Vulnerability Disclosure Policy
Last updated: June 23, 2026
AttestLayer welcomes good-faith reports of security vulnerabilities affecting buy.attestlayer.com or the direct-buyer Buyer Review Pack workflow.
Report vulnerabilities to security@attestlayer.com. Include a clear description, affected URL or component, steps to reproduce, expected and observed behavior, and any relevant evidence.
Do not:
- access, alter, download, or delete another person's data;
- disrupt the Service or degrade availability;
- use social engineering, phishing, or physical attacks;
- submit automated high-volume scans;
- publicly disclose a vulnerability before AttestLayer has had a reasonable opportunity to investigate and address it.
AttestLayer will acknowledge a good-faith report, investigate it, and communicate status where appropriate. AttestLayer does not authorize activities that violate law or third-party rights.
