Capture or receive the work, files and agreements that matter. StateNull keeps them organized, routes them to the tools you already use, and lets you check later whether the record changed.
Records, Proof Requests, Trust-E Cases, destinations, Verify and the Cloud Vault are not separate products — they are the steps one record moves through.
Capture photos, scans, notes and files — or receive them through a proof-request link
Records and cases keep files, context and corrections together
Send links and route records to the tools and folders you already use
Review, request exact corrections, approve, and record agreements
Check later whether the record changed; export the history when needed
Sealed captures, scans, notes and received files — each with its own history. Create them in the app or receive them from others; later changes are detectable.
Send one link that shows the person on site exactly what to capture; review, request corrections and approve — inside the same record. How Proof Requests work →
A shared case between two parties: messages, files and agreements land in one record that both sides can check later. Ships in the app on Google Play and in the direct edition.
Share and route records through the tools you already use — email, chat, network folders, cloud storage. StateNull adds the record; your tools keep doing their job.
Drop a file on statenull.com/verify to check it against its record, and read the audit history of views, corrections, decisions and exports.
Your records stay encrypted on the device — and, if you choose, back up end-to-end encrypted to your Cloud Vault, opened in the browser with your own Recovery Code.
A service visit, vehicle return, property handover, claim, inspection or audit can all stop for the same reason: the required evidence is missing, unclear or scattered. StateNull turns it into one request, one correction path and one reviewable record.
Precise statements only — what the record does, and what it does not claim.
In-app photo, scan and PDF captures are fingerprinted and signed at the moment of capture, so any later change to the file is detectable. Video and voice notes are stored encrypted with a tamper-evident audit entry.
Timestamps, identity and context where available, corrections, review decisions, agreements and the audit history stay with the record.
Capture and sealing may work offline. Guest links, server review, sync, fresh RFC-3161 tokens, sharing and billing require connectivity.
ML-DSA is the NIST FIPS 204 algorithm. We do not claim a FIPS 140-3 validated module, and we do not promise protection for a fixed number of years.
StateNull's RFC-3161 timestamp authority is operated by StateNull. It is not an independent or qualified trust service.
Signed location records what the device supplied. It does not prove the scene and does not make spoofing impossible.
Send one link. StateNull tells subcontractors, tenants or customers exactly what proof is required, warns about dark, blurry or duplicate photos before they leave, and gives your office one review, correction, approval and export record. No guest account. No app installation.
Institutional trust is falling, and AI can now fabricate any photo, voice or video on demand. So trust has moved to what can't be faked — mathematics, an open track record, and independent confirmation. StateNull is built for exactly this world.
Authenticity you can check first-hand is the hardest thing to fake.
In StateNull: the seal is applied at the moment of capture — the file is fingerprinted before it can be altered, so any later change to the file is detectable.Credibility built over years of consistency and open publishing — not popularity.
In StateNull: published, standardized cryptography (SHA-256, ML-DSA-65 / NIST FIPS 204). Open algorithms anyone can scrutinize — not a proprietary black box.Open ecosystems where anyone can challenge an incorrect claim in public.
In StateNull: a seal is verifiable by any independent reviewer — at statenull.com/verify or from the open proof bundle, not only inside our app. Proof you can hand to the other side.Independently reproducible results, not official statements.
In StateNull: the seal is pure math. Change a single pixel and verification fails — a result anyone can reproduce offline, without taking our word for anything.Value in sources that have been reliable for decades.
In StateNull: every sealed photo, scan and PDF is also signed with a post-quantum algorithm, chosen so the record stays checkable as technology changes. Evidence has to outlast the tech that made it.Confidence comes from independent signals that agree.
In StateNull: fingerprint + trusted time + signed location + hardware attestation + a hash-chained audit ledger — multiple independent anchors that must all line up.Both plans start instantly, self-serve — EU-hosted, with end-to-end-encrypted content. No sales call required.
One secure seat. Document damage, defects, incidents — and check later whether anything changed. For inspectors, adjusters, journalists, landlords.
See plans →Shared case workflows, organization roles, an admin console. Everyone captures — everything stays verifiable. Live in minutes. Field service with subcontractors? See Proof Requests →
See plans →Each one in plain language — and, if you're the technical reviewer, the exact mechanism underneath.
The exact pixels get a unique fingerprint at the moment of capture. Change one pixel — the fingerprint no longer matches.
SHA-256 hash is computed in memory at capture time, before any file is written to storage. The hash is recorded in the signed provenance manifest and in the audit ledger, so both the content and the record of it are protected.Not just the phone's clock — a network-verified timestamp is sealed in, so backdating shows up in the recorded history.
RFC-3161 timestamp authority issues a signed, verifiable time anchor (not an independent or qualified trust service; fresh tokens require connectivity).The location the device supplied is locked into the seal — if you opt in. It records what the device reported at capture; it does not prove the scene.
