Skip to content
AttestLayer

AttestLayer Policy

Cookies Policy

This policy applies to attestlayer.com and the public informational or account-free discovery surfaces at api.attestlayer.com, verify.attestlayer.com, and registry.attestlayer.com. Those surfaces do not load optional analytics. Buy publishes its consent-specific Cookie Notice; Partners and Program publish their necessary-only browser-storage boundary in their local Privacy Notice; authenticated Console storage is governed by the Console policy set.

attestlayer.com is the corporate and trust site. Direct-buyer, partner, Console, Verify, Registry, and API tasks use their dedicated domains.
Updated 27 August 2026 Canonical root-domain policy

What cookies and similar technologies are used

Strictly necessary. A covered surface may use essential request, security, or abuse-prevention state needed to serve and protect that surface. It is not used for advertising or cross-site profiling.

No optional analytics. The covered surfaces do not use third-party product analytics, advertising cookies, or tracking pixels, and AttestLayer does not sell personal data collected through them.

How to control cookies

You can control or clear browser storage through your browser settings. Blocking strictly necessary storage may affect a protected function. The covered surfaces do not load optional analytics cookies, so their effective setting is necessary-only.

More information

See the Privacy Policy for how AttestLayer handles personal data and the Subprocessors page for the providers involved. Questions can be sent to privacy@attestlayer.com.

Record-only boundary

Standard AttestLayer workflows are designed around records the customer is authorized to provide without endpoint installation or production credentials. Package verification can establish integrity and issuer-receipt authenticity; it does not establish the truth or completeness of supplied records, control effectiveness, compliance, certification, legal sufficiency, or customer approval.