Security and data handling
The Buyer Review Pack is record-only and browser-based. It does not require system credentials, agents, software installation, or production-system access.
Request bytes and generated packages follow separate handling boundaries.
Buyer-request and source bytes submitted for Buyer Review Pack processing travel in the generation request and are not intentionally persisted as separate working-upload objects; the application does not retain those bytes for reuse after the request ends. Generated packages remain available during the 30-day order window; authorized evidence copied into a generated ZIP remains inside that ZIP during its access period. Package-object deletion is lifecycle-driven and asynchronous, and a deleted object can remain operator-recoverable during a seven-day soft-delete period.
Do not upload credentials, private keys, API keys, passwords, payment-card data, government identification numbers, health information, source code, or any record you are not authorized to provide.
Core platform controls
- HTTPS with TLS 1.2 or higher for public endpoints
- Google Cloud infrastructure in Montréal for direct-buyer source-record processing
- Google-managed encryption at rest for supported storage services
- Cloud SQL PostgreSQL for application data
- Least-privilege access controls for production services
- Signed package receipts using versioned Ed25519 signing keys
- SHA-256 manifest hashing for issued package integrity checks
Separate systems for payments and analytics
Stripe processes card payments, invoices, receipts, and payment status. AttestLayer does not store full payment-card numbers.
PostHog processes limited website and product analytics. Uploaded buyer requests, source records, generated response statements, evidence binder index files, manifests, receipts, and package files are not sent to PostHog.
Package verification
Issued packages include a canonical manifest and an Ed25519 signed receipt binding the manifest SHA-256. Verification recalculates package-file hashes against the manifest and validates the receipt only when its key ID resolves to the applicable issuer key published by the AttestLayer Registry. Registry inclusion is separate and is not currently active for Buyer Review Pack issuance; the separate registry key applies only if that contract is activated in the future. Internet access is required to retrieve current published trust keys. A successful verification confirms package integrity and receipt validity; it does not prove that a source record is true, complete, current, or accepted by an external buyer.
Procurement-ready documents
The following documents are available before purchase:
