Registry and verification policy
A flow-specific summary for partners.attestlayer.com and program.attestlayer.com.
Qualification does not issue a Registry entry
The public Partner and Program qualification flow collects business contact and fit information. It does not issue a Buyer Review Pack, create a transparency-log entry, or provide proof that an organization has joined a partner program.
Buyer Review Pack receipt trust
If a Buyer Review Pack is later purchased and issued, its receipt binds the canonical manifest SHA-256 and is verified against the applicable issuer key published at the Registry issuer JWKS. A package-supplied key cannot establish its own trust.
Registry inclusion is separate and is not currently active for Buyer Review Pack issuance. A package or receipt alone must not be represented as proof of transparency-log inclusion.
Current Registry boundaries
- Only artifacts deliberately published through the Registry path are Registry entries.
- Public inclusion and consistency proof generators currently fail closed with HTTP 501 pending independent RFC 6962 conformance vectors.
- Checkpoints are self-issued by AttestLayer; external witnessing and external anchoring are not active.
- The legacy registry-wide verification-kit download is retired.
- Registry material proves only the cryptographic facts it actually contains—not compliance, truth, completeness, certification, or buyer approval.
How a reviewer verifies an issued package
- Keep the complete
buyer-review-pack.zip. - Upload it to the hosted verifier.
- Confirm every manifest-covered file, the canonical manifest hash, and the signed receipt pass.
- Confirm the receipt key ID resolves through the Registry-published issuer JWKS.
- Do not infer Registry inclusion unless a separate, valid inclusion contract and proof are supplied.
The canonical Registry policy and live readiness status are published at registry.attestlayer.com/registry-policy and registry.attestlayer.com/ready. See also Partner & Program Security.
