No. 01 / 03VaultKeeperv1.2.0 · AGPL-3.0Go-to-market

The evidence locker no foreign government can shut off.

AGPL-3.0 open sourceSelf-host in 15 minAir-gap compatibleZero telemetry

Open-source, self-hosted evidence management for international courts, tribunals, and human rights investigators. Chain of custody that holds up in court.

§ 01 — Chain of custody

Custody that holds up in court.

Each custody event is hash-chained to the one before it. Seizure, analysis, seal, disclosure, redaction, court — if any link breaks, the record says so.

Case file · illustrativeDEMO-2026-014

Drone footage, sector 4

Evidence · 00:04:12 · 218 MB
Sealed

Witness W-0144 testimony

Protected · pseudonymised
Sealed

Banking trail

3,842 records · legal hold
Hold

Forensic image SM-S911

128 GB · SHA-256 verified
Sealed
Seizure
Analysis
Seal
Disclosure
Redaction
Court
Verifying…
§ 02 — What we replace

Built for work that cannot be paused by a sanction.

Legacy e-discovery tools run on clouds your jurisdiction doesn't control. A political shift abroad should not end a war-crimes investigation in The Hague.

01

Sovereign by default

Self-host on any infrastructure. Zero telemetry, zero outbound calls, air-gap compatible. No vendor lock-in.

02

Provably append-only

Every custody event is hash-chained. PostgreSQL RLS refuses UPDATEs and DELETEs — even from superusers.

03

Witness-safe

AES-256-GCM encryption of witness PII. Defence sees pseudonyms. Duress passphrases produce decoy vaults.

04

Open source, always

AGPL-3.0. Read the code, audit the crypto, fork if you have to. Evidence survives the company.

§ 03 — How it works

Seizure to sentence, every link signed.

Four phases, each cryptographically bound to the next.

Phase 01

Ingest

Chunked resumable uploads, client-side SHA-256, RFC 3161 timestamping. If a byte is off, the upload fails with a 409.

Phase 02

Seal

Append-only custody log. Each row hash-chains the previous. PostgreSQL RLS refuses UPDATEs — even from superusers.

Phase 03

Work

Real-time CRDT collaboration, redaction editor, witness linking, corroboration scoring — all on the sealed chain.

Phase 04

Export

One-click ZIP with evidence, custody log, and hash manifest. Court clerks verify with our open validator.

§ 04 — Use cases

Three cases, one chain.

Scenario 01 — Field documentation

An NGO preserves footage from a conflict zone.

  1. Upload over unreliable links with resumable chunks
  2. Hash on the device before it leaves
  3. Timestamp under RFC 3161
  4. Seal into the custody log
Scenario 02 — Protected testimony

A tribunal links witness statements without exposing identities.

  1. Encrypt witness PII at rest
  2. Defence works with pseudonyms only
  3. Redact collaboratively on the sealed record
  4. Duress passphrase opens a decoy vault
Scenario 03 — Disclosure

Prosecution hands evidence to defence and the court.

  1. Export evidence, custody log, and hash manifest
  2. Share as one ZIP
  3. Clerk runs the open validator
  4. Integrity confirmed without VaultKeeper
§ 05 — Tech & architecture

Every layer self-hosted.

Written in Rust and TypeScript. Runs on your own servers, on-prem, or fully air-gapped.

IngestChunked uploadsClient-side SHA-256RFC 3161

Files are hashed before they leave the client. A mismatched byte rejects the upload with a 409.

Custody logPostgreSQLRow-level securityHash chain

Append-only at the database level. Each row hash-chains the previous; UPDATE and DELETE are refused, even for superusers.

WorkspaceCRDTRedaction editorCorroboration

Real-time collaboration, redaction, witness linking, and corroboration scoring on top of the sealed chain.

On-prem AIWhisperOCRTranslation

Transcription, text extraction, and translation run locally. Nothing leaves the box.

FederationVKE1Protobuf

The VaultKeeper Evidence Exchange spec defines cryptographic evidence sharing between institutions.

Verificationclerk-validatorRust

A standalone tool that lets court clerks verify integrity without running VaultKeeper.

§ 06 — Security & compliance

Designed for hostile conditions.

01

Tamper-evident by construction

Hash-chained custody events and database-enforced append-only logs. There is no admin backdoor.

02

Witness protection

AES-256-GCM encryption of witness PII, pseudonymised views for defence, and duress passphrases that open decoy vaults.

03

No outbound traffic

Zero telemetry and zero outbound calls. Air-gap compatible, with AI processing kept on-prem.

04

Berkeley Protocol

Built to the Berkeley Protocol on Digital Open Source Investigations for handling digital evidence.

05

Auditable code

AGPL-3.0. Anyone can read the custody engine and verify the cryptography.

06

Responsible disclosure

Report to [email protected]. Acknowledged within 24 hours, with a 90-day disclosure timeline.

§ 07 — Built for

Institutions that cannot afford to lose a case.

International tribunals

ICC, ad-hoc tribunals, hybrid courts. Complex multi-jurisdictional cases with strict admissibility requirements.

Human rights investigators

Open-source investigators and documentation groups. Documenting violations, preserving digital evidence under hostile conditions.

Legal teams

Defence and prosecution handling sensitive material where chain of custody is legally critical. First-class defence counsel support.

Truth commissions

Transitional justice bodies managing testimony archives, victim statements, and historical documentation across decades.

§ 08 — The shift

Sovereign and open, or cloud-locked.

VaultKeeper · Sovereign · OpenLegacy · Proprietary · Cloud-locked
Self-hosted on any infrastructure — cloud, on-prem, air-gappedForeign-cloud hosting. One sanctions action and you're locked out.
DB-level append-only logs with hash chaining; no admin backdoorAdmin-modifiable audit logs that defence counsel challenge.
Cryptographic federation for cross-tribunal evidence exchangeFile-export "federation" — no cryptographic guarantees.
On-prem AI — Whisper, OCR, translation. Nothing leaves the boxCloud AI. Witness statements through whoever owns the GPU.
AGPL-3.0. Read the source. Fork it. Verify the custody engine.Proprietary. You cannot audit the custody engine.
§ 09 — Integrations

Open formats in and out.

01

Court export

ZIP with evidence, custody log, and hash manifest.

02

VKE1 federation

Cryptographic exchange between institutions running VaultKeeper.

03

Open validator

Independent integrity checks for clerks and defence.

04

Any infrastructure

Your servers, on-prem, or air-gapped.

§ 10 — Status

Where it stands.

v1.2.0Sealed evidence escrow shipping
2026Go-to-market: institutional demos and pilot deployments in The Hague
DraftVKE1 evidence exchange specification
§ 11 — FAQ
How long does deployment take?+

A typical NGO is live in 15 minutes on its own server. A full tribunal migration takes six weeks.

Can we run it without internet access?+

Yes. VaultKeeper is air-gap compatible, makes no outbound calls, and runs transcription, OCR, and translation locally.

How does defence counsel verify evidence?+

Every export includes the custody log and a hash manifest. The open clerk-validator checks integrity without needing access to VaultKeeper.

Who can change the custody log?+

No one. The log is append-only at the database level, and each entry is hash-chained to the previous one. Row-level security refuses updates and deletes, including from superusers.

What happens if Trelvio stops existing?+

The code is AGPL-3.0. Institutions can fork it, hire a maintainer, and keep running their own instance. Evidence survives the company.

§ 12 — Pilot

Run a pilot this quarter.

A typical NGO is live in 15 minutes on their own server. A full tribunal migration takes six weeks.