Registry and Verification Policy
Last updated: July 17, 2026
1. Purpose
Buyer Review Pack receipt trust is checked against the published issuer JWKS. Separate Registry transparency-log inclusion is not currently active for Buyer Review Pack issuance, and a package or receipt must not be treated as proof of inclusion.
2. What the Registry contains
Registry entries contain cryptographic commitments and technical metadata necessary to verify an issued package. The Registry does not contain customer names, company names, email addresses, source records, buyer requests, evidence binder index files, or recoverable source content.
3. What verification confirms
Verification can confirm whether package files match the canonical manifest and whether the Ed25519 signed receipt binding the manifest SHA-256 validates against a trusted issuer JWKS snapshot published by the AttestLayer Registry. Registry inclusion is a separate contract and is not currently active for Buyer Review Pack issuance.
Verification does not confirm that source records are true, complete, current, lawful, or accepted by an external buyer. It does not create an audit, certification, legal opinion, compliance approval, or buyer-acceptance guarantee.
4. Trust keys and internet access
Receipt verification succeeds only when the receipt key ID resolves to the applicable issuer key published by the AttestLayer Registry. Registry-checkpoint verification uses the separate registry key. The verifier retrieves current published keys over the internet. If the applicable receipt key ID is absent or the key set cannot be retrieved, the verifier reports that it cannot complete trust verification. A package cannot establish its own trust by embedding its own key.
5. Registry availability
The Registry publishes its current available status and verification materials at registry.attestlayer.com. AttestLayer does not promise a specific checkpoint cadence, merge delay, witness status, or third-party notarization on this direct-buyer page.
6. External review
Anyone may independently inspect the verification materials and published trust keys. External witnessing and notarization are not represented as active unless the Registry expressly publishes that status.
7. Questions
Security and registry questions: security@attestlayer.com
