Skip to content
AttestLayer

AttestLayer Policy

Terms of Use

These terms govern use of the attestlayer.com root site only unless a page on this root domain explicitly states otherwise.

attestlayer.com is the corporate and trust site. Direct-client, partner, Console, Verify, Registry, and API tasks use their dedicated domains.
Updated 25 September 2026 Canonical root-domain policy

What these terms cover

These terms apply to the attestlayer.com root website, including company pages, trust pages, policy pages, public informational material, and corporate contact routes served on that domain.

They do not replace the service-specific terms on buy.attestlayer.com, partners.attestlayer.com, verify.attestlayer.com, registry.attestlayer.com, or any separate written order or commercial agreement.

Acceptable use

You may use AttestLayer's first-party public surfaces only for lawful purposes and in a way that does not abuse, disable, or interfere with the service.

  • Do not attempt unauthorized access, credential attacks, or service disruption.
  • Do not upload unlawful material or material you are not entitled to submit.
  • Do not use public web surfaces to scrape, copy, or benchmark the service in a way that bypasses normal access controls.
  • Do not perform security testing outside the rules described on the Vulnerability Disclosure page.

Your responsibilities

You are responsible for the accuracy of the information you provide through the root site and for the lawful use of any company, trust, or contact workflow made available on this domain.

  • You should not use the root site to submit secrets, private keys, credentials, or unrelated customer artifacts.
  • You remain responsible for how you interpret and use public informational material made available on this domain.
  • You remain responsible for reviewing the separate terms of any service-specific domain you later choose to use.

Commercial, delivery, and service-specific terms

Root-domain pages describe the company, trust posture, and policy library. The root site does not operate checkout, accept customer source files, create an entitlement, or deliver a customer package.

  • A direct Buyer Review Pack purchase is governed by the terms and policies presented on buy.attestlayer.com and by its order confirmation.
  • A partner, enterprise, or invoiced engagement is governed by its signed order form, invoice terms, or other executed agreement.
  • Verification and registry surfaces may expose public material without creating a paid service relationship on their own.

Intellectual property and disclaimers

AttestLayer retains rights in its site content, software, verification tooling, and branding. You retain rights in correspondence sent to the root site. Any service that accepts customer data is governed by service-specific terms or an executed agreement defining the limited rights needed to process and deliver that service.

Except where a signed agreement states otherwise, AttestLayer provides the public site and related materials on an as-is basis. AttestLayer is not an audit opinion, legal advice service, compliance certification body, or substitute for a client's own review obligations.

Changes, suspension, and contact

AttestLayer may update these terms as the service changes. Material updates will be posted on attestlayer.com. Continued use after an update takes effect means you accept the revised terms.

AttestLayer may suspend or limit access where needed to protect the service, respond to abuse, meet legal obligations, or prevent security harm.

Questions about these terms can be sent to contact@attestlayer.com.

Record-only boundary

Standard AttestLayer workflows are designed around records the customer is authorized to provide without endpoint installation or production credentials. Package verification can establish integrity and issuer-receipt authenticity; it does not establish the truth or completeness of supplied records, control effectiveness, compliance, certification, legal sufficiency, or customer approval.