Cryptographic Evidence Chain
Every piece of evidence is hashed, linked into a chain with the previous entry, signed, and independently timestamped. Subsequent tampering is detectable — proven, not just claimed.
Proof instead of assertion.
Every piece of evidence is canonicalized, hashed, linked into a hash chain with the previous entry, and signed with the organization's own certificate (RSA-PSS). Subsequent tampering is therefore detectable — the chain itself reveals the break.
In addition to its own signature, every piece of evidence is confirmed by an eIDAS-qualified timestamp authority (RFC 3161). This makes the timestamp tamper-proof even against ReportAct itself — not just against third parties.
For approvals (policies, risks, RoPA entries, and more), there is a central approval queue following the four-eyes principle; every approval or rejection is cryptographically sealed.
What the evidence chain delivers technically.
Hash chain with RSA-PSS signature
Every piece of evidence is canonicalized, hashed, and chained to the previous entry — any subsequent change visibly breaks the chain.
RFC 3161 timestamp
Additional confirmation from an eIDAS-qualified timestamp authority makes the timestamp tamper-proof even against ReportAct itself.
Public, independent verification
Every piece of evidence can be verified by third parties — such as auditors — via a public URL without login, with no need to trust ReportAct.
Signed approval workflows
Four-eyes principle for policies, risks, RoPA entries, and more; every approval or rejection is cryptographically sealed.
From evidence to independent verification.
Capture evidence
A piece of evidence is captured in the system and canonicalized.
Hash, chain, sign
The evidence is hashed, bound to the previous chain block, and signed with the organization's own certificate; a qualified timestamp confirms the time.
Verify independently
Using a public verify URL, any third party can check content, chain, signature, and timestamp — without ReportAct access.
Carries the evidence trail for every regime.
Management-accountability records, cryptographically sealed and independently verifiable.
Regulation details →Every status change in the reporting cascade is sealed, so it cannot be altered unnoticed.
Regulation details →Evidence of when which TOM was in force — relevant for the 72-hour deadline.
Regulation details →Evidence that proves itself.
We'll show you live how a sealed piece of evidence is created — and how an auditor verifies it without ReportAct access.