Sitinel / Evidence Chain

Evidence
Chain.

A cryptographic chain-of-custody built for parking disputes, theft investigations, and premises-liability claims. It supports authentication under FRE 901/902 and follows ISO/IEC 27037 and SWGDE digital-evidence practice. Below: exactly what we sign, when, and how a third party checks it.

vs. the record-and-hope camera world.

Stock NVRLoops every 7 to 45 days, and files can be rewritten off a USB cable. No hash, no signature.No chain
Verkada VerifyChecks a file was not altered after the fact, at export time. Nothing is signed at the moment of capture.After the fact
Evidence lockersAxon-style systems manage custody after upload, by hand. No at-capture tamper-evidence.Post-upload
SitinelPer-frame hash signed at capture, hourly signed root, public append-only log.✓ Signed at capture

How a third party verifies

  1. You export a clip. The export bundles the frame bytes, the per-frame hashes, and the Merkle proof linking those hashes to a signed hourly root.
  2. The third party recomputes the hashes locally from the clip bytes.
  3. They walk the Merkle proof to reconstruct the root.
  4. They fetch the same signed root from Sitinel's public transparency log.
  5. If the signatures match and the root is present in the log, the clip is authentic and has not been edited since capture.

No trust in Sitinel required. No access to any other footage required. The math does the work.

What this is designed to prevent

Frequently asked, by insurers

What leaves the site by default?

The signed hash roots (about 5 KB per day per camera) stream to the transparency log, and every sealed incident clip replicates to durable off-site storage so a stolen or failed recorder cannot erase your evidence. The full continuous record stays on-site unless you turn on the cloud retention tier. Inference always stays on the edge.

Who holds the signing keys?

Each device generates and holds its own key on first boot. Sitinel cannot sign on a device's behalf, and keys never leave the hardware.

What happens if a device is destroyed?

Historical signed roots are still in the public log, and any already-exported clips remain verifiable. Future captures after the incident obviously stop, but that itself is evidence.

Is this aligned with any existing standard?

The design follows the transparency-log and Merkle-proof patterns used by Certificate Transparency (TLS) and the software supply-chain log sigstore, and it is built to support authentication under FRE 902(13)/(14) via a written certification, aligned with ISO/IEC 27037 and SWGDE. It is a pedigree, not a promise of admissibility, which is always the court's call.

For insurers & adjusters

We'll get you a print-ready one-pager you can forward to carriers and counsel. Email insurers@sitinel.ai and we'll send it over.

Start a pilot →

Last updated · July 1, 2026