EvidenceVaultEvidenceVault
Sign inRequest a pilot →
Product

Built for evidence that has to be perfect when you ask for it back.

EvidenceVault is the long-term cold-storage layer purpose-built for digital forensic evidence. Every feature exists to make the chain of custody self-evident — to investigators, auditors, the courts, and your organisation.

Customer-controlled keys

Customer-managed key in your tenant's own Azure Key Vault. Disable the key from your portal and the operator cannot decrypt — verifiable in under a minute, every time.

Mathematical immutability

Sealed evidence is written to version-level WORM blob storage with double encryption (CMK on top of platform key). Mutation is technically impossible, not just policy-blocked.

Hash-chained audit log

Every action carries SHA-256(prev || row). Tamper any single row and every link after it breaks. The Verify Integrity button on /audit recomputes the chain in milliseconds and pinpoints any divergence.

Three-tier lifecycle

Cool → Cold at 30 days, Cold → Archive at 90 days — defaults your organisation can change from the portal, along with the offence-category policy that sets per-blob retention. Lifecycle runs in Azure Storage; nothing to schedule, nothing to forget.

Reason-coded retrieval

Retrievals require a typed reason and Inspector approval. SLA computed from urgency tier; every read is logged against the case. Drift on hash recompute auto-quarantines to a separate WORM container.

Separation of duties

Your officers and our operators sign in to completely separate systems — different addresses, different code, no shared session. Our staff can see that your tenant is running and healthy; they cannot list, open or download a single exhibit. The separation is built into the software rather than promised in a policy.

Storage

Three ways to hold the storage.

Where your evidence physically sits is a decision you make with us when the service is commissioned. Whichever you choose, the encryption key stays yours and we have no way to read what you store.

We provide the storage

The simplest way to start. We hold the storage account; you hold the encryption key. Nothing for your IT team to set up.

Billing. Microsoft's storage and download charges are passed on to you at cost, itemised.
You provide the storage

The storage account is yours, in your organisation's own Azure subscription. You keep custody of the account as well as the key.

Billing. Storage is billed to you by Microsoft under your organisation's existing enterprise agreement, at the rates you have already negotiated. You pay us a platform fee on top.
You provide the storage, on a private connection

As above, and the platform reaches your storage over a private link inside Microsoft's network rather than the public internet. For organisations that need the boundary enforced by the network itself. Arranged during commissioning — it needs a short piece of design with your IT team.

Billing. Storage on your enterprise agreement as above; the platform fee is agreed per customer.
Detailed control mappings, threat model, and accreditations are in the security & sovereignty brief.
Run a 90-day pilot for your organisation.
Dedicated UK-region tenant. Three named users. No commercial commitment.
Request a pilot →