Signed twice: once with today's standard cryptography, once with a post-quantum algorithm. Evidence often has to hold up for decades.
RSA-PSS + ML-DSA-65 (NIST FIPS 204, finalized 2024) over the same canonical manifest. A future quantum computer breaking RSA does not break the seal — the lattice-based signature still holds.Every view, edit, export and share is written into a tamper-evident logbook. Edits never touch the original.
SQLCipher database; each entry links to the previous one, so deletion or reordering breaks the chain visibly. Edits (crop, annotate) create audited derivatives — the sealed original stays byte-identical.One tap produces a signed PDF designed to support legal and compliance workflows: what was captured, when, where, by whom, and everything that happened to it since.
SHA-256, capture time, signer-certificate fingerprint, the full audit trail and a chain-integrity verdict — and is itself sealed and signed on creation. Built to support hash-based self-authentication workflows (e.g. FRE 902(14)). Legal hold exempts a case from retention cleanup.Claims, courts, compliance, field documentation — every feature below ships today and is listed as it actually works.
Photo, document scan and multi-page PDF are fully sealed at the moment of capture, before they touch storage; video and voice notes record into your encrypted Records with a tamper-evident audit entry.
Everything you capture lives in your encrypted Records on the device — never in the phone's normal gallery, never in plaintext.
Who captured it, who looked at it, who exported it — recorded automatically, provable on demand.
Send evidence end-to-end encrypted. The server only ever stores ciphertext it cannot read — and you stay in control after sending. To operate, the service does process account, request and delivery metadata (file names, sizes, types, recipients, timestamps) — never your file contents.
What revoking does: it burns the server-held keys and ciphertext, so the link can never be opened again from that moment on. It cannot reach a copy someone already downloaded or decrypted — a recipient who opened the file before you revoked it may still have what they saw.
Talk about the evidence where the evidence lives. Chat is end-to-end encrypted; the server is a blind relay for message content. Comms ships in the app on Google Play and in the direct edition.
Roll out to one device or a whole team — with the controls an IT/security team actually needs.
Generative AI made every unsealed image attackable as a fake — in a claim, in a dispute, in the press. The numbers are not hypothetical.
US AI-enabled fraud losses are projected to reach $40 billion by 2027 (Deloitte, 32% CAGR from $12.3B in 2023). Global deepfake fraud already costs billions a year — and in studies, only 0.1% of people reliably spot a deepfake. "That photo could be AI" is now a standard attack on evidence.
Hash-based court rules (like US FRE 902(14)) authenticate the copy — they can't prove the original wasn't altered before it was copied. Sealing at the moment of capture closes exactly that gap: the fingerprint exists before anyone had a chance to edit.
Police-cloud evidence suites are locked to one vertical and one cloud. Creator tools (C2PA) have no chain of custody and assume you're online. Camera-hardware signing is locked to specific devices. StateNull is software, offline-capable, post-quantum, independently verifiable, any industry — no one else occupies all five at once.
In 2025, a major camera maker's content-credential signing was revoked after a signing vulnerability — proving that the hard part isn't the algorithm, it's the keys. StateNull is built around that: its own PKI, device certificates, signed policies, a key vault and real revocation.
Shared content is end-to-end encrypted — the service stores ciphertext it cannot read — on EU-hosted infrastructure with logically isolated per-tenant storage. And verification never depends on our servers: anyone can check a sealed file in a browser or fully offline.
No AI "enhancement" that silently alters pixels — that would destroy evidential value, so we deliberately don't build it. And no compliance theater: the security section below says exactly what ships today and what is roadmap.
No compliance theater. Everything under "shipping" runs in the product now; everything under "roadmap" is stated as roadmap, nothing in between.
ML-KEM key exchange (FIPS 203) · SLH-DSA (FIPS 205) · a FIPS-140-3-validated crypto module (today we use the FIPS 204 algorithm, not a validated module) · full PAdES-B/-T signatures · C2PA conformance listing · third-party penetration-test report and certifications. If your tender requires one of these, talk to us — we'll tell you exactly where it stands.
These aren't app features you'd notice. They're the certifications and standards a serious buyer checks off. Here's each one: what it is, why it matters to you, and exactly where we stand. No blur.
What it is: our signatures are already quantum-safe (ML-DSA-65); this will extend post-quantum protection to the live connection too. Today the transport is classical TLS 1.3 with certificate pinning.
Why you need it: an attacker can record your encrypted traffic today and decrypt it in ~10 years once quantum computers arrive ("harvest now, decrypt later"). For evidence that stays sensitive for decades, that matters.
Status: roadmap — engineering, edge + client. Not required for the seal itself.
What it is: a backup signature built on completely different math from our main one.
Why you need it: belt and braces. If a weakness is ever found in one algorithm family, the second, unrelated one still holds — insurance for long-horizon archives.
