Privacy Policy
This Policy explains the information attest collects and the limited purposes for which it is processed.
Effective date: August 26, 2026
1. Scope
This Policy covers attestinfra.com, attest accounts, the Service, API, SDK, and related interactions. It applies to website visitors, account users, and authorized integrators. For Customer Personal Data processed on Customer’s behalf, the DPA provides additional terms.
2. Information collected
Account information
Signup currently collects full name, work email, and company or organization. We also process security and session information needed to authenticate users.
Event metadata
Public ingestion currently supports POST /v1/events and POST /v1/traces. Depending on the integration, submitted descriptors can include eventType, Event identity, source, action or actor descriptors, timestamps, hashes, workflow relationships, outcomes, and other supplied metadata. The Service does not require raw sensitive content.
Usage and billing
We process environment, Verification Pass, billing status, usage, and subscription identifiers. Stripe processes payment-card details; attest does not directly store card numbers.
Website and server information
Hosting and application infrastructure may produce standard server information such as IP address, request details, browser or user-agent information, and timestamps for delivery, reliability, and security. The current public application does not include a separate behavioral analytics or advertising integration.
3. Uses
Information is used to receive, normalize, verify, persist, retrieve, report, and export Events and Verification Records; authenticate accounts; secure and support the Service; meter and process billing; provide transactional account email; investigate misuse; comply with law; and communicate material service or security information.
4. Uses attest does not make
attest does not sell, rent, lease, or trade Customer or event data. It does not use Customer event metadata to train machine-learning models, for advertising, or for behavioral profiling unrelated to delivering the Service. It discloses data only to necessary service providers, when legally required, for security or operational necessity, or as otherwise expressly described.
5. Subprocessors
These active providers process information only as necessary for their stated function:
| Provider | Function | Processing location |
|---|---|---|
| Render | Application hosting and infrastructure | United States |
| Managed PostgreSQL via Render | Account, verification, and usage persistence | United States |
| Stripe, Inc. | Payments, subscriptions, and usage metering | United States |
| Resend | Transactional account and security email | United States processing |
Material subprocessor changes will be reflected here. Customers with a DPA receive its notice and objection protections.
6. Location and transfers
Current application hosting and managed PostgreSQL processing are configured in the United States. International transfers are addressed in the DPA.
7. Retention
Verification Records are retained during active Service. Following termination, a 90-day export window applies; records are then deleted subject to law or valid legal hold. Billing and usage records may be retained for up to seven years for tax and accounting purposes. Standard security/server information is retained only as operationally necessary.
8. Security
Measures include TLS in transit, access controls, environment-scoped API authentication, logical Production/Sandbox separation, safe operational logging, replay and duplicate protection, and durable database persistence. No system is impenetrable, and attest does not claim otherwise. See the DPA security measures for more detail.
9. Rights and requests
Depending on applicable law, individuals may have rights of access, correction, deletion, restriction, objection, or portability. Authenticated customers have supported record search, retrieval, and CSV activity export. Other account, Personal Data, or deletion actions may be requested through applicable account or support controls; not every action is currently a self-service dashboard or API operation. attest will respond within the period required by applicable law.
10. Children
attest is business infrastructure, is not directed to anyone under 18, and does not knowingly collect Personal Data from children.
11. Changes
Material changes will be communicated by account email or notice on attestinfra.com before taking effect. Related contractual terms appear in the Terms of Service, Privacy Policy, Data Processing Agreement, FAQ, and Docs.