Create account Sign in Pricing Get the Android app
Why StateNull
Why StateNullThe trust shiftHow it works The sealWho is it forUse cases
Product
Proof Requests — field proof by link ProductDeployment
Security & trust
SecurityTrust CenterStandards
Verifiable records

Make the record before details get lost.

Capture or receive the work, files and agreements that matter. StateNull keeps them organized, routes them to the tools you already use, and lets you check later whether the record changed.

The lifecycle

One record, from first capture to final check

Records, Proof Requests, Trust-E Cases, destinations, Verify and the Cloud Vault are not separate products — they are the steps one record moves through.

📸

Create or receive

Capture photos, scans, notes and files — or receive them through a proof-request link

🗂️

Organize

Records and cases keep files, context and corrections together

🔗

Share & route

Send links and route records to the tools and folders you already use

🤝

Review & agree

Review, request exact corrections, approve, and record agreements

🔎

Verify & export

Check later whether the record changed; export the history when needed

📷

Records

Sealed captures, scans, notes and received files — each with its own history. Create them in the app or receive them from others; later changes are detectable.

Proof Requests

Send one link that shows the person on site exactly what to capture; review, request corrections and approve — inside the same record. How Proof Requests work →

🤝

Trust-E Cases

A shared case between two parties: messages, files and agreements land in one record that both sides can check later. Ships in the app on Google Play and in the direct edition.

🗺️

Destinations & mapped folders

Share and route records through the tools you already use — email, chat, network folders, cloud storage. StateNull adds the record; your tools keep doing their job.

🔎

Verify & Audit

Drop a file on statenull.com/verify to check it against its record, and read the audit history of views, corrections, decisions and exports.

🗄️

Cloud Vault

Your records stay encrypted on the device — and, if you choose, back up end-to-end encrypted to your Cloud Vault, opened in the browser with your own Recovery Code.

Who it is for

Different work. The same evidence gap.

A service visit, vehicle return, property handover, claim, inspection or audit can all stop for the same reason: the required evidence is missing, unclear or scattered. StateNull turns it into one request, one correction path and one reviewable record.

Find your use case → Thirteen sectors the shipped product can serve today, each with the decision it unblocks and what it will not do — plus the expansion sectors we do not sell yet.
What the record guarantees

Security under the workflow — not in the way

Precise statements only — what the record does, and what it does not claim.

🔏

Sealed at capture

In-app photo, scan and PDF captures are fingerprinted and signed at the moment of capture, so any later change to the file is detectable. Video and voice notes are stored encrypted with a tamper-evident audit entry.

📖

The record keeps the history

Timestamps, identity and context where available, corrections, review decisions, agreements and the audit history stay with the record.

📶

Offline — stated precisely

Capture and sealing may work offline. Guest links, server review, sync, fresh RFC-3161 tokens, sharing and billing require connectivity.

🖋️

Post-quantum — stated precisely

ML-DSA is the NIST FIPS 204 algorithm. We do not claim a FIPS 140-3 validated module, and we do not promise protection for a fixed number of years.

🕰️

Timestamps — stated precisely

StateNull's RFC-3161 timestamp authority is operated by StateNull. It is not an independent or qualified trust service.

📍

Location — stated precisely

Signed location records what the device supplied. It does not prove the scene and does not make spoofing impossible.

Seal at capture · SHA-256 fingerprint · Trusted time & signed location · Post-quantum ML-DSA-65 · Chain-of-custody PDF · Encrypted records · View-once sharing · Offline capture & sealing · EU hosting · Seal at capture · SHA-256 fingerprint · Trusted time & signed location · Post-quantum ML-DSA-65 · Chain-of-custody PDF · Encrypted records · View-once sharing · Offline capture & sealing · EU hosting ·
NEW · Proof Requests — field proof by link

Don't discover the missing job photo after the subcontractor has left.

Send one link. StateNull tells subcontractors, tenants or customers exactly what proof is required, warns about dark, blurry or duplicate photos before they leave, and gives your office one review, correction, approval and export record. No guest account. No app installation.

