Executive summary
EvidenceVault is a long-term, immutable storage platform for closed-case digital forensic evidence, built and operated in the United Kingdom by EvidenceVault. It is designed around one core promise: the evidence you put in today is provably the same evidence you retrieve in seven, ten or twenty years' time.
Three commitments make that promise hold:
- Azure UK South only. All bytes — primary, backup, and metadata — live in the Azure UK South (London) region, zone-redundant across three availability zones. No replication to UK West, no replication overseas. Ever.
- UK-cleared personnel only. Every engineer with production access holds active SC clearance and NPPV3 force vetting. There is no offshore support.
- Mathematical immutability. Sealed items are stored on write-once blob storage with customer-managed encryption keys. Mutation is not policy-blocked — it is technically impossible.
Data sovereignty
EvidenceVault runs entirely on Microsoft Azure UK regions. The platform topology is:
Single-region operation is a deliberate sovereignty decision, not a cost compromise.
Personnel & vetting
We recognise that for a UK police force, who has hands on the production environment matters as much as how the environment is built. EvidenceVault is operated by a small UK team under the following non-negotiable rules:
- Production access requires both SC clearance and NPPV3. No exceptions, no temporary uplift accounts, no contractor bypass.
- No offshore engineering. All design, development, operations and customer support are performed by UK-resident, UK-cleared personnel.
- No production access for sales, marketing or commercial staff.
- Annual re-vetting with mandatory disclosure of any change in clearance status.
Encryption & key management
Immutability & integrity
Sealed evidence is written to Azure Blob Storage with immutability policies applied at the container level — specifically, a time-based legal hold tied to the item's retention schedule.
Integrity is verified continuously, on three layers:
- Ingest hash. SHA-256 computed on the practitioner's workstation before upload.
- Storage layer hash. Azure Blob Storage's MD5 + content-integrity checks on every read.
- Continuous re-verification. The platform re-computes SHA-256 on every sealed object on a 24-hour cycle. Any drift triggers a P1 incident.
Audit & observability
Every action on the platform is recorded in an append-only, hash-chained audit log.
The audit log captures:
- Every authentication, including failed attempts and MFA challenges
- Every view, retrieval request, retrieval approval, and rehydration
- Every retention extension, with reason and approver
- Every disposal event, including dual sign-off where required
- Every EvidenceVault support session — start, end, scope, and authorising ticket
Access control & SSO
EvidenceVault integrates with your force's Microsoft Entra ID for single sign-on. Provisioning is group-based: your IT team controls membership in EV-Practitioners, EV-Inspectors, EV-Admin.
Multi-factor authentication is enforced at the IdP layer — we require it but we don't run a parallel factor. Your existing FIDO2 or authenticator-app rollout applies unchanged.
Resilience & disaster recovery
Incident response
- Integrity drift (P1). A sealed object's hash no longer matches its recorded value. The object is quarantined within 30 seconds; your force lead is notified within 15 minutes.
- Personnel access incident (P1). Production access revoked immediately; written notice within 1 hour; full root-cause analysis within 5 working days.
Accreditations & standards
- ISO/IEC 27001 — information security management (current)
- Cyber Essentials Plus — annual recertification
- NCSC Cloud Security Principles — alignment statement against all 14 principles available on request
- UK GDPR & DPA 2018 — DPIA and ROPA available on request
- G-Cloud 14 — listed as a Cloud Software service for UK public-sector procurement
- OFFICIAL-SENSITIVE — accredited classification ceiling for the platform
Contractual commitments
Several commitments described in this brief are written contractual terms in our standard force agreement:
- Data shall remain within the Azure UK South region at all times.
- All personnel with production access shall hold active SC and NPPV3.
- EvidenceVault shall hold no escrow or master key capable of decrypting customer evidence.
- Sealed evidence shall not be mutated or deleted by EvidenceVault outside the customer's published retention schedule.
- Quarterly SIRO-signed personnel attestations shall be provided to the customer.
- Notification of any P1 integrity or personnel-access incident within 15 minutes.