Platform

Controlled digital evidence capture for teams that need more than screenshots.

Provena helps organizations capture online activity in a controlled remote browser, preserve the resulting evidence with cryptographic integrity references, organize it into a structured package, and generate reports designed for legal, compliance, audit, investigative, and technical review.

01 · Capture

Controlled capture

The session runs in a dedicated remote browser operated by Provena — not on your machine, and not in your everyday browser. That difference is what separates controlled capture from a browsing session that happened to be recorded.

  • A locked-down interaction policy, enforced server-side: system shortcuts, developer tools, and the context menu are refused, and navigation is restricted to http and https.
  • A single-use worker per session, destroyed afterwards — isolation by disposal, not by cleanup.
  • Viewport and full-page screenshots with a provenance mark rendered into the pixels: the Provena label, capture timestamp, and session identifier travel inside the image itself.
  • Video recording with full technical metadata — resolution, frame rate, duration, codecs — plus navigation aids for later review.
  • Downloads preserved as evidence through a controlled acceptance path, with organization-level limits enforced at the runtime.
  • Server identity captured per origin: TLS certificate, IP address, DNS records, and fingerprints.
  • Watch mode — an invited witness can observe the live session without controlling it.
Explore controlled capture →
02 · Integrity

Integrity & chain of custody

Every file is fingerprinted, every step is recorded — as the work happens, not reconstructed later. The custody chain is implemented, not asserted: modification, deletion, reordering, and insertion are all detectable on verification.

  • SHA-512 as the canonical hash, with SHA-256 and SHA3-512 as supplementary references from different hash families.
  • Transfer integrity: files are hashed at origin, re-hashed at destination, and stored only when the values match.
  • A hash-linked custody chain — each event carries its own hash and the hash of the previous event, across setup, capture, processing, access, and retention.
  • A structured evidence package (a plain ZIP file) with a manifest inventory listing every file, its path, size, and hash.
  • Two distinct seals: the package seal fixes the evidence set; the custody seal fixes the recorded chain itself.
  • An access trail: report views, package downloads, and public checks become custody events after sealing.
Explore integrity & custody →
03 · Proofs

External proofs

The package hash and the custody seal are registered with independent external providers — creating proof of existence that stands on its own, even without trusting Provena. Only hashes are registered; evidence content never leaves the platform.

  • Public blockchain networks: Solana, Hedera, and Algorand, with entries that can be checked on any public explorer.
  • OpenTimestamps with Bitcoin attestation, producing portable .ots proof artifacts.
  • RFC 3161 timestamp authorities such as Sectigo and DigiCert — signed, dated tokens from regulated third parties.
  • Independent families corroborating the same value: different systems fail in different ways, and multiple confirmed sources strengthen the record.
Explore external proofs →
04 · Review

Reports & analysis

The same canonical record, readable by three different audiences — and equipped with the analysis tools reviewers actually use.

  • An online report plus a PDF/A-2B export (ISO 19005-2), the archival format designed for long-term readability.
  • Three reading modes — Essential, Legal, Technical — adjusting depth and timestamp presentation without changing the underlying record.
  • A custody analyzer with six views — table, timeline, sequence, flow, mindmap, and verifier — for inspecting the chain in depth.
  • A frame-by-frame video timeline with chapters, frame export, and A/B loop; screenshot comparison with side-by-side, slider, and pixel-difference analysis.
  • Legal support material: suggested filing language, an attachment checklist, and Word export.
  • Every report ships with its own methodology, threat model, audit instructions, and glossary.
Explore reports & analysis →
05 · Verification

Independent verification

Verification that does not require trusting Provena — or even having an account.

  • A public check for sessions and files, open to anyone who receives Provena material.
  • Private-by-design file verification: the hash is computed locally in the reviewer's browser, and the file content is never uploaded.
  • In-browser custody verification that recomputes every event hash and checks the chain's links live.
  • Canonical custody export and audit scripts for fully offline verification with standard tools.
Explore independent verification →
Evidence

What a session preserves.

Screenshots
Static visual captures of the browser state, with the provenance mark in the pixels.
Videos
Time-based recordings preserving motion, sequence, and procedural flow.
Files
Standalone files obtained during the session — source material preserved with the session that produced it.
Page snapshots
One image plus saved HTML per unique page visited — a navigation catalogue supporting the primary evidence.
Technical logs
Structured session, network, and domain records supporting audit and reconstruction.
Server identity
TLS certificate, IP, and DNS data observed during capture, for reviewing the remote origin.
Evidence package
The consolidated set — every preserved file plus the manifest inventory — sealed as one unit.
Custody chain
The hash-linked sequence of events documenting capture, transfer, storage, access, proof, and retention.
Lifecycle

From session to sealed record.

  1. 01 The session is created with its context: label, initial URL, resolution, locale, and timezone.
  2. 02 A dedicated remote worker is allocated — and the custody chain starts recording.
  3. 03 The operator works: screenshots, video, downloads, page snapshots, and logs are generated as evidence.
  4. 04 Every file is hashed at origin and verified again at storage before it is accepted.
  5. 05 The package is consolidated with its manifest and sealed; after teardown, the custody chain itself is sealed.
  6. 06 The package hash and custody seal are registered with independent external-proof providers.
  7. 07 The report is available for review — and the record is open to public and offline verification from then on.
Transparency

Every capability, documented.

What the platform preserves, what reviewers can verify independently, what depends on external systems — and what Provena does not claim. It's all written down.

Read our methodology →

See the platform working.

The fastest way to evaluate Provena is a real session and a real report.

Talk to us See a sample report