EvidenceVaultEvidenceVaultSecurity & sovereignty brief
← BackSign inRequest a pilot
Document v1.4·Audience: DFU heads & Force IT security·Published April 2026

How EvidenceVault keeps your evidence secure, sovereign, and unaltered.

A plain-English engineering brief for Heads of Digital Forensic Units, Force CTOs and accreditation teams. It covers data residency, personnel vetting, encryption, immutability, audit, and the contractual commitments that back all of the above.

OFFICIAL — for circulation within UK police forces
SECTION 1

Executive summary

EvidenceVault is a long-term, immutable storage platform for closed-case digital forensic evidence, built and operated in the United Kingdom by EvidenceVault. It is designed around one core promise: the evidence you put in today is provably the same evidence you retrieve in seven, ten or twenty years' time.

Three commitments make that promise hold:

  • Azure UK South only. All bytes — primary, backup, and metadata — live in the Azure UK South (London) region, zone-redundant across three availability zones. No replication to UK West, no replication overseas. Ever.
  • UK-cleared personnel only. Every engineer with production access holds active SC clearance and NPPV3 force vetting. There is no offshore support.
  • Mathematical immutability. Sealed items are stored on write-once blob storage with customer-managed encryption keys. Mutation is not policy-blocked — it is technically impossible.
SECTION 2

Data sovereignty

EvidenceVault runs entirely on Microsoft Azure UK regions. The platform topology is:

Region
UK South (London) — sole region for production, ingest, application services and audit log
Storage redundancy
ZRS — Zone-Redundant Storage, three availability zones inside UK South
Cross-region replication
None. No replication to UK West or any other region. Egress to non-UK-South Azure regions is policy-blocked.
Audit log archive
UK South with locally-redundant immutable blob storage
Customer support tooling
UK-based ticketing & PSN-connected admin workstations only

Single-region operation is a deliberate sovereignty decision, not a cost compromise.

i
No data egress to non-UK destinations. The platform's network egress controls block outbound traffic to all non-UK Azure regions and to all non-UK third-party services.
SECTION 3

Personnel & vetting

We recognise that for a UK police force, who has hands on the production environment matters as much as how the environment is built. EvidenceVault is operated by a small UK team under the following non-negotiable rules:

  • Production access requires both SC clearance and NPPV3. No exceptions, no temporary uplift accounts, no contractor bypass.
  • No offshore engineering. All design, development, operations and customer support are performed by UK-resident, UK-cleared personnel.
  • No production access for sales, marketing or commercial staff.
  • Annual re-vetting with mandatory disclosure of any change in clearance status.
SECTION 4

Encryption & key management

At rest
AES-256-GCM envelope encryption on every blob
In transit
TLS 1.3 only, with FS-only cipher suites
Key custody
Customer-managed keys (CMK) in your force's Azure Key Vault
Key rotation
Annual at minimum; on-demand via your tenant admin console
HSM backing
FIPS 140-2 Level 3 HSM available on request (Azure Premium Key Vault)
!
EvidenceVault cannot decrypt your evidence. Customer-managed keys are held in your tenant's Key Vault, under your force's RBAC. EvidenceVault holds no escrow copy. We have no master key.
SECTION 5

Immutability & integrity

Sealed evidence is written to Azure Blob Storage with immutability policies applied at the container level — specifically, a time-based legal hold tied to the item's retention schedule.

Integrity is verified continuously, on three layers:

  • Ingest hash. SHA-256 computed on the practitioner's workstation before upload.
  • Storage layer hash. Azure Blob Storage's MD5 + content-integrity checks on every read.
  • Continuous re-verification. The platform re-computes SHA-256 on every sealed object on a 24-hour cycle. Any drift triggers a P1 incident.
SECTION 6

Audit & observability

Every action on the platform is recorded in an append-only, hash-chained audit log.

The audit log captures:

  • Every authentication, including failed attempts and MFA challenges
  • Every view, retrieval request, retrieval approval, and rehydration
  • Every retention extension, with reason and approver
  • Every disposal event, including dual sign-off where required
  • Every EvidenceVault support session — start, end, scope, and authorising ticket
SECTION 7

Access control & SSO

EvidenceVault integrates with your force's Microsoft Entra ID for single sign-on. Provisioning is group-based: your IT team controls membership in EV-Practitioners, EV-Inspectors, EV-Admin.

Multi-factor authentication is enforced at the IdP layer — we require it but we don't run a parallel factor. Your existing FIDO2 or authenticator-app rollout applies unchanged.

SECTION 8

Resilience & disaster recovery

Storage durability
99.9999999999% (twelve nines) via Azure ZRS — three availability zones in UK South
RPO (data recovery point)
≤ 15 minutes (sealed objects); ≤ 1 hour (audit log)
RTO (service restoration)
≤ 4 hours for ingest & retrieval; archive reads remain available throughout
Service availability target
99.95% monthly, contractually backed
SECTION 9

Incident response

  • Integrity drift (P1). A sealed object's hash no longer matches its recorded value. The object is quarantined within 30 seconds; your force lead is notified within 15 minutes.
  • Personnel access incident (P1). Production access revoked immediately; written notice within 1 hour; full root-cause analysis within 5 working days.
SECTION 10

Accreditations & standards

  • ISO/IEC 27001information security management (current)
  • Cyber Essentials Plusannual recertification
  • NCSC Cloud Security Principlesalignment statement against all 14 principles available on request
  • UK GDPR & DPA 2018DPIA and ROPA available on request
  • G-Cloud 14listed as a Cloud Software service for UK public-sector procurement
  • OFFICIAL-SENSITIVEaccredited classification ceiling for the platform
SECTION 11

Contractual commitments

Several commitments described in this brief are written contractual terms in our standard force agreement:

  • Data shall remain within the Azure UK South region at all times.
  • All personnel with production access shall hold active SC and NPPV3.
  • EvidenceVault shall hold no escrow or master key capable of decrypting customer evidence.
  • Sealed evidence shall not be mutated or deleted by EvidenceVault outside the customer's published retention schedule.
  • Quarterly SIRO-signed personnel attestations shall be provided to the customer.
  • Notification of any P1 integrity or personnel-access incident within 15 minutes.
SECTION 12

Contacts

Security enquiries
SIRO
Available on request via force liaison
24×7 ops line
+44 161 555 0199
!
Ready to start a conversation? Request a 90-day pilot for your force — discovery call within two working days, pilot tenant within five. Request a pilot →