Skip to content
AttestLayer

AttestLayer Policy

Privacy Policy

This privacy policy applies only to the attestlayer.com corporate, trust, and informational site unless a page on this root domain explicitly states otherwise.

attestlayer.com is the corporate and trust site. Direct-client, partner, Console, Verify, Registry, and API tasks use their dedicated domains.
Updated 25 September 2026 Canonical root-domain policy

Scope and AttestLayer's role

This policy covers the attestlayer.com root site only: company pages, trust pages, policy pages, public informational material, and correspondence that you initiate through the business contact addresses published on that root domain.

AttestLayer acts as the controller for website usage data, contact data, trust or procurement inquiry data, and limited operational data collected through those root-domain pages.

This policy does not govern buy.attestlayer.com, partners.attestlayer.com, verify.attestlayer.com, registry.attestlayer.com, pay.attestlayer.com, or console.attestlayer.com. Each of those domains keeps its own policy set.

What AttestLayer collects

AttestLayer collects only the categories of data needed to operate the root corporate and informational site.

  • Website usage data such as page requests, browser or device metadata, referrer data, IP-based security logs, and first-party operational metrics.
  • Contact and inquiry data that you send to a published AttestLayer address, such as names, work email addresses, company names, and support, trust, procurement, or partnership correspondence.
  • Corporate routing data such as which surface or workflow a visitor asks to be directed toward.
  • Security and abuse-prevention data such as authentication events, rate-limit events, and fraud or misuse signals.

AttestLayer does not sell personal data collected through the root site.

How AttestLayer uses data

AttestLayer uses collected data to operate, secure, and improve the root site and to answer inbound corporate, trust, procurement, or partnership requests.

  • Provide public site content, trust references, and documentation.
  • Route visitors to the appropriate AttestLayer surface for their requested workflow.
  • Respond to support, trust, procurement, legal, or security inquiries.
  • Detect abuse, protect service reliability, and satisfy legal obligations.

Where law requires a legal basis, AttestLayer relies on contract performance, legitimate interests in operating and securing the service, compliance obligations, and consent where consent is the correct basis.

Sharing and subprocessors

AttestLayer shares root-site data only with service providers needed to host and secure the root site or handle correspondence sent to its published business addresses. The root site does not collect payment-card data, complete a checkout, or accept Buyer Review Pack uploads.

  • Google Cloud Platform for root-site hosting, operational logs, and infrastructure.
  • Google Workspace for business mailboxes and correspondence initiated through the published contact addresses.
  • Twilio SendGrid for transactional message delivery where that provider is used for a root-site inquiry or notice.
  • No third-party analytics provider is used on the attestlayer.com root site.

The current provider list is maintained on the Subprocessors page. AttestLayer may also disclose data where required by law, to protect the service, or as part of a corporate transaction involving the business.

Retention, security, and your choices

The root site does not accept Buyer Review Pack files, source records, or payment-card data. Operational logs are retained only as long as needed for site reliability, abuse prevention, and security investigation. Correspondence is retained according to its business, support, procurement, security, privacy, or legal purpose and any applicable preservation obligation.

Customer uploads, Client Console activity, package delivery, and secure-room access occur on separate service-specific domains and are governed by the privacy notice, retention terms, and access controls published for the applicable service.

AttestLayer uses technical and organizational safeguards appropriate to this informational site, including HTTPS delivery and access restrictions for administrative systems. The Security page explains the published security scope and the independent assurance outcomes AttestLayer does not claim.

You can request access, correction, or deletion by contacting privacy@attestlayer.com. Some records may need to be retained to preserve security, respond to a dispute, or meet legal obligations.

Additional disclosures

Automated decision-making. AttestLayer does not use the personal data collected through the attestlayer.com root site to make decisions that produce legal effects on you or similarly significant effects on you without meaningful human involvement. Limited automated processing is used for abuse prevention, security signal detection, rate limiting, and routing of inbound inquiries to the correct AttestLayer team. AttestLayer does not use this site to provide audit opinions, certification, legal advice, or other regulated decisions about visitors.

Cross-border processing. AttestLayer is based in Montreal, Quebec, Canada. Service providers may process information in Canada or other locations identified in their terms and on the Subprocessors page. Where Quebec law requires it, AttestLayer assesses the privacy factors for a transfer outside Quebec and uses a written agreement that records the required safeguards.

Security incidents. If AttestLayer becomes aware of a confirmed security incident that compromises the confidentiality, integrity, or availability of personal data processed through the attestlayer.com root site and that meets the notification threshold of applicable law or any written agreement, AttestLayer will provide notice to affected counterparties and, where required, regulators, within the timeframes required by that law or agreement. Suspected vulnerabilities can be reported to security@attestlayer.com; the public coordinated-disclosure process is published on the Vulnerability Disclosure page.

Privacy Officer and complaints

Privacy Officer (person in charge of the protection of personal information): Rabie-Abdollah Macbahi, Services AttestLayer. The Privacy Officer can be reached at privacy@attestlayer.com.

To make a privacy complaint, use the subject “Privacy complaint” and describe the relevant site, date, information, and requested resolution. Do not email passwords, payment-card data, private keys, or unnecessary sensitive records.

Record-only boundary

Standard AttestLayer workflows are designed around records the customer is authorized to provide without endpoint installation or production credentials. Package verification can establish integrity and issuer-receipt authenticity; it does not establish the truth or completeness of supplied records, control effectiveness, compliance, certification, legal sufficiency, or customer approval.