Status: roadmap — low effort, deliberately deprioritized (our main PQ signature already covers the quantum case).
What it is: the difference between "we use the approved algorithm" and "an accredited lab certified our exact implementation."
Why you need it: US federal and some regulated buyers are legally required to run only lab-validated crypto modules — no validation, no deal.
Status: roadmap — we use the FIPS 204 algorithm today; swapping to a pre-validated module is engineering, not a new lab audit. The cheapest of the seven.
What it is: beyond the device's own signed time, a StateNull-operated timestamp authority stamps "this hash existed at exactly 14:03:22 UTC" — a standard RFC-3161 token any tool can check. It is not an independent or qualified trust service.
Why you need it: in a dispute, a separately signed statement of when is harder to challenge than the device's own clock alone.
Status: shipping now — server-side TSA with its own timestamping certificate; tokens verify in openssl ts.
What it is: the European standard that makes Adobe Reader show a signed PDF with a green "valid signature" check.
Why you need it: a reviewer can then verify your report in the tool they already trust — no need to trust ours.
Status: roadmap — builds on the timestamp authority above.
What it is: today the app can embed a real C2PA 1.3 content credential (a standards-based JUMBF/COSE manifest) into the JPEG when you export — an opt-in setting — signed with a hardware-backed device key under our own claim-signer certificate. That certificate is not on the public C2PA trust list, and we hold no conformance listing: stock C2PA validators verify the manifest as valid but show it as an unknown source. Conformance is what would change that — Adobe, Google and camera tools recognising StateNull as a known source.
Why you need it: once we are conformance-listed, your sealed media would show as a recognised source in any C2PA tool. Today, stock validators read the embedded manifest as standards-valid from an unknown source; full verification of the seal itself is through StateNull's own offline verifier.
Status: roadmap — a membership & conformance process (organizational), not just code.
What it is: an independent security team attacks the product and publishes a report; formal certifications (e.g. ISO 27001) audit the organization.
Why you need it: "trust us" isn't evidence. An outside attacker's report — and a certificate — is what your own security team will ask for first.
Status: roadmap — scheduled with the first paid deployment.
We list these openly on purpose. If your tender requires one, tell us which and we'll give you an exact, dated status — never a vague yes.
Start self-serve in minutes; grow into SSO, device management and your own infrastructure when you need to.
Individual and Team plans run on StateNull's EU-hosted service (Finland) with logically isolated per-tenant storage. Shared content is end-to-end encrypted — the server stores ciphertext it cannot read — and a sealed file verifies in any browser or fully offline, without our servers.
Larger deployments add SAML single sign-on (Okta, Entra, ADFS, Ping, Keycloak), device enrolment with policy and compliance, a per-tenant certificate authority, and a hash-chained audit log with a SIEM webhook. You can also self-host the whole stack: the console generates a compose bundle and an installer, and it runs on your own infrastructure.
Be capturing sealed evidence in a minute. Sign up with your email, get a code, install the app — your first photo comes out sealed and verifiable.
Sign up with your email, install the app, take a photo — then open its record and check it yourself. €0 today; payment method required; then the plan price unless canceled before day 14.
Android today. No desktop build yet — the web app runs in any browser with nothing to install.
We publish what StateNull supports and, just as plainly, what it doesn't yet. No certification we don't hold.
Drop any file in your browser — we check it against the live registry and tell you original, altered, or unknown, plus when and by whom. The quickest way to check a file.
Check a StateNull file or proof bundle with pure math — Merkle inclusion + signed tree head — entirely in your browser, or on an air-gapped desktop. No upload, no server, no account. Don't trust us; verify it yourself.
An honestly-sourced explainer: what the industry's C2PA / Content Credentials standard proves, where it breaks — a screenshot or re-upload can strip it, and it proves origin, not truth — and how StateNull can embed a real C2PA 1.3 credential of its own into the JPEG on export (an opt-in setting) — signed by a StateNull claim-signer certificate that is not on the public C2PA trust list and holds no conformance listing, so stock validators show it as valid, from an unknown source — plus an independent, offline-provable registry so your provenance survives. ▶ Watch the film →
Coordinated-disclosure program, scope, safe-harbor, and response SLAs (RFC 9116 security.txt).
Live service status and a running changelog of what shipped, when.
An honest table of every standard — what we support vs. what is independently certified (and what's roadmap). Ask and we'll send it.
A real CycloneDX SBOM with a deliberately minimal dependency graph. Available on request.
Send one link, collect the required proof, review exact corrections, and deliver the current approved record. Start with a 14-day checkout trial — €0 today, payment method required.
StateNull is available now and is not independently audited today. If your procurement needs a specific artifact (pen-test summary, DPA, conformity status), tell us which and you'll get an exact, dated status — never a vague yes.