Skip to content
AttestLayer

AttestLayer Policy

Data Retention

This page describes retention for attestlayer.com website operations and correspondence. Product records follow the policy and agreement for the applicable service.

attestlayer.com is the corporate and trust site. Direct-buyer, partner, Console, Verify, Registry, and API tasks use their dedicated domains.
Updated 27 August 2026 Canonical root-domain policy

Root-site retention

Operational logs are retained only as long as reasonably needed for reliability, abuse prevention, security investigation, and legal obligations. Correspondence is retained according to its business, support, procurement, security, privacy, or legal purpose and any applicable preservation obligation.

The root site does not accept Buyer Review Pack uploads, private package downloads, or payment-card data. Direct-buyer customer records are governed by the product-specific retention commitments on buy.attestlayer.com and the applicable order.

Record-only boundary

Standard AttestLayer workflows are designed around records the customer is authorized to provide without endpoint installation or production credentials. Package verification can establish integrity and issuer-receipt authenticity; it does not establish the truth or completeness of supplied records, control effectiveness, compliance, certification, legal sufficiency, or customer approval.