AttestLayer

Surfaces

Every AttestLayer surface, in one map.

AttestLayer is split across purpose-built subdomains so direct buyers, partners, reviewers, institutional channels, and API consumers each see the surface they need without confusion.

All surfaces are part of the same record-only evidence rail. None of them certify compliance or replace audit work.

Public surfaces

attestlayer.com

Apex site: who AttestLayer is, what we publish, and where to go next.

Open apex

buy.attestlayer.com

Direct-buyer purchase paths: Activation, Monthly Coverage, Founding Customer Proof Pack, Enterprise Deal Rail, Enterprise Buyer Proof Pack.

Open buy

partners.attestlayer.com

Service-provider partner program and Distribution Pack.

Open partners

program.attestlayer.com

Standardization Program for institutional and platform partners.

Open program

verify.attestlayer.com

Reviewer-facing verification page and offline verifier walkthrough.

Open verify

registry.attestlayer.com

Public verification metadata and JWKS key discovery.

Open registry

api.attestlayer.com

Evidence API (FES-1.0-preview), endpoints, OpenAPI, changelog.

Open API

console.attestlayer.com

Customer console for live workspaces; account access required.

Open console

How the surfaces relate

Apex publishes the boundary

attestlayer.com states what AttestLayer is, what it is not, and where each workflow lives.

Buy and partners route purchase intent

buy is for direct buyers. partners is for service providers. program is for institutional and platform partners.

Verify and registry serve reviewers

verify is for reviewer verification flows. registry exposes JWKS and limited verification metadata.

API and console serve operators

api.attestlayer.com is the public evidence API. console.attestlayer.com is the authenticated workspace surface.

The AttestLayer trust model

AttestLayer’s trust model is intentionally narrow. It records what was submitted, what was accepted into scope, what was issued, and how the issued kit can be checked.

The model uses

  • SHA-256 artifact hashing
  • manifest-based evidence inventory
  • canonical receipt hashing
  • Ed25519 receipt signatures
  • JWKS public-key discovery
  • offline verification
  • fail-closed verification behavior

What it proves

  • files match the manifest
  • manifest matches the receipt
  • receipt key ID matches a public key
  • receipt signature verifies
  • the kit has not been modified since issuance

What it does not prove

  • company compliance status
  • company security status
  • controls are operating effectively
  • a buyer, auditor, insurer, bank, regulator, or PSP has accepted the packet
  • the evidence content is legally sufficient

Integrity and issuance evidence only. Not audit, certification, or compliance guarantee.