Built for digital chain of custody at institutional scale.
Institutions don't adopt apps — they adopt standards. Provena is infrastructure: policy-enforced capture, custody recorded as it happens, and verification open to any party, in any proceeding.
Policy is enforced, not suggested.
Every capture runs under rules the institution sets — resolved when the session is configured and enforced server-side, where they cannot be talked around.
- Organization-level capture policy — duration, screenshots, video, download volume, and watchers governed per organization; an unset value falls back to the default, never to unlimited.
- A controlled lifecycle — sessions move through enforced state transitions, each one leaving custody events; nothing skips a stage silently.
- Every access is part of the record — report views, downloads, and public checks are appended to the custody chain, building an institutional audit trail by default.
- Deletion is a workflow, not an erasure — controlled removal preserves the custody records of what occurred, including the deletion itself.
No trust in any vendor required.
A record an institution relies on cannot depend on the goodwill of the company that produced it. Every layer of a Provena record is checkable outside Provena — by the court, by either party, by an appointed expert.
- Verification without an account — any party to a proceeding can check a session or a file directly, with nothing to install and no content ever uploaded.
- Existence proven by third parties — the sealed record is registered with public networks and time-stamp authorities that hold their own copy of the proof.
- Audits run on standard tools — the package is a plain ZIP, the hashes are standard, and the chain re-verifies with scripts an expert runs on their own machine.
- Limits stated in the record itself — every report carries its scope statement and threat model, so institutional reliance is informed reliance.
Built to outlast the case — and the vendor.
Reports ship in an archival PDF format designed to open identically decades from now — fit for institutional records management.
Later review needs no original operator present: package, manifest, custody export, and external references answer on their own.
The record's elements — hashes, custody, external proofs — are technical facts, presentable within the rules of whatever forum reviews them.
Start with the methodology.
The document your technical reviewers will ask for first — how a record is made, and the limits we state before anyone asks.