Certification & Online Trace Collection · service active
WACZ · ISO 28500/ eIDAS timestamping/ Client area
C.E.R.T.O.
Sign in Register free
IT EN
C · E · R · T · O — Certification and Online Trace Collection

Freeze digital
evidence before
it disappears.

C.E.R.T.O. certifies web pages, files, email, chats and cloud content autonomously, without intermediaries and with full legal value.

Do-it-yourself forensic capture: you turn online content into a bundle that holds up in court — one even the opposing party can verify. Without calling in an expert.

Exhibit · EX-0007/26 Sealed
Source
https://example-target.it/post/9182
SHA-256
9f2a1c7b·4e0d·a83f·11c6·
5d7e9042bb1a3f88c0e4d2790a6f
Timestamp
2026-06-01T10:42:17Z · InfoCert TSA
Chain of custody
Valid<br>under<br>eIDAS
Hash MD5 · SHA-1 · SHA-256 · SHA-512 BagIt 1.0 · Ed25519 signature Double RFC 3161 timestamp Public offline verification
What we capture

Nine forensic acquisition modules.

C.E.R.T.O. acquires and seals nine kinds of digital content. Every acquisition produces a BagIt bundle signed with Ed25519, with a double RFC 3161 timestamp, a CASE/UCO description, a forensic report and 5-year archiving.

Chain of custody

The same chain of custody, whatever you capture.

How the content is captured changes from module to module, but from there every exhibit follows the exact same documented path — fingerprint, signature, timestamp, description and verification — without a single bit being altered.

01 · ACQUIRE

Acquisition

Forensic collection of the content and its origin metadata, using each module's specific method.

02 · HASH

Fingerprint

Computation of MD5, SHA-1, SHA-256 and SHA-512 hashes that uniquely identify each file.

03 · SIGN

Bundle & signature

BagIt 1.0 bundle signed with an Ed25519 key bound to the device identity.

04 · STAMP

Double timestamp

Double RFC 3161 timestamp — inner anchor and outer seal — with a free cascade and optional eIDAS InfoCert.

05 · VERIFY

Verification & preservation

CASE/UCO and offline verification by anyone; secure archiving for five years.

The evidence that can't be torn down

Verifiable even by the opposing party.

Anyone can dispute a screenshot: "you edited it", "that's not the real date". A C.E.R.T.O. bundle can't be. Together with the evidence you hand over a digital fingerprint (a code that changes if even a single bit is touched, so tampering becomes obvious) and a certified timestamp (the official, non-falsifiable date of the acquisition).

And the decisive point: the opposing party can run the verification itself, offline and without trusting you. The bundle is checked with open, standard tools (BagIt, CASE/UCO — the internationally recognized formats for digital exhibits). If the file is authentic, verification confirms it; if someone tampered with it, it shows. There's no arguing with data like that.

How a bundle is verified
WeakScreenshot or photoNo proof of date, integrity or origin. Disputable.
WeakPrintout or PDFCan be edited before saving: no technical seal.
C.E.R.T.O.C.E.R.T.O. bundleFingerprint + timestamp + chain of custody.
C.E.R.T.O.Verifiable by the opposing partyOffline re-check of the bundle, with no need to trust you.
C.E.R.T.O.International standardsBagIt, CASE/UCO, RFC 3161: open, recognized formats.
Forensic desktop application

C.E.R.T.O.

Collecting online evidence with C.E.R.T.O. is easy and secure, because:

  • you collect everything from a single app for Windows and macOS, with 9 acquisition modules ready to use;
  • no external tools are needed: a built-in browser and HD video recording are already on board;
  • every exhibit is sealed and time-stamped: a BagIt bundle signed with Ed25519, a double RFC 3161 timestamp and CASE/UCO;
  • anyone can verify it, offline and independently, without having to trust us.
Register free
C.E.R.T.O. dashboard — acquisition module selection
Who uses C.E.R.T.O.

Digital evidence for those who can't get it wrong.

