Skip to content

Frequently asked questions

What is the free Fit Check?

The Fit Check screens the current request's file format, deadline, business email, stated record categories, and fixed scope. It does not inspect the source records, estimate how many requirements will be supported, grade answer quality, or predict buyer acceptance. It returns a fit-passed, needs-more-information, or not-fit result; a fit result is not an evidence-readiness guarantee.

Do I need an API key for the Fit Check?

No. The Fit Check and Buyer Review Pack flow are browser-first. You do not need an API key, terminal, installation, connector, or system access to start.

Can I use a Gmail or Outlook email?

Automated checkout requires a business-domain email. Free-email submissions may require follow-up and do not receive the instant automated checkout path.

Do I need to install anything?

No. AttestLayer does not install software, agents, browser extensions, or connectors. You upload selected records through Buyer Console after purchase.

What is Buyer Console?

Buyer Console is the browser-based workspace for paid Buyer Review Pack orders. It shows the purchased review capacity, remaining slots, request history, same-request re-runs, upload instructions, generated packages, and download links.

What file types can I upload?

The buyer-request slot accepts text-extractable PDF, DOCX, XLSX, CSV, TSV, TXT, or MD, up to 20 MiB. The source-evidence slot accepts PDF with extractable text, DOCX, XLSX, CSV, JSON, TXT, or MD. Image-only buyer-request PDFs are unsupported, every source PDF must contain extractable text, and PNG and JPG are not accepted. Each run supports up to 40 source files and 20 MiB combined across the buyer request and sources. Do not upload secrets, credentials, private keys, payment-card data, health information, source code, production access, or unauthorized records.

What does AttestLayer offer and what does it cost?

After a passed Fit Check, the current options are Buyer Review Pack: 1 review for US$5,950 (US$5,950 / review), expiring 30 calendar days after purchase; Two-Review Pipeline Pack: 2 reviews for US$10,950 (US$5,475 / review), expiring 30 calendar days after purchase; Potential US$950 savings if both slots are used before expiry; Three-Review Pipeline Pack: 3 reviews for US$15,950 (US$5,316.67 / review), expiring 30 calendar days after purchase; Potential US$1,900 savings if all three slots are used before expiry; Five-Review Pipeline Pack: 5 reviews for US$24,950 (US$4,990 / review), expiring 30 calendar days after purchase; Potential US$4,800 savings if all five slots are used before expiry. Prices exclude applicable taxes. Every effective per-review price and savings amount assumes every purchased slot is used before expiry; unused capacity expires. Capacity packs are not faster-processing tiers, subscriptions, or annual workflow platforms.

What is included for each buyer review?

Each eligible review receives its own buyer requirement coverage matrix, source-linked draft response statements where submitted records support them, evidence binder index, gap and confirmation report, buyer forwarding note, canonical manifest, Ed25519 signed receipt binding the manifest SHA-256, verification instructions, checksums, and downloadable ZIP. The service does not return a completed copy of the buyer's original workbook or fill a procurement portal, and no analyst QA is included. Your team reviews and transfers any approved answers. Each included review also allows up to two same-request re-runs during the 30-day order window.

Are authorized source files included in the generated ZIP?

Authorized evidence marked downloadable is included under evidence/downloadable in that request's ZIP and is indexed by name, access mode, and SHA-256 hash. Internal records are excluded and cannot support positive buyer-facing statements. Buyer questionnaires, README files, upload instructions, Fit Check files, and internal files are never treated as source evidence.

How do multi-review capacity packs work?

The currently available two-, three-, and five-review packs reserve that number of separate eligible review slots for 30 calendar days after purchase. Effective unit prices and savings assume all purchased slots are used before expiry; unused capacity expires. Each request remains separately scoped and generated, and each receives its own package and verification set. These packs do not add analyst QA, a completion SLA, portal submission, or annual workflow software. A confirmed failed generation does not consume a slot. If generation status is unknown after a timeout, check Package history before retrying the same request reference.

Will you return the buyer's completed spreadsheet or fill its portal?

No. The current product produces a separate source-linked appendix and draft response materials. Your team must review every statement and copy approved answers into the buyer's original workbook or procurement portal. AttestLayer does not log in to, complete, or submit a buyer system.

Can I submit a full RFP or a standardized questionnaire with more than 75 questions?

Not as one request. The current fixed scope supports up to 75 atomic buyer requirements and is intended for security, privacy, or AI-governance review sections. A full RFP, CAIQ-sized questionnaire, or any request with more than 75 extracted requirements must be narrowed before Fit Check.

Is a human analyst or delivery-time SLA included?

No. Generation is automated and does not include an analyst quality-assurance pass. Processing time varies with file size and request complexity, and there is no guaranteed completion time unless a signed agreement states one.

