Download sample verification kit
Download a static sample bundle to inspect its manifest and receipt, then use the hosted sample verification flow before starting a Buyer Review Pack.
Download
attestlayer-sample-kit.zip
ZIP SHA-256 18109da39463ee4fd20882451e52d979dee596d9a3493d751c4c0b6f273d85e9
Manifest Root Hash 18e1ca5c6cc86bfcf00ac7a8f86e603735c3d317555ad76d6bb7ad6671dec28a
| Schema | MANIFEST-02 / FES-1.0 |
| Receipt Key ID | 8adefa300a1059bc |
| Bundle Type | static sample verification bundle |
What to Look For
Inside this compact sample bundle:
- START-HERE.pdf — quick orientation for the demo bundle
- manifest.json — SHA-256 file index with root hash (MANIFEST-02)
- receipt.json — Ed25519 signed receipt (FES-1.0, kid: 8adefa300a1059bc)
- artifacts/sample-binder.pdf — sample evidence binder index
- mapping.json — file role descriptions
- README-FIRST.md — kit overview and verification instructions
Live Buyer Review Pack receipts bind the canonical manifest SHA-256 and are trusted only when their key_id resolves to the applicable issuer key published by the AttestLayer Registry at issuer.jwks.json. A receipt cannot establish trust by embedding its own public key. Registry inclusion is separate and is not currently active for Buyer Review Pack issuance.
How live Buyer Review Pack delivery differs
A live Buyer Review Pack is generated separately for one approved buyer request. It includes the executive summary, requirement matrix, source-linked statements, evidence binder, gap and confirmation report, buyer forwarding note, canonical manifest, Ed25519 signed receipt binding the manifest SHA-256, verification instructions, checksums, and authorized downloadable evidence when applicable. Its current schema and file list are documented on the Documentation page. The downloadable sample above is a separate demonstration and does not define the live package file list.
The live buyer questionnaire, README files, upload instructions, Fit Check files, and records marked internal are excluded from supporting evidence. The current service does not offer hosted view-only evidence, post-issuance revocation, or in-place replacement.
Live work uses only records your organization authorizes for that buyer request. AttestLayer does not create unsupported claims, provide legal advice, issue a certification, or guarantee buyer acceptance.
Inspect Artifacts Individually
How to Verify
- Download the sample kit above.
- Go to verify.attestlayer.com and upload the ZIP.
- The verifier checks every SHA-256 hash in the manifest and verifies the Ed25519 receipt signature against the applicable trusted key set.
- Do not treat any file carried inside a package as the trust source for a live Buyer Review Pack; live trust resolves the receipt key ID through the applicable Registry-published issuer key.
