Skip to content
AttestLayerAttestLayer

Registry and verification policy

A flow-specific summary for partners.attestlayer.com and program.attestlayer.com.

Qualification does not issue a Registry entry

The public Partner and Program qualification flow collects business contact and fit information. It does not issue a Buyer Review Pack, create a transparency-log entry, or provide proof that an organization has joined a partner program.

Buyer Review Pack receipt trust

If a Buyer Review Pack is later purchased and issued, its receipt binds the canonical manifest SHA-256 and is verified against the applicable issuer key published at the Registry issuer JWKS. A package-supplied key cannot establish its own trust.

Registry inclusion is separate and is not currently active for Buyer Review Pack issuance. A package or receipt alone must not be represented as proof of transparency-log inclusion.

Current Registry boundaries

  • Only artifacts deliberately published through the Registry path are Registry entries.
  • Public inclusion and consistency proof generators currently fail closed with HTTP 501 pending independent RFC 6962 conformance vectors.
  • Checkpoints are self-issued by AttestLayer; external witnessing and external anchoring are not active.
  • The legacy registry-wide verification-kit download is retired.
  • Registry material proves only the cryptographic facts it actually contains—not compliance, truth, completeness, certification, or buyer approval.

How a reviewer verifies an issued package

  1. Keep the complete buyer-review-pack.zip.
  2. Upload it to the hosted verifier.
  3. Confirm every manifest-covered file, the canonical manifest hash, and the signed receipt pass.
  4. Confirm the receipt key ID resolves through the Registry-published issuer JWKS.
  5. Do not infer Registry inclusion unless a separate, valid inclusion contract and proof are supplied.

The canonical Registry policy and live readiness status are published at registry.attestlayer.com/registry-policy and registry.attestlayer.com/ready. See also Partner & Program Security.