How this platform works

Every project on this site runs the same open-source evidence kit. This page explains what it does with your data — honestly, including the parts it doesn't do well yet.

What happens to a submission

  1. Sealed in your browser. Before anything leaves your machine, your answers are encrypted to a public key using libsodium's sealed-box encryption. The server never sees plaintext.
  2. Stored as ciphertext. Cloudflare KV/R2 holds only sealed blobs. A database dump, a subpoena to the hosting provider, or a rogue admin exposes ciphertext.
  3. Hashed and anchored. Records are merkle-hashed and timestamped so anyone can later prove what existed and when — without trusting the operators.
  4. You keep a receipt. An unguessable id shown once at submit time. It is your only credential to check, change consent, or delete your submission.

Who can read your submission

StateWho can read it
Today — interim epochThe incident operator only, using a locally-held key. There is no server-side decryption.
After representative electionk-of-n elected representatives, in a logged key ceremony. The operator's unilateral key is shredded; no single person can open submissions alone.
Sealed-private consentNo one. Not the operator, not the representatives, not by unanimous vote. You can release it later if you choose.
RevokedDeleted from all hosted storage — record, files, escrow, public listing — replaced by a content-free tombstone. Already-decrypted organizer copies are excluded from exports.

Current state: interim epoch — the election has not happened yet. This page will update when representatives are seated.

Why not just use…

Honest answers, including where the alternatives genuinely win:

ToolThe gapWhere they win
Google FormsNo encryption, no custody — Google sees everything, and so does a subpoena to them.Zero setup, everyone knows it.
SecureDrop / GlobaLeaksAnonymous tips, not claims — no amounts, ledger, consent lifecycle, or wallet binding.Tor-grade anonymity we don't match.
Stretto / Kroll / EpiqCourt-appointed claims administrators — they only exist after litigation or insolvency begins.Court-recognized scale; we hand them the register when they arrive.
Chainalysis / TRM / ArkhamEnterprise forensics for investigators — priced for governments, not claimants.Attribution depth nobody else has.
Page Vault / MirrorWebSnapshots of pages — they can't see a backend silently editing its own terms, and they don't intake claims.Human affidavits courts recognize.
Harvey / CoCounselLegal AI for law firms — cloud-only, enterprise-priced, attorney-side. Your data would leave the community.Westlaw/Lexis-grounded research depth.
Filevine / SimplyConvertFirm-side plaintiff pipelines — the firm owns claimant data, not the community.Polished intake UX at law-firm scale.
changedetection.io / VisualpingChange alerts — a notification isn't evidence. No custody chain, no claims context.Cheap, mature alerting at scale.

The one-line position: forms lose custody, tip tools don't do claims, claims administrators show up after it's decided, forensics serves investigators, legal AI serves firms — and none of them let a third party verify everything without trusting the operator.

What this does not do

Verify, don't trust

The claims above are checkable, not just asserted: verify a proof of any submission receipt in your browser — the merkle path and timestamps resolve offline. The full comparison against every adjacent tool lives in the open-source repo (docs/COMPETITORS.md).