Run your first proof request → How Proof Requests work
The evolution of trust · 2026 & beyond

People stopped trusting claims. They trust verification.

Institutional trust is falling, and AI can now fabricate any photo, voice or video on demand. So trust has moved to what can't be faked — mathematics, an open track record, and independent confirmation. StateNull is built for exactly this world.

1

Direct experience

Authenticity you can check first-hand is the hardest thing to fake.

In StateNull: the seal is applied at the moment of capture — the file is fingerprinted before it can be altered, so any later change to the file is detectable.
2

Proven track record & expertise

Credibility built over years of consistency and open publishing — not popularity.

In StateNull: published, standardized cryptography (SHA-256, ML-DSA-65 / NIST FIPS 204). Open algorithms anyone can scrutinize — not a proprietary black box.
3

Collaborative communities

Open ecosystems where anyone can challenge an incorrect claim in public.

In StateNull: a seal is verifiable by any independent reviewer — at statenull.com/verify or from the open proof bundle, not only inside our app. Proof you can hand to the other side.
4

Objective principles — mathematics

Independently reproducible results, not official statements.

In StateNull: the seal is pure math. Change a single pixel and verification fails — a result anyone can reproduce offline, without taking our word for anything.
5

Enduring reputation & consistency

Value in sources that have been reliable for decades.

In StateNull: every sealed photo, scan and PDF is also signed with a post-quantum algorithm, chosen so the record stays checkable as technology changes. Evidence has to outlast the tech that made it.
6

Triangulation of independent sources

Confidence comes from independent signals that agree.

In StateNull: fingerprint + trusted time + signed location + hardware attestation + a hash-chained audit ledger — multiple independent anchors that must all line up.
StateNull's promise, in one line: Don't trust us — verify it yourself, with mathematics. Every sealed capture carries its own proof, and anyone can check it — offline, in seconds, without asking us to vouch for anything.
Where to start

Pick the StateNull that fits you

Both plans start instantly, self-serve — EU-hosted, with end-to-end-encrypted content. No sales call required.

👤 Individual

One secure seat. Document damage, defects, incidents — and check later whether anything changed. For inspectors, adjusters, journalists, landlords.

See plans →
Self-serve · from €15 / user / mo billed annually

👥 Team / small business

Shared case workflows, organization roles, an admin console. Everyone captures — everything stays verifiable. Live in minutes. Field service with subcontractors? See Proof Requests →

See plans →
Self-serve · from €19 / user / mo billed annually
What's inside the seal

Six things locked into every sealed capture

Each one in plain language — and, if you're the technical reviewer, the exact mechanism underneath.

🔍

A digital fingerprint

The exact pixels get a unique fingerprint at the moment of capture. Change one pixel — the fingerprint no longer matches.

Technical detail
A SHA-256 hash is computed in memory at capture time, before any file is written to storage. The hash is recorded in the signed provenance manifest and in the audit ledger, so both the content and the record of it are protected.
🕐

Trusted time

Not just the phone's clock — a network-verified timestamp is sealed in, so backdating shows up in the recorded history.

Technical detail
An SNTP-derived timestamp is signed into the manifest alongside the device clock, so any drift is itself visible in the proof. For deployments that need standards-based time attestation, a StateNull-operated RFC-3161 timestamp authority issues a signed, verifiable time anchor (not an independent or qualified trust service; fresh tokens require connectivity).
📍

Signed location

The location the device supplied is locked into the seal — if you opt in. It records what the device reported at capture; it does not prove the scene.

Technical detail
GPS coordinates (with accuracy and provider) come from the OS location stack directly — no Google services — and are embedded in the signed manifest as a versioned claim. Captures made without location remain fully verifiable.
🖋️

Two signatures

Signed twice: once with today's standard cryptography, once with a post-quantum algorithm. Evidence often has to hold up for decades.

