EVIDENCE VAULT

Sealed the moment
it's collected.

Every artifact is hashed on arrival and written once — immutable, encrypted, and access-logged. When it's time to produce evidence, its integrity is provable down to the byte.

EVIDENCE VAULT · CASE-4471WORM · SEALED
memory.dmp
sha256:a3f4e9c1…d72b · 4.2 GB
SEALED
disk.e01
sha256:7c10b8a2…91ef · 512 GB
SEALED
capture.pcap
sha256:9bd3f6e0…4a17 · 88 MB
SEALED
Immutable · access loggedretention · 7y
HOW IT WORKS

Provable from collection to court.

01
Collect

Artifacts are ingested and hashed the instant they arrive.

02
Seal

Written once, encrypted, and made immutable — WORM by default.

03
Track

Every view, download, and export is logged and attributed.

04
Produce

Export with an integrity proof a court will accept.

WHAT'S INSIDE

Built to survive scrutiny.

WORM immutability

Write-once storage that nothing — and no one — can quietly alter.

Cryptographic sealing

SHA-256 on every artifact, re-verified on every access.

Access audit

A complete, attributable record of who touched what, and when.

Legal hold & retention

Policy-driven holds and retention that hold up under audit.

CRYPTOGRAPHIC VERIFICATION

Integrity you can recompute, not just trust.

Each artifact's SHA-256 is chained into a per-case Merkle tree. The root is anchored to an RFC 3161 timestamp authority every hour, so the moment of sealing is provable independent of threatDefendr — even years later.

SHA-256 + BLAKE3 dual-hash on ingest, re-verified on every read.
Merkle anchoring to an external RFC 3161 TSA — tamper of any byte breaks the root.
Dual-control seals — production exports require two-person authorization.
INTEGRITY PROOF · CASE-4471VERIFIED
$ td vault verify CASE-4471 --recompute
→ hashing 3 artifacts (4.7 GB)…
memory.dmp    a3f4e9c1…d72b
disk.e01      7c10b8a2…91ef
capture.pcap  9bd3f6e0…4a17
→ merkle root
d1c0… e88f 9a42 5b73 c6d1
→ TSA anchor 2026-06-20T14:00:03Z
✓ INTEGRITY INTACT · 0 mismatches
CHAIN OF CUSTODY

Every hand it passed through, on the record.

A continuous, signed custody log — no gaps, no edits, no “trust me.” Each transfer is attributed, timestamped, and cryptographically linked to the one before it.

CHAIN OF CUSTODY →
TIMESTAMPEVENTACTORSIGNATURE
{{ c.time }} {{ c.kind }}{{ c.event }} {{ c.actor }} {{ c.sig }}
ADMISSIBILITY & COMPLIANCE

Engineered around the standards counsel asks for.

The vault maps to the evidentiary and forensic standards courts and regulators expect — so your team spends the deposition explaining the case, not the tooling.

{{ s.code }}
{{ s.title }}

{{ s.desc }}

WHO RELIES ON IT

One vault, four very different bad days.

{{ u.no }}
{{ u.title }}

{{ u.desc }}

COLLECTS FROM
{{ x }}
PRODUCES TO
{{ x }}
TECHNICAL SPECIFICATION

The details your architects will ask for.

{{ sp.k }} {{ sp.v }}
PROOF

“Opposing counsel challenged our evidence handling on day one. We produced the integrity proof and the full custody log in under a minute. The motion to exclude was withdrawn the same afternoon.”

RM
R. Mercer
DIR. INCIDENT RESPONSE · FORTUNE 100 INSURER

Make every artifact defensible by default.

See the vault seal, verify, and produce a piece of evidence end to end — in a 30-minute walkthrough on your own retention policy.

// EVIDENCE VAULT

Sealed the moment
it's collected.

Every artifact is hashed on arrival and written once — immutable, encrypted, and access-logged. When it's time to produce evidence, its integrity is provable down to the byte.

EVIDENCE VAULT · CASE-4471WORM · SEALED
memory.dmp
sha256:a3f4e9c1…d72b · 4.2 GB
SEALED
disk.e01
sha256:7c10b8a2…91ef · 512 GB
SEALED
capture.pcap
sha256:9bd3f6e0…4a17 · 88 MB
SEALED
Immutable · access loggedretention · 7y
1.4M
Artifacts sealed
920TB
Under WORM
4.2M
Integrity checks / day
0
Tamper events
// EVIDENCE LIFECYCLE

Provable from collection to court.

LIFECYCLE · PER-ARTIFACTSEALING
01CollectArtifacts are ingested and hashed the instant they arrive.HASHED
02SealWritten once, encrypted, and made immutable — WORM by default.WORM
03TrackEvery view, download, and export is logged and attributed.LOGGED
04ProduceExport with an integrity proof a court will accept.CERTIFIED
// VAULT LEDGER · LIVE

Built to survive scrutiny.

ARTIFACTCASESHA-256STATE
memory.dmpCASE-4471a3f4e9c1…d72bSEALED
disk.e01CASE-44717c10b8a2…91efSEALED
capture.pcapCASE-44689bd3f6e0…4a17SEALED
production.zipCASE-44595e8a1d44…0c33PRODUCED
// CRYPTOGRAPHIC VERIFICATION

Integrity you can recompute, not just trust.

Each artifact's SHA-256 is chained into a per-case Merkle tree. The root is anchored to an RFC 3161 timestamp authority every hour, so the moment of sealing is provable independent of threatDefendr — even years later.

SHA-256 + BLAKE3 dual-hash on ingest, re-verified on every read.
Merkle anchoring to an external RFC 3161 TSA — tamper of any byte breaks the root.
Dual-control seals — production exports require two-person authorization.
INTEGRITY PROOF · CASE-4471VERIFIED
$ td vault verify CASE-4471 --recompute
→ hashing 3 artifacts (4.7 GB)…
memory.dmp    a3f4e9c1…d72b
disk.e01      7c10b8a2…91ef
capture.pcap  9bd3f6e0…4a17
→ merkle root
d1c0… e88f 9a42 5b73 c6d1
→ TSA anchor 2026-06-20T14:00:03Z
✓ INTEGRITY INTACT · 0 mismatches
// CHAIN OF CUSTODY

Every hand it passed through, on the record.

A continuous, signed custody log — no gaps, no edits, no “trust me.” Each transfer is attributed, timestamped, and cryptographically linked to the one before it.

CHAIN OF CUSTODY →
TIMESTAMPEVENTACTORSIGNATURE
{{ c.time }} {{ c.kind }}{{ c.event }} {{ c.actor }} {{ c.sig }}
// ADMISSIBILITY & COMPLIANCE

Engineered around the standards counsel asks for.

The vault maps to the evidentiary and forensic standards courts and regulators expect — so your team spends the deposition explaining the case, not the tooling.

{{ s.code }}
{{ s.title }}

{{ s.desc }}

// WHO RELIES ON IT

One vault, four very different bad days.

{{ u.no }}
{{ u.title }}

{{ u.desc }}

COLLECTS FROM
{{ x }}
PRODUCES TO
{{ x }}
// TECHNICAL SPECIFICATION

The details your architects will ask for.

{{ sp.k }} {{ sp.v }}
// PROOF

“Opposing counsel challenged our evidence handling on day one. We produced the integrity proof and the full custody log in under a minute. The motion to exclude was withdrawn the same afternoon.”

RM
R. Mercer
DIR. INCIDENT RESPONSE · FORTUNE 100 INSURER

Make every artifact defensible by default.

See the vault seal, verify, and produce a piece of evidence end to end — in a 30-minute walkthrough on your own retention policy.