Security Feature Features / Cryptographic Evidence Chain

Cryptographic Evidence Chain

Every piece of evidence is hashed, linked into a chain with the previous entry, signed, and independently timestamped. Subsequent tampering is detectable — proven, not just claimed.

What is the Cryptographic Evidence Chain

Proof instead of assertion.

Every piece of evidence is canonicalized, hashed, linked into a hash chain with the previous entry, and signed with the organization's own certificate (RSA-PSS). Subsequent tampering is therefore detectable — the chain itself reveals the break.

In addition to its own signature, every piece of evidence is confirmed by an eIDAS-qualified timestamp authority (RFC 3161). This makes the timestamp tamper-proof even against ReportAct itself — not just against third parties.

For approvals (policies, risks, RoPA entries, and more), there is a central approval queue following the four-eyes principle; every approval or rejection is cryptographically sealed.

Core capabilities

What the evidence chain delivers technically.

Hash chain with RSA-PSS signature

Every piece of evidence is canonicalized, hashed, and chained to the previous entry — any subsequent change visibly breaks the chain.

RFC 3161 timestamp

Additional confirmation from an eIDAS-qualified timestamp authority makes the timestamp tamper-proof even against ReportAct itself.

Public, independent verification

Every piece of evidence can be verified by third parties — such as auditors — via a public URL without login, with no need to trust ReportAct.

Signed approval workflows

Four-eyes principle for policies, risks, RoPA entries, and more; every approval or rejection is cryptographically sealed.

How it works

From evidence to independent verification.

Capture evidence

A piece of evidence is captured in the system and canonicalized.

Hash, chain, sign

The evidence is hashed, bound to the previous chain block, and signed with the organization's own certificate; a qualified timestamp confirms the time.

Verify independently

Using a public verify URL, any third party can check content, chain, signature, and timestamp — without ReportAct access.

Connected regulations

Carries the evidence trail for every regime.

NIS2 & NISG

Management-accountability records, cryptographically sealed and independently verifiable.

Regulation details →
DORA

Every status change in the reporting cascade is sealed, so it cannot be altered unnoticed.

Regulation details →
GDPR

Evidence of when which TOM was in force — relevant for the 72-hour deadline.

Regulation details →
Next step

Evidence that proves itself.

We'll show you live how a sealed piece of evidence is created — and how an auditor verifies it without ReportAct access.