Technical detail
Hybrid RSA-PSS + ML-DSA-65 (NIST FIPS 204, finalized 2024) over the same canonical manifest. A future quantum computer breaking RSA does not break the seal — the lattice-based signature still holds.
📖

An unbroken logbook

Every view, edit, export and share is written into a tamper-evident logbook. Edits never touch the original.

Technical detail
A hash-chained audit ledger inside an encrypted SQLCipher database; each entry links to the previous one, so deletion or reordering breaks the chain visibly. Edits (crop, annotate) create audited derivatives — the sealed original stays byte-identical.
📋

A chain-of-custody report

One tap produces a signed PDF designed to support legal and compliance workflows: what was captured, when, where, by whom, and everything that happened to it since.

Technical detail
The chain-of-custody report contains identity, SHA-256, capture time, signer-certificate fingerprint, the full audit trail and a chain-integrity verdict — and is itself sealed and signed on creation. Built to support hash-based self-authentication workflows (e.g. FRE 902(14)). Legal hold exempts a case from retention cleanup.
What it does

Built for pictures that must hold up

Claims, courts, compliance, field documentation — every feature below ships today and is listed as it actually works.

Sealed capture — five capture modes

Photo, document scan and multi-page PDF are fully sealed at the moment of capture, before they touch storage; video and voice notes record into your encrypted Records with a tamper-evident audit entry.

  • Flash, pinch-zoom, tap-focus, framing grid — a real camera, not a compliance form
  • Guided case flow: enter a case reference, capture everything into that case, notes are sealed too
  • Private mode & watermarking; captures never pass through the OS gallery
🔒 SEALEDIMG_0027
🔒 SEALEDAUD_0031

Encrypted records

Everything you capture lives in your encrypted Records on the device — never in the phone's normal gallery, never in plaintext.

  • AES-256-GCM at rest; viewing decrypts only in memory — no temp files
  • Search, albums, retention rules — with legal hold that exempts open cases
  • Edits (crop, annotate) become audited copies; the sealed original is never modified
  • Optional Long-term Archive — keep sealed evidence for years as a separate end-to-end-encrypted retention copy, on an automatic weekly or monthly schedule
🔒
🔒
🔒
🔒

Chain of custody, automated

Who captured it, who looked at it, who exported it — recorded automatically, provable on demand.

  • Views, exports and shares are logged into the hash-chained, signed audit ledger
  • One-tap signed chain-of-custody PDF per item or case
  • Cross-device authorship: a recipient can verify who captured a shared file ("authored by @alex")
📸 → 📖 → 📋
capture · logbook · signed report

Sharing you can take back

Send evidence end-to-end encrypted. The server only ever stores ciphertext it cannot read — and you stay in control after sending. To operate, the service does process account, request and delivery metadata (file names, sizes, types, recipients, timestamps) — never your file contents.

  • Per-recipient key wrapping (ECIES) + AES-256-GCM
  • View-once, expiry and burn — or revoke access at any time
  • Recipient-side verification: seal intact, author confirmed

What revoking does: it burns the server-held keys and ciphertext, so the link can never be opened again from that moment on. It cannot reach a copy someone already downloaded or decrypted — a recipient who opened the file before you revoked it may still have what they saw.

📄 → 🔐 → 🔗
file · encrypt · view-once link

Secure comms, same seal of quality

Talk about the evidence where the evidence lives. Chat is end-to-end encrypted; the server is a blind relay for message content. Comms ships in the app on Google Play and in the direct edition.

  • E2E chat — per-recipient keys, ciphertext-only storage, delete-for-everyone
  • Opt-in @handle directory — discoverable only if you choose
  • Encrypted 1:1 calls — every call is forced through StateNull's own TURN relay over TLS on port 443, so calls also work on locked-down networks; there is no direct peer-to-peer path and our SFU publishes no media ports
Sealed the site photos — case #4471
Verified ✓ report attached 🔒

Fleet & control

Roll out to one device or a whole team — with the controls an IT/security team actually needs.

