Skip to content
Security

Security and verification.

Every step from a user's approval to the reported outcome is signed, and the record holding those steps is tamper-evident. This page is the front door to the mechanics: what is signed, where the public keys live, and how to check all of it without trusting us.

Signed evidence

What is signed.

  • The immutable mandate and its policy digest.
  • The verified approval proof: the hosted passkey ceremony that bound the user to those exact terms.
  • Every proposed action and decision (ALLOW, DENY, INDETERMINATE), with the period each allowed charge is attributed to.
  • Reservation, commit, cancellation, revocation, and expiry events.
  • Lifecycle assertions your platform supplies, labelled as yours and never re-signed as ours.

Attesso stores no payment credentials, provider secrets, passkey private keys, or biometric data. The signature covers the list above as one flattened JWS.

Keys

Only public keys are published.

Signing keys are held by Attesso and never leave our infrastructure. The public key sets are open, cacheable, and need no API key:

Evidence keys
https://api.attesso.com/.well-known/jwks.json
Record log keys
https://api.attesso.com/.well-known/record-log-jwks.json

Evidence signatures are ES256 (ECDSA P-256). Rotated log keys stay published, so checkpoints signed under earlier keys remain verifiable.

Verification

How to check it.

  1. 1. Fetch the bundle. The evidence endpoint returns one flattened JWS per mandate, carrying the events listed above.
  2. 2. Verify the signature. Resolve the protected kid only from the published evidence keys and check the ES256 signature offline.
  3. 3. Prove the record.Fetch the latest signed checkpoint, show that a snapshot you saved earlier is still contained in it (an RFC 6962 consistency proof), and prove your mandate's events are included.
  4. 4. Check the anchor. The checkpoint hash carries an RFC 3161 timestamp from an independent time authority, so the checkpoint existed by that moment regardless of our clock.

Verification needs no Attesso service; you fetch fresh proofs only when you want to extend the guarantee. Both procedures have runnable guides:

Limits

What this does not prove.

  • Evidence is not a payment receipt and does not prove that an external provider performed an action. It distinguishes Attesso-verified events from facts your platform reported.
  • Checkpoints are signed by one published key. Saved checkpoints and the prev_hash chain pin earlier history, and rotated log keys stay published so old checkpoints remain verifiable.
Reporting

Report a vulnerability.

Report suspected vulnerabilities to info@attesso.com; we typically respond within one business day. The machine-readable contact is published at /.well-known/security.txt.

This page reflects the v1 security model as of October 2026. Operated by Attesso B.V., registered in ’s-Hertogenbosch, the Netherlands, KVK 42040136.

Everything above is checkable.

The guides run on your machine against the published keys.