Is there a subscription or monthly plan?

No. Buyer Review Pack and its capacity packs are one-time purchases. There is no subscription, monthly plan, platform implementation, or usage-based billing for this direct-buyer workflow.

How do I pay?

Card checkout is processed by Stripe for Services AttestLayer. Invoice and PO/reference support are available from checkout for eligible Fit Check requests. Card orders activate after successful payment confirmation; invoice orders activate after cleared payment.

What is the refund policy?

Refund eligibility is governed by the Refunds and Billing Policy. If AttestLayer confirms request fit and cannot produce an affected automated output solely because of an AttestLayer processing failure, AttestLayer refunds the affected order or issues an equivalent credit at the customer's choice. Missing, incomplete, unsupported, changed, or out-of-scope customer records do not constitute an AttestLayer processing failure.

Do you guarantee the buyer will accept the package?

No. AttestLayer does not guarantee buyer acceptance, reviewer approval, procurement approval, contract award, or any compliance outcome. The buyer evaluates the underlying records against its own requirements.

What is AttestLayer's record-only boundary?

AttestLayer packages customer-authorized records into source-linked, reviewer-verifiable response materials. It does not provide audits, certifications, legal opinions, compliance approvals, penetration testing, security assessments, insurance opinions, operate customer controls, or promise buyer acceptance.

What can a reviewer verify?

A reviewer can use the hosted verifier to check package-file hashes against the canonical manifest and validate the Ed25519 signed receipt binding the manifest SHA-256. Receipt trust completes only when the receipt key ID resolves to the applicable issuer key published by the AttestLayer Registry. Registry inclusion is separate and is not currently active for Buyer Review Pack issuance. Verification does not prove that source records are true, complete, current, lawful, compliant, or acceptable to a buyer.

Does verification require internet access?

Current-key verification requires internet access unless the verifier already has a supported cached trust snapshot. If current trust keys cannot be retrieved and no supported cached snapshot is available, the verifier reports that it cannot complete current-key verification.

Where is AttestLayer headquartered and who is the seller of record?

The legal seller is Services AttestLayer, operating as AttestLayer. Quebec NEQ: 2282022963. Head office: 360 Saint-Jacques Street, Suite G101, Montreal, Quebec H2Y 1P5, Canada.

Do you access our systems?

No. The Buyer Review Pack workflow does not require customer system access, credentials, agents, endpoint installs, production API keys, privileged access, or integrations.

What data do you store, and for how long?

Email-verification challenge rows are deleted after seven days. Verified sessions and unused Fit Check authorities are deleted approximately 30 days after expiry when they are not linked to a purchase. Request-fit, buyer-request, and source bytes travel in their processing request and are not intentionally persisted as reusable working uploads. Generated packages and order access remain available for the 30-day capacity window; evidence copied into a ZIP follows that package window and deletion lifecycle. Paid Fit Check/order metadata, purchase intents, Stripe event references, entitlements, transactional delivery records, resolved alerts, and provider delivery metadata are ordinarily retained for seven years for billing, accounting, fraud prevention, integrity, support, and disputes, and longer only where law or a preserved legal hold requires it. A definitive pre-acceptance email rejection can be retried safely. An ambiguous transport result is quarantined for manual reconciliation and is never blindly auto-resent. SendGrid processed or accepted means the provider accepted the message for handling; it does not prove inbox delivery. Only a provider delivered event marks the message delivered.

Who are your subprocessors?

Current confirmed subprocessors for the direct-buyer workflow are listed on the Subprocessors page. They include Google Cloud Platform for infrastructure, Stripe for payments and billing, PostHog for consent-based analytics, and transactional email providers where active.

How do I access my package or Buyer Console?

After purchase, open Buyer Console from the confirmation page or confirmation email. Use the same business email connected to the order. Buyer Console tracks every separate request and package under the order. If access fails, contact billing@attestlayer.com.

I paid but did not get access or my confirmation email.

Email billing@attestlayer.com with the purchase email, company name, and Stripe receipt or invoice reference. AttestLayer will verify payment status and resend or repair access where appropriate. Do not submit a second payment until the first payment status has been checked.

Can I talk to a person?

Yes. For product or accessibility support, email support@attestlayer.com. For general questions, email contact@attestlayer.com. For billing, invoice, PO, or access questions, email billing@attestlayer.com. For privacy requests, email privacy@attestlayer.com. For security questions, email security@attestlayer.com.

Unsubscribe or stop contacting me.

Use the unsubscribe link in the outreach email when available, or reply with an opt-out request. AttestLayer will suppress future outreach to that address where required.

Check a live buyer request