  • Built-in fleet management for your organisation's OWN enrolled devices: enrolment (QR/token/bulk), signed policies with anti-replay, and remote lock & wipe of a lost or stolen company device
  • Own PKI with device certificates, RBAC, SIEM webhook, tamper-evident admin audit
  • Individual and Team plans run on the EU-hosted multi-tenant service with logically isolated per-tenant storage — shared content is end-to-end encrypted
📱
🔒
🛡️
Why this exists

Photos stopped being trusted. We make them checkable.

Generative AI made every unsealed image attackable as a fake — in a claim, in a dispute, in the press. The numbers are not hypothetical.

📉

The problem is measurable

US AI-enabled fraud losses are projected to reach $40 billion by 2027 (Deloitte, 32% CAGR from $12.3B in 2023). Global deepfake fraud already costs billions a year — and in studies, only 0.1% of people reliably spot a deepfake. "That photo could be AI" is now a standard attack on evidence.

⚖️

The legal gap we close

Hash-based court rules (like US FRE 902(14)) authenticate the copy — they can't prove the original wasn't altered before it was copied. Sealing at the moment of capture closes exactly that gap: the fingerprint exists before anyone had a chance to edit.

🧭

Why nothing else covers it

Police-cloud evidence suites are locked to one vertical and one cloud. Creator tools (C2PA) have no chain of custody and assume you're online. Camera-hardware signing is locked to specific devices. StateNull is software, offline-capable, post-quantum, independently verifiable, any industry — no one else occupies all five at once.

🔑

Trust lives in key management

In 2025, a major camera maker's content-credential signing was revoked after a signing vulnerability — proving that the hard part isn't the algorithm, it's the keys. StateNull is built around that: its own PKI, device certificates, signed policies, a key vault and real revocation.

🏰

Your data, under your keys

Shared content is end-to-end encrypted — the service stores ciphertext it cannot read — on EU-hosted infrastructure with logically isolated per-tenant storage. And verification never depends on our servers: anyone can check a sealed file in a browser or fully offline.

🔍

Honest by design

No AI "enhancement" that silently alters pixels — that would destroy evidential value, so we deliberately don't build it. And no compliance theater: the security section below says exactly what ships today and what is roadmap.

Security & standards

What ships today — and what doesn't yet

No compliance theater. Everything under "shipping" runs in the product now; everything under "roadmap" is stated as roadmap, nothing in between.

SHIPPING TODAY
ML-DSA-65 signatures (NIST FIPS 204 algorithm) Hybrid classical + post-quantum, on by default AES-256-GCM at rest · SHA-256 at capture Hash-chained, signed audit ledger Own PKI · device certificates · revocation Certificate pinning · signed device policies E2E sharing (ECIES) · zero plaintext at rest RFC-3161 timestamp authority · StateNull-operated signed time ISO 27037-aligned evidence handling
ON THE ROADMAP — NOT CLAIMED YET

ML-KEM key exchange (FIPS 203) · SLH-DSA (FIPS 205) · a FIPS-140-3-validated crypto module (today we use the FIPS 204 algorithm, not a validated module) · full PAdES-B/-T signatures · C2PA conformance listing · third-party penetration-test report and certifications. If your tender requires one of these, talk to us — we'll tell you exactly where it stands.

The standards journey

Seven things procurement asks about — in plain language

These aren't app features you'd notice. They're the certifications and standards a serious buyer checks off. Here's each one: what it is, why it matters to you, and exactly where we stand. No blur.

🔐

Quantum-safe connection ML-KEM · FIPS 203

What it is: our signatures are already quantum-safe (ML-DSA-65); this will extend post-quantum protection to the live connection too. Today the transport is classical TLS 1.3 with certificate pinning.

Why you need it: an attacker can record your encrypted traffic today and decrypt it in ~10 years once quantum computers arrive ("harvest now, decrypt later"). For evidence that stays sensitive for decades, that matters.

Status: roadmap — engineering, edge + client. Not required for the seal itself.

