Skip to content
AttestLayer

AttestLayer Security

Security

AttestLayer publishes narrow, evidence-backed security statements and keeps product, verification, and independent-assurance boundaries explicit. Standard record workflows are designed not to require endpoint installation or production credentials.

attestlayer.com is the corporate and trust site. Direct-client, partner, Console, Verify, Registry, and API tasks use their dedicated domains.
Updated 25 September 2026 Canonical root-domain policy

Security boundary

Package verification can establish manifest integrity and issuer-receipt authenticity. It does not prove Registry inclusion, checkpoint continuity, the truth of underlying business facts, control effectiveness, certification, or customer approval.

Data flow

The corporate site does not accept customer source records. Product-specific collection, processing, retention, and delivery terms are published on the applicable service domain.

Access and tenant isolation

The corporate site is not the authenticated customer workspace. Direct-order access and service controls are described in the Buyer Review Pack security summary. Review the applicable service scope and evidence status rather than assuming that a corporate webpage establishes an operating control.

Direct-product security summary

Upload/document security

Customer requests and evidence are submitted through the authorized direct-product workflow, not this corporate page. The product documentation describes supported inputs, prohibited information and processing boundaries.

Supported inputs and product boundary

Automated/AI processing boundary

The direct-product processing notice explains how the selected scope prepares proposed responses or checks a completed response, and what remains the customer’s responsibility. Provider and data-use statements must be read with the applicable subprocessor and privacy documents.

Automated processing notice

Storage, retention and deletion

Working inputs, generated packages, support records and payment/integrity metadata have different retention rules. Consult the current direct-product retention schedule for their periods and exceptions.

Direct-product retention schedule

Package integrity and verification

Package verification can establish manifest integrity and issuer-receipt authenticity. It does not prove Registry inclusion, checkpoint continuity, the truth of underlying business facts, control effectiveness, certification, or customer approval.

Payments, email and analytics

These functions use the providers and purposes disclosed for the applicable product. Infrastructure-provider status is not independent certification of AttestLayer.

Direct-product subprocessors

Operational security

  • Buyer Review Pack application processing, private object storage, and the order database run in Google Cloud Montréal (northamerica-northeast1).
  • Public sites use HTTPS. Google-managed encryption protects supported storage and database data at rest.
  • Customer package storage uses public-access prevention, least-privilege service identities, and tenant-scoped authorization.
  • Console access is email-verified. Payment webhooks are signed. Operational logs are retained for incident review.
  • Report a security incident to security@attestlayer.com.

We do not yet have SOC 2, ISO 27001, an independent penetration test, or cyber insurance.

Independent assurance status

Review the current assurance scope for the status of independent certifications, testing, insurance, and other third-party outcomes. AttestLayer does not treat a source setting or narrow observation as certification, an audit, penetration testing, or organization-wide assurance.

AttestLayer does not publish a broader assurance claim for this area.

Human security contact

Report suspected vulnerabilities or send a procurement-security question to security@attestlayer.com. Do not include secrets or exploit-sensitive data in the first message.