Professionals across sectors use C.E.R.T.O. to acquire legally valid digital evidence.

Legal sector

C.E.R.T.O. Desktop
  • Evidence for civil litigation
  • Copyright infringement documentation
  • Online defamation capture
  • Forensic preservation of web content

Cybersecurity

C.E.R.T.O. Desktop
  • Capture of phishing pages and fraudulent sites
  • Documentation of data breaches and exposed credentials
  • Acquisition of leaks and data published online
  • Capture of defacements and compromised content

Corporate compliance

C.E.R.T.O. Desktop
  • Audit and compliance monitoring
  • Competitor analysis
  • Brand protection
  • Digital due diligence

Private investigations

C.E.R.T.O. Desktop
  • OSINT and social media monitoring
  • Background checks
  • Fraud investigation
  • Online asset tracing

Journalism & media

C.E.R.T.O. Desktop
  • Verification and archiving of online sources
  • Capturing content before it is removed
  • OSINT documentation for investigations
  • Defensive evidence in case of lawsuits

Human resources

C.E.R.T.O. Desktop
  • Evidence for disciplinary proceedings
  • Capture of employees' online conduct
  • Documentation of defamation against the company
  • Reputational checks on candidates

Creators & intellectual property

C.E.R.T.O. Desktop
  • Proof of authorship and publication date
  • Documentation of plagiarism and stolen content
  • Capture of unauthorized trademark use
  • Monitoring of online counterfeiting

Insurance & debt recovery

C.E.R.T.O. Desktop
  • Documentation of online insurance fraud
  • Capture of social-media evidence to support claims
  • Asset tracing and the debtor's online holdings
  • Verification of listings and commercial activity
9
Forensic acquisition modules
3
Starting price per slot
5 yrs
Archiving with public verification
0
Subscriptions — slots never expire
Frequently asked questions

The questions we get asked first.

Is a screenshot valid as evidence in court?

On its own, no: it is an easily edited image with no certified date and no technical context, and the opposing party can challenge it without much effort. C.E.R.T.O. instead produces a BagIt bundle signed with an Ed25519 key, with a double RFC 3161 timestamp and the content's hash fingerprint: if even a single bit is altered, tampering becomes demonstrable.

Do I need a forensic expert to acquire digital evidence?

No. C.E.R.T.O. is designed to be used independently by lawyers, companies and private individuals: the acquisition follows a documented forensic procedure with no need for a technical consultant. An expert remains useful when the opposing party challenges the technical merits of the evidence.

How do I preserve a web page before it is deleted?

By acquiring it into a WACZ archive (ISO 28500 standard), which freezes the page, the navigation video, the screenshots and the HTTP traffic. Even if the original content is removed or changed, the bundle stays intact and can be verified by anyone.

How much does it cost to acquire digital evidence?

You buy packs of slots: one slot equals one complete acquisition, whatever the size of the content. Prices range from €6 per slot (pack of 5) down to €3 per slot (pack of 1,000), VAT excluded. There is no subscription and slots never expire.

Can the opposing party verify the evidence I produced?

Yes, and that is the whole point. Every bundle includes a public verification that also works offline: the judge or the opposing expert can recompute the hashes and check the signature and timestamps independently, without C.E.R.T.O. and without an internet connection.

What is the difference between the included timestamp and the InfoCert one?

The double RFC 3161 timestamp included in every acquisition certifies the bundle's date and is free of charge. The optional qualified InfoCert timestamp is issued by a qualified trust service provider and carries the reinforced evidentiary effect granted by the European eIDAS regulation.

Can a WhatsApp chat be acquired forensically?

Yes. The WhatsApp module captures conversations, media and metadata with a session recording and a cryptographic seal, so the captured content is tied to a precise moment and cannot be altered. An equivalent module exists for Telegram (channels, groups and chats).

What happens if the online content is deleted after the acquisition?

