Skip to content
AttestLayer

AttestLayer Policy

Subprocessors

This list covers the third-party providers AttestLayer currently uses to operate the attestlayer.com root site and related corporate informational workflows.

attestlayer.com is the corporate and trust site. Direct-client, partner, Console, Verify, Registry, and API tasks use their dedicated domains.
Updated 25 September 2026 Canonical root-domain policy

Scope and update model

This page is the subprocessor list for the attestlayer.com root site only. It is not the processor list for buy.attestlayer.com, partners.attestlayer.com, verify.attestlayer.com, or registry.attestlayer.com.

Material updates to the providers used for first-party operations will be reflected here. Specific enterprise agreements may supplement this list where a separate negotiated processor schedule applies.

Current providers

Provider Purpose Notes
Google Cloud Platform Website hosting, storage, logs, and root-site infrastructure. Canada (Montreal) for primary service resources. Limited provider support and security processing may occur in other locations under Google terms.
Google Workspace Business mailboxes and correspondence sent to the contact addresses published on the root site. Message and account metadata may be processed where Google provides Workspace services.
Twilio SendGrid Transactional message delivery where used for a root-site inquiry, policy notice, or trust communication. Used for operational messages, not advertising resale.

Record-only boundary

Standard AttestLayer workflows are designed around records the customer is authorized to provide without endpoint installation or production credentials. Package verification can establish integrity and issuer-receipt authenticity; it does not establish the truth or completeness of supplied records, control effectiveness, compliance, certification, legal sufficiency, or customer approval.