted into scope, what was issued, and how the issued kit can be checked.

The model uses

  • SHA-256 artifact hashing
  • manifest-based evidence inventory
  • canonical receipt hashing
  • Ed25519 receipt signatures
  • JWKS public-key discovery
  • offline verification
  • fail-closed verification behavior

What it proves

  • files match the manifest
  • manifest matches the receipt
  • receipt key ID matches a public key
  • receipt signature verifies
  • the kit has not been modified since issuance

What it does not prove

  • company compliance status
  • company security status
  • controls are operating effectively
  • a buyer, auditor, insurer, bank, regulator, or PSP has accepted the packet
  • the evidence content is legally sufficient

Integrity and issuance evidence only. Not audit, certification, or compliance guarantee.