Nothing: the bundle is self-contained and remains valid even if the original disappears — which is precisely why you acquire it. Every bundle is also kept for 5 years with public verification, at no cost beyond the slot.

What format are the bundles produced in?

BagIt 1.0 (RFC 8493) with a CASE/UCO description, MD5, SHA-1, SHA-256 and SHA-512 hashes, an Ed25519 signature and a double RFC 3161 timestamp. These are open standards: the bundle can be opened and verified with third-party tools, without depending on us.

What can you acquire with C.E.R.T.O.?

Nine content types: web pages, remote files, email and certified mail, images, screen captures, FTP/SFTP, cloud (Google Drive, Dropbox, OneDrive, iCloud), WhatsApp and Telegram. Every module produces the same kind of signed and time-stamped bundle.

What is the difference between C.E.R.T.O. and LOCUS?

C.E.R.T.O. is the desktop app and acquires content that lives online (web pages, email, chats, cloud). LOCUS is the mobile app and captures what happens in front of you (photos, video and audio with location and a certified date). Slots are shared: the same account uses them on both.

Can email and certified mail be certified?

Yes. The Email module connects to the mailbox over IMAP and preserves the full EML source, checking DKIM, SPF and DMARC and analysing the delivery hops: this documents not only the message content but also where it really came from.

Which operating systems does C.E.R.T.O. run on?

On Windows (x64) and macOS (Apple Silicon). Downloads are reserved for registered users and registration is free: your private area contains the packages for both platforms and the API key that activates the app on first launch.

Which standards does C.E.R.T.O. follow?

ISO/IEC 27037 for handling digital evidence, BagIt 1.0 (RFC 8493) for the bundle, RFC 3161 for the timestamp, Ed25519 (RFC 8032) for the signature, CASE/UCO for describing the exhibit and WACZ/ISO 28500 for web archives. These are open, documented standards, not proprietary formats.

How do you verify a bundle without having C.E.R.T.O.?

Every bundle contains the verify.sh and verify.bat scripts and an interactive dashboard: they recompute the hashes of every file, check the Ed25519 signature and the two RFC 3161 timestamps and state whether the bundle is valid. The timestamp authorities' certificates are included in the bundle, so verification also works with no internet connection.

How is the acquisition's date and time guaranteed to be correct?

The computer's clock is not trusted. During the acquisition C.E.R.T.O. queries three independent NTP servers and records their consensus (median and deviation), and the bundle's date is in any case set by an RFC 3161 timestamp issued by a third-party authority: neither the person acquiring nor we can alter it.

How do you prove which tool performed the acquisition?

The report includes a tool attestation block: the MD5, SHA-256 and SHA-512 hashes of the application binary that performed the acquisition, and the versions of the components used. The block is sealed together with the rest, so it verifiably documents what the evidence was produced with.

What if the site is protected by Cloudflare or an anti-bot system?

The acquisition still succeeds: C.E.R.T.O. recognises the protection system, clears the challenge using a real browser and — crucially — states so in the report. The fact that the content sat behind an anti-bot protection is documented, not hidden.

Can I acquire a Gmail or Microsoft 365 mailbox?

Yes. For Microsoft 365 and Outlook the connection uses OAuth2, so you authorise access without handing over your password. For other providers an app password is used. In both cases the messages are preserved in their full EML source.

Can I use C.E.R.T.O. from more than one computer?

Yes. The acquisition register and your slot balance are synchronised on the server and tied to the account, not to a single machine: you can install the app on another computer and find everything there.

What exactly does a bundle contain?

It depends on the module, but always: the acquired content, the hash inventory of every file, the forensic report in PDF, an interactive dashboard to explore the exhibit, the acquisition log, the CASE/UCO description, the timestamps and the verification scripts. For the web there are also the replayable WACZ archive, the screenshots, the session video, the HTTP traffic and the TLS certificates.

Ready to start

Get started with C.E.R.T.O.

Download the app and acquire your first digital evidence in minutes. No subscription, no expiry — you only pay for the slots you use.