attest

Privacy Policy

This Policy explains the information attest collects and the limited purposes for which it is processed.

Effective date: August 26, 2026

1. Scope

This Policy covers attestinfra.com, attest accounts, the Service, API, SDK, and related interactions. It applies to website visitors, account users, and authorized integrators. For Customer Personal Data processed on Customer’s behalf, the DPA provides additional terms.

2. Information collected

Account information

Signup currently collects full name, work email, and company or organization. We also process security and session information needed to authenticate users.

Event metadata

Public ingestion currently supports POST /v1/events and POST /v1/traces. Depending on the integration, submitted descriptors can include eventType, Event identity, source, action or actor descriptors, timestamps, hashes, workflow relationships, outcomes, and other supplied metadata. The Service does not require raw sensitive content.

Usage and billing

We process environment, Verification Pass, billing status, usage, and subscription identifiers. Stripe processes payment-card details; attest does not directly store card numbers.

Website and server information

Hosting and application infrastructure may produce standard server information such as IP address, request details, browser or user-agent information, and timestamps for delivery, reliability, and security. The current public application does not include a separate behavioral analytics or advertising integration.

3. Uses

Information is used to receive, normalize, verify, persist, retrieve, report, and export Events and Verification Records; authenticate accounts; secure and support the Service; meter and process billing; provide transactional account email; investigate misuse; comply with law; and communicate material service or security information.

4. Uses attest does not make

attest does not sell, rent, lease, or trade Customer or event data. It does not use Customer event metadata to train machine-learning models, for advertising, or for behavioral profiling unrelated to delivering the Service. It discloses data only to necessary service providers, when legally required, for security or operational necessity, or as otherwise expressly described.

5. Subprocessors

These active providers process information only as necessary for their stated function:

ProviderFunctionProcessing location
RenderApplication hosting and infrastructureUnited States
Managed PostgreSQL via RenderAccount, verification, and usage persistenceUnited States
Stripe, Inc.Payments, subscriptions, and usage meteringUnited States
ResendTransactional account and security emailUnited States processing

Material subprocessor changes will be reflected here. Customers with a DPA receive its notice and objection protections.

6. Location and transfers

Current application hosting and managed PostgreSQL processing are configured in the United States. International transfers are addressed in the DPA.

7. Retention

Verification Records are retained during active Service. Following termination, a 90-day export window applies; records are then deleted subject to law or valid legal hold. Billing and usage records may be retained for up to seven years for tax and accounting purposes. Standard security/server information is retained only as operationally necessary.

8. Security

Measures include TLS in transit, access controls, environment-scoped API authentication, logical Production/Sandbox separation, safe operational logging, replay and duplicate protection, and durable database persistence. No system is impenetrable, and attest does not claim otherwise. See the DPA security measures for more detail.

9. Rights and requests

Depending on applicable law, individuals may have rights of access, correction, deletion, restriction, objection, or portability. Authenticated customers have supported record search, retrieval, and CSV activity export. Other account, Personal Data, or deletion actions may be requested through applicable account or support controls; not every action is currently a self-service dashboard or API operation. attest will respond within the period required by applicable law.

10. Children

attest is business infrastructure, is not directed to anyone under 18, and does not knowingly collect Personal Data from children.

11. Changes

Material changes will be communicated by account email or notice on attestinfra.com before taking effect. Related contractual terms appear in the Terms of Service, Privacy Policy, Data Processing Agreement, FAQ, and Docs.