Skip to content

Vulnerability Disclosure Policy

Last updated: June 23, 2026

AttestLayer welcomes good-faith reports of security vulnerabilities affecting buy.attestlayer.com or the direct-buyer Buyer Review Pack workflow.

Report vulnerabilities to security@attestlayer.com. Include a clear description, affected URL or component, steps to reproduce, expected and observed behavior, and any relevant evidence.

Do not:

  • access, alter, download, or delete another person's data;
  • disrupt the Service or degrade availability;
  • use social engineering, phishing, or physical attacks;
  • submit automated high-volume scans;
  • publicly disclose a vulnerability before AttestLayer has had a reasonable opportunity to investigate and address it.

AttestLayer will acknowledge a good-faith report, investigate it, and communicate status where appropriate. AttestLayer does not authorize activities that violate law or third-party rights.