Skip to content
AttestLayer

AttestLayer Policy

Vulnerability Disclosure

Updated 25 September 2026. Report issues to security@attestlayer.com.

attestlayer.com is the corporate and trust site. Direct-client, partner, Console, Verify, Registry, and API tasks use their dedicated domains.
Updated 25 September 2026 Canonical root-domain policy

What is in scope

Every site AttestLayer operates: attestlayer.com and www; buy, console, verify, registry, api, partners, program; ops (reporting only; see testing rules); pay (our configuration only; Stripe's own systems are out of scope).

How to report an issue

Email security@attestlayer.com. Include the affected URL or component, the steps to reproduce, the impact you observed, and any proof-of-concept. Don't include other people's personal data or secrets.

  • The affected URL, host, or surface.
  • Clear steps to reproduce the issue.
  • The observed impact and any suggested severity.
  • Timestamps, screenshots, logs, or proof-of-concept material that helps confirm the report.

Rules of engagement

You may test the public pages and your own account or order. The Fit Check and test-mode checkout may be used with test data. Keep testing safe and minimal: no denial-of-service or load testing, no automated high-volume scanning, no social engineering, no physical attacks, no attempts against the ops sign-in, and don't access, change or keep data that isn't yours. Stop as soon as you have enough to show the problem, and report it.

Safe harbour. If you act in good faith and follow this policy, we consider your research authorized, won't take legal action against you, and won't report you to law enforcement. If a third party takes action against you, we'll make it clear that your research was authorized by this policy. This can't bind third parties such as Stripe, Google or SendGrid.

Coordination and disclosure expectations

We acknowledge your report within 3 business days, give an initial assessment within 10 business days, and update you at least every 14 days until it's resolved. We aim to fix critical issues within 30 days.

Please give us 90 days, or until a fix ships if sooner, before publishing. We're happy to credit you by name if you'd like. We don't run a paid bug bounty.

Out of scope: third-party services; reports that only list missing headers or best practices without a demonstrated impact; clickjacking on pages without sensitive actions; self-XSS; rate limiting on non-sensitive endpoints; SPF/DKIM/DMARC reports without a working spoof.

Record-only boundary

Standard AttestLayer workflows are designed around records the customer is authorized to provide without endpoint installation or production credentials. Package verification can establish integrity and issuer-receipt authenticity; it does not establish the truth or completeness of supplied records, control effectiveness, compliance, certification, legal sufficiency, or customer approval.