attest

Terms of Service

These Terms define the product, responsibility, custody, billing, and risk boundaries for the attest Service.

Effective date: August 26, 2026

1. Agreement and authority

These Terms govern access to and use of attest (the “Service”). By creating an account, accessing the API, using the SDK, or otherwise using the Service, the individual or organization doing so (“Customer”) agrees to these Terms. A person acting for an organization represents that they have authority to bind it.

2. The Service

attest receives machine activity Events submitted by Customer systems, applies the Service’s verification rules, and persists a resulting Verification Record. A supported record may be returned as a Verification Receipt. Related observations, machine workflows, and verification or reconciliation functionality may form part of the Service as it evolves; only functionality documented as currently available is promised.

“Verified” has a narrow meaning: attest verifies the record and process it receives according to the Service’s verification rules and independently preserves the resulting attest record. attest does not certify the objective truth, factual correctness, legality, wisdom, appropriateness, regulatory compliance, or correctness of the underlying real-world or machine claim, nor that an external model or tool behaved as represented unless attest directly observed that boundary. The source remains responsible for the underlying claim and submission.

3. What attest does—and does not do

For accepted Events, attest may normalize event metadata, establish Event identity, apply replay and duplicate protection, timestamp, hash, cryptographically sign, persist, retrieve, report, export, and meter Verification Records. Cryptographic integrity mechanisms can help check whether a specific supported signed record has been modified.

attest is a verification and evidence layer, not an authorization system. It does not approve or block Customer actions. It does not provide legal advice, compliance certification, regulatory assurance, or a guarantee that any Verification Receipt will be accepted as evidence or legal proof by a court, regulator, auditor, or other authority.

4. Custody and Customer data

Before attest receives and accepts an Event, the originating system is responsible for the underlying claim and its transmission. Once attest accepts and persists a Verification Record, attest assumes responsibility for preserving the integrity of the attest record it created. This responsibility concerns custody of that record—not ownership or truth of the underlying Event.

Customer retains ownership of its submitted data and intellectual property. attest uses Customer event metadata only to provide, secure, meter, support, and operate the Service. attest does not sell Customer event metadata, use it for advertising, or use it to train machine-learning models. Disclosures are limited to necessary service providers, legal requirements, security or operational necessities, and purposes expressly described in the Privacy Policy and DPA.

5. Accounts and API credentials

Customer must provide accurate account and billing information, protect session and API credentials, and is responsible for activity under its credentials. Customer must promptly use the applicable account or support controls if credentials may be compromised. attest may suspend or revoke credentials reasonably believed compromised or used contrary to these Terms.

6. Sandbox, Production, pricing, and billing

Sandbox is for testing and is non-billable. Production activity is billable. One unique verified Production Event equals one Verification Pass and costs $0.001. An Event recognized as a duplicate under replay protection does not create or bill another Verification Pass. Production credentials determine Production treatment even if Customer intended to test. Billing is processed through Stripe. Pricing may change on at least 30 days’ prior written notice and never retroactively for already-metered Passes.

7. Acceptable use and data minimization

Customer may use the Service lawfully for machine-activity verification. Customer may not attempt unauthorized access, interfere with the Service, infringe rights, transmit unlawful or harmful content, reverse engineer prohibited portions, resell without consent, or use event metadata as general-purpose storage.

The Service is intended for minimal machine-event descriptors, not raw confidential payloads. Customer should not submit passwords, API keys, authentication headers, payment-card numbers, financial account credentials, full medical records, legal documents, or unnecessary Personal Data. Customer is responsible for submitted content, a lawful basis, required notices and consents, and regulatory duties caused by that content.

8. Access, export, retention, and termination

During active Service, Verification Records are retained and authenticated customers have supported search, retrieval, and CSV activity export functionality. Customer may request other access, account deletion, return, or deletion through applicable account or support controls; these are request rights and not a representation that record or account deletion is self-service.

After termination, Verification Records remain available under a 90-day export window and are then deleted, subject to legal requirements or a valid legal hold. Certain billing and usage records may be retained for up to seven years for tax and accounting obligations. On termination, credentials are revoked and outstanding charges remain due.

9. Availability and source-side failure

attest uses commercially reasonable efforts to operate the Service but does not promise uninterrupted or error-free availability. attest cannot verify an Event it never receives. If Customer does not successfully submit an Event and receive acceptance under the current API contract, no attest Verification Record may exist. Customer controls whether its workflow continues, retries, queues, fails closed, or fails open; it must maintain appropriate source-side fallback behavior. attest does not authorize the underlying action.

10. Warranty disclaimer

TO THE MAXIMUM EXTENT PERMITTED BY LAW, THE SERVICE IS PROVIDED “AS IS” AND “AS AVAILABLE,” WITHOUT EXPRESS OR IMPLIED WARRANTIES, INCLUDING MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, AND NON-INFRINGEMENT. ATTEST DOES NOT WARRANT UNINTERRUPTED, ERROR-FREE, OR IMPENETRABLE OPERATION; OBJECTIVE SOURCE TRUTH; EVIDENTIARY ACCEPTANCE; OR SATISFACTION OF ANY LAW, REGULATION, OR COMPLIANCE STANDARD.

11. Limitation of liability

TO THE MAXIMUM EXTENT PERMITTED BY LAW, ATTEST’S TOTAL AGGREGATE LIABILITY ARISING FROM THESE TERMS OR THE SERVICE WILL NOT EXCEED FEES PAID BY CUSTOMER DURING THE 12 MONTHS BEFORE THE EVENT GIVING RISE TO THE CLAIM. ATTEST WILL NOT BE LIABLE FOR INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY, OR PUNITIVE DAMAGES, INCLUDING LOST PROFITS, DATA, OR BUSINESS OPPORTUNITY.

attest is not liable for underlying source truth; regulatory determinations; Customer systems’ failure to submit activity; reliance on a Receipt as legal proof; or decisions based on the existence or absence of a Verification Record.

12. Indemnification

Customer will indemnify, defend, and hold harmless attest and its personnel and agents from third-party claims, liabilities, damages, losses, and reasonable expenses arising from Customer’s use, submitted content, breach of these Terms, violation of law or rights, or use of Verification Records in legal, regulatory, or commercial contexts.

13. Intellectual property

The Service, API, SDK, documentation, website, marks, and associated intellectual property remain the property of their respective owner(s) and licensors. No ownership rights are transferred to Customer except the limited right to use the Service under these Terms. Customer may refer to attest accurately but may not otherwise use its marks without consent.

14. Suspension, termination, and survival

Customer may request termination through applicable account or support controls. attest may suspend or terminate for breach, compromised credentials, 12 consecutive months of inactivity, or discontinuation of the Service on 90 days’ prior notice. Provisions that by nature should survive—including payment, custody during retention, warranty disclaimers, liability limits, indemnification, and intellectual property—survive.

15. Changes

attest may modify these Terms. Material changes receive at least 30 days’ prior notice by account email or a notice on attestinfra.com. Continued use after the effective date accepts the updated Terms; Customer may terminate before then.

16. Governing law and disputes

Virginia law governs without regard to conflict-of-law rules. Disputes will be resolved in state or federal courts in Virginia. Before filing, each party will attempt informal resolution through the support channel made available through the Service for 30 days.

17. General

If a provision is unenforceable, it is enforced to the maximum permissible extent and the remainder continues. These Terms, the Privacy Policy, and any applicable DPA are the entire agreement concerning the Service and supersede prior communications. A waiver must be written and signed by both parties.