Security boundary
Package verification can establish manifest integrity and issuer-receipt authenticity. It does not prove Registry inclusion, checkpoint continuity, the truth of underlying business facts, control effectiveness, certification, or customer approval.
Data flow
The corporate site does not accept customer source records. Product-specific collection, processing, retention, and delivery terms are published on the applicable service domain.
Access and tenant isolation
The corporate site is not the authenticated customer workspace. Direct-order access and service controls are described in the Buyer Review Pack security summary. Review the applicable service scope and evidence status rather than assuming that a corporate webpage establishes an operating control.
Direct-product security summary
Upload/document security
Customer requests and evidence are submitted through the authorized direct-product workflow, not this corporate page. The product documentation describes supported inputs, prohibited information and processing boundaries.
Supported inputs and product boundary
Automated/AI processing boundary
The direct-product processing notice explains how the selected scope prepares proposed responses or checks a completed response, and what remains the customer’s responsibility. Provider and data-use statements must be read with the applicable subprocessor and privacy documents.
Automated processing notice
Storage, retention and deletion
Working inputs, generated packages, support records and payment/integrity metadata have different retention rules. Consult the current direct-product retention schedule for their periods and exceptions.
Direct-product retention schedule
Package integrity and verification
Package verification can establish manifest integrity and issuer-receipt authenticity. It does not prove Registry inclusion, checkpoint continuity, the truth of underlying business facts, control effectiveness, certification, or customer approval.
Payments, email and analytics
These functions use the providers and purposes disclosed for the applicable product. Infrastructure-provider status is not independent certification of AttestLayer.
Direct-product subprocessors
Operational security
- Buyer Review Pack application processing, private object storage, and the order database run in Google Cloud Montréal (northamerica-northeast1).
- Public sites use HTTPS. Google-managed encryption protects supported storage and database data at rest.
- Customer package storage uses public-access prevention, least-privilege service identities, and tenant-scoped authorization.
- Console access is email-verified. Payment webhooks are signed. Operational logs are retained for incident review.
- Report a security incident to security@attestlayer.com.
We do not yet have SOC 2, ISO 27001, an independent penetration test, or cyber insurance.
Independent assurance status
Review the current assurance scope for the status of independent certifications, testing, insurance, and other third-party outcomes. AttestLayer does not treat a source setting or narrow observation as certification, an audit, penetration testing, or organization-wide assurance.
AttestLayer does not publish a broader assurance claim for this area.
Procurement documents
Human security contact
Report suspected vulnerabilities or send a procurement-security question to security@attestlayer.com. Do not include secrets or exploit-sensitive data in the first message.