Surfaces
Every AttestLayer surface, in one map.
AttestLayer is split across purpose-built subdomains so direct buyers, partners, reviewers, institutional channels, and API consumers each see the surface they need without confusion.
All surfaces are part of the same record-only evidence rail. None of them certify compliance or replace audit work.
Public surfaces
buy.attestlayer.com
Direct-buyer purchase paths: Activation, Monthly Coverage, Founding Customer Proof Pack, Enterprise Deal Rail, Enterprise Buyer Proof Pack.
Open buyverify.attestlayer.com
Reviewer-facing verification page and offline verifier walkthrough.
Open verifyHow the surfaces relate
Apex publishes the boundary
attestlayer.com states what AttestLayer is, what it is not, and where each workflow lives.
Buy and partners route purchase intent
buy is for direct buyers. partners is for service providers. program is for institutional and platform partners.
Verify and registry serve reviewers
verify is for reviewer verification flows. registry exposes JWKS and limited verification metadata.
API and console serve operators
api.attestlayer.com is the public evidence API. console.attestlayer.com is the authenticated workspace surface.
The AttestLayer trust model
AttestLayer’s trust model is intentionally narrow. It records what was submitted, what was accepted into scope, what was issued, and how the issued kit can be checked.
The model uses
- SHA-256 artifact hashing
- manifest-based evidence inventory
- canonical receipt hashing
- Ed25519 receipt signatures
- JWKS public-key discovery
- offline verification
- fail-closed verification behavior
What it proves
- files match the manifest
- manifest matches the receipt
- receipt key ID matches a public key
- receipt signature verifies
- the kit has not been modified since issuance
What it does not prove
- company compliance status
- company security status
- controls are operating effectively
- a buyer, auditor, insurer, bank, regulator, or PSP has accepted the packet
- the evidence content is legally sufficient
Integrity and issuance evidence only. Not audit, certification, or compliance guarantee.