C.E.R.T.O. certifies web pages, files, email, chats and cloud content autonomously, without intermediaries and with full legal value.
Do-it-yourself forensic capture: you turn online content into a bundle that holds up in court — one even the opposing party can verify. Without calling in an expert.
C.E.R.T.O. acquires and seals nine kinds of digital content. Every acquisition produces a BagIt bundle signed with Ed25519, with a double RFC 3161 timestamp, a CASE/UCO description, a forensic report and 5-year archiving.
How the content is captured changes from module to module, but from there every exhibit follows the exact same documented path — fingerprint, signature, timestamp, description and verification — without a single bit being altered.
Forensic collection of the content and its origin metadata, using each module's specific method.
Computation of MD5, SHA-1, SHA-256 and SHA-512 hashes that uniquely identify each file.
BagIt 1.0 bundle signed with an Ed25519 key bound to the device identity.
Double RFC 3161 timestamp — inner anchor and outer seal — with a free cascade and optional eIDAS InfoCert.
CASE/UCO and offline verification by anyone; secure archiving for five years.
Anyone can dispute a screenshot: "you edited it", "that's not the real date". A C.E.R.T.O. bundle can't be. Together with the evidence you hand over a digital fingerprint (a code that changes if even a single bit is touched, so tampering becomes obvious) and a certified timestamp (the official, non-falsifiable date of the acquisition).
And the decisive point: the opposing party can run the verification itself, offline and without trusting you. The bundle is checked with open, standard tools (BagIt, CASE/UCO — the internationally recognized formats for digital exhibits). If the file is authentic, verification confirms it; if someone tampered with it, it shows. There's no arguing with data like that.
How a bundle is verifiedCollecting online evidence with C.E.R.T.O. is easy and secure, because:
Professionals across sectors use C.E.R.T.O. to acquire legally valid digital evidence.
On its own, no: it is an easily edited image with no certified date and no technical context, and the opposing party can challenge it without much effort. C.E.R.T.O. instead produces a BagIt bundle signed with an Ed25519 key, with a double RFC 3161 timestamp and the content's hash fingerprint: if even a single bit is altered, tampering becomes demonstrable.
No. C.E.R.T.O. is designed to be used independently by lawyers, companies and private individuals: the acquisition follows a documented forensic procedure with no need for a technical consultant. An expert remains useful when the opposing party challenges the technical merits of the evidence.
By acquiring it into a WACZ archive (ISO 28500 standard), which freezes the page, the navigation video, the screenshots and the HTTP traffic. Even if the original content is removed or changed, the bundle stays intact and can be verified by anyone.
You buy packs of slots: one slot equals one complete acquisition, whatever the size of the content. Prices range from €6 per slot (pack of 5) down to €3 per slot (pack of 1,000), VAT excluded. There is no subscription and slots never expire.
Yes, and that is the whole point. Every bundle includes a public verification that also works offline: the judge or the opposing expert can recompute the hashes and check the signature and timestamps independently, without C.E.R.T.O. and without an internet connection.
The double RFC 3161 timestamp included in every acquisition certifies the bundle's date and is free of charge. The optional qualified InfoCert timestamp is issued by a qualified trust service provider and carries the reinforced evidentiary effect granted by the European eIDAS regulation.
Yes. The WhatsApp module captures conversations, media and metadata with a session recording and a cryptographic seal, so the captured content is tied to a precise moment and cannot be altered. An equivalent module exists for Telegram (channels, groups and chats).
Nothing: the bundle is self-contained and remains valid even if the original disappears — which is precisely why you acquire it. Every bundle is also kept for 5 years with public verification, at no cost beyond the slot.
BagIt 1.0 (RFC 8493) with a CASE/UCO description, MD5, SHA-1, SHA-256 and SHA-512 hashes, an Ed25519 signature and a double RFC 3161 timestamp. These are open standards: the bundle can be opened and verified with third-party tools, without depending on us.
Nine content types: web pages, remote files, email and certified mail, images, screen captures, FTP/SFTP, cloud (Google Drive, Dropbox, OneDrive, iCloud), WhatsApp and Telegram. Every module produces the same kind of signed and time-stamped bundle.
C.E.R.T.O. is the desktop app and acquires content that lives online (web pages, email, chats, cloud). LOCUS is the mobile app and captures what happens in front of you (photos, video and audio with location and a certified date). Slots are shared: the same account uses them on both.
Yes. The Email module connects to the mailbox over IMAP and preserves the full EML source, checking DKIM, SPF and DMARC and analysing the delivery hops: this documents not only the message content but also where it really came from.
On Windows (x64) and macOS (Apple Silicon). Downloads are reserved for registered users and registration is free: your private area contains the packages for both platforms and the API key that activates the app on first launch.
ISO/IEC 27037 for handling digital evidence, BagIt 1.0 (RFC 8493) for the bundle, RFC 3161 for the timestamp, Ed25519 (RFC 8032) for the signature, CASE/UCO for describing the exhibit and WACZ/ISO 28500 for web archives. These are open, documented standards, not proprietary formats.
Every bundle contains the verify.sh and verify.bat scripts and an interactive dashboard: they recompute the hashes of every file, check the Ed25519 signature and the two RFC 3161 timestamps and state whether the bundle is valid. The timestamp authorities' certificates are included in the bundle, so verification also works with no internet connection.
The computer's clock is not trusted. During the acquisition C.E.R.T.O. queries three independent NTP servers and records their consensus (median and deviation), and the bundle's date is in any case set by an RFC 3161 timestamp issued by a third-party authority: neither the person acquiring nor we can alter it.
The report includes a tool attestation block: the MD5, SHA-256 and SHA-512 hashes of the application binary that performed the acquisition, and the versions of the components used. The block is sealed together with the rest, so it verifiably documents what the evidence was produced with.
The acquisition still succeeds: C.E.R.T.O. recognises the protection system, clears the challenge using a real browser and — crucially — states so in the report. The fact that the content sat behind an anti-bot protection is documented, not hidden.
Yes. For Microsoft 365 and Outlook the connection uses OAuth2, so you authorise access without handing over your password. For other providers an app password is used. In both cases the messages are preserved in their full EML source.
Yes. The acquisition register and your slot balance are synchronised on the server and tied to the account, not to a single machine: you can install the app on another computer and find everything there.
It depends on the module, but always: the acquired content, the hash inventory of every file, the forensic report in PDF, an interactive dashboard to explore the exhibit, the acquisition log, the CASE/UCO description, the timestamps and the verification scripts. For the web there are also the replayable WACZ archive, the screenshots, the session video, the HTTP traffic and the TLS certificates.
Download the app and acquire your first digital evidence in minutes. No subscription, no expiry — you only pay for the slots you use.