EvidenceVault is the long-term cold-storage layer purpose-built for digital forensic evidence. Every feature exists to make the chain of custody self-evident — to investigators, auditors, the courts, and your organisation.
Customer-managed key in your tenant's own Azure Key Vault. Disable the key from your portal and the operator cannot decrypt — verifiable in under a minute, every time.
Sealed evidence is written to version-level WORM blob storage with double encryption (CMK on top of platform key). Mutation is technically impossible, not just policy-blocked.
Every action carries SHA-256(prev || row). Tamper any single row and every link after it breaks. The Verify Integrity button on /audit recomputes the chain in milliseconds and pinpoints any divergence.
Cool → Cold at 30 days, Cold → Archive at 90 days — defaults your organisation can change from the portal, along with the offence-category policy that sets per-blob retention. Lifecycle runs in Azure Storage; nothing to schedule, nothing to forget.
Retrievals require a typed reason and Inspector approval. SLA computed from urgency tier; every read is logged against the case. Drift on hash recompute auto-quarantines to a separate WORM container.
Your officers and our operators sign in to completely separate systems — different addresses, different code, no shared session. Our staff can see that your tenant is running and healthy; they cannot list, open or download a single exhibit. The separation is built into the software rather than promised in a policy.
Where your evidence physically sits is a decision you make with us when the service is commissioned. Whichever you choose, the encryption key stays yours and we have no way to read what you store.
The simplest way to start. We hold the storage account; you hold the encryption key. Nothing for your IT team to set up.
The storage account is yours, in your organisation's own Azure subscription. You keep custody of the account as well as the key.
As above, and the platform reaches your storage over a private link inside Microsoft's network rather than the public internet. For organisations that need the boundary enforced by the network itself. Arranged during commissioning — it needs a short piece of design with your IT team.