🧬

A second quantum-safe signature SLH-DSA · FIPS 205

What it is: a backup signature built on completely different math from our main one.

Why you need it: belt and braces. If a weakness is ever found in one algorithm family, the second, unrelated one still holds — insurance for long-horizon archives.

Status: roadmap — low effort, deliberately deprioritized (our main PQ signature already covers the quantum case).

🏅

Lab-certified crypto FIPS 140-3 validated

What it is: the difference between "we use the approved algorithm" and "an accredited lab certified our exact implementation."

Why you need it: US federal and some regulated buyers are legally required to run only lab-validated crypto modules — no validation, no deal.

Status: roadmap — we use the FIPS 204 algorithm today; swapping to a pre-validated module is engineering, not a new lab audit. The cheapest of the seven.

🕰️

Standards-based timestamps RFC-3161 · LIVE

What it is: beyond the device's own signed time, a StateNull-operated timestamp authority stamps "this hash existed at exactly 14:03:22 UTC" — a standard RFC-3161 token any tool can check. It is not an independent or qualified trust service.

Why you need it: in a dispute, a separately signed statement of when is harder to challenge than the device's own clock alone.

Status: shipping now — server-side TSA with its own timestamping certificate; tokens verify in openssl ts.

📎

Signatures your PDF reader trusts PAdES-B/-T

What it is: the European standard that makes Adobe Reader show a signed PDF with a green "valid signature" check.

Why you need it: a reviewer can then verify your report in the tool they already trust — no need to trust ours.

Status: roadmap — builds on the timestamp authority above.

🌐

Industry-standard provenance C2PA listing

What it is: today the app can embed a real C2PA 1.3 content credential (a standards-based JUMBF/COSE manifest) into the JPEG when you export — an opt-in setting — signed with a hardware-backed device key under our own claim-signer certificate. That certificate is not on the public C2PA trust list, and we hold no conformance listing: stock C2PA validators verify the manifest as valid but show it as an unknown source. Conformance is what would change that — Adobe, Google and camera tools recognising StateNull as a known source.

Why you need it: once we are conformance-listed, your sealed media would show as a recognised source in any C2PA tool. Today, stock validators read the embedded manifest as standards-valid from an unknown source; full verification of the seal itself is through StateNull's own offline verifier.

Status: roadmap — a membership & conformance process (organizational), not just code.

🎯

Proven by outsiders Pen-test & certs

What it is: an independent security team attacks the product and publishes a report; formal certifications (e.g. ISO 27001) audit the organization.

Why you need it: "trust us" isn't evidence. An outside attacker's report — and a certificate — is what your own security team will ask for first.

Status: roadmap — scheduled with the first paid deployment.

We list these openly on purpose. If your tender requires one, tell us which and we'll give you an exact, dated status — never a vague yes.

Deployment

From one user to a whole organisation

Start self-serve in minutes; grow into SSO, device management and your own infrastructure when you need to.

🇪🇺 EU-hosted, end-to-end encrypted

Individual and Team plans run on StateNull's EU-hosted service (Finland) with logically isolated per-tenant storage. Shared content is end-to-end encrypted — the server stores ciphertext it cannot read — and a sealed file verifies in any browser or fully offline, without our servers.

EU hosting (Finland)E2E-encrypted contentPer-tenant isolationOffline verification
See plans →

🏢 Organisations — SSO, devices, your own servers

Larger deployments add SAML single sign-on (Okta, Entra, ADFS, Ping, Keycloak), device enrolment with policy and compliance, a per-tenant certificate authority, and a hash-chained audit log with a SIEM webhook. You can also self-host the whole stack: the console generates a compose bundle and an installer, and it runs on your own infrastructure.

SAML SSODevice managementPer-tenant PKIAudit log + SIEMSelf-hosted option
Compare plans →

👤 Individuals & teams — free trial

Be capturing sealed evidence in a minute. Sign up with your email, get a code, install the app — your first photo comes out sealed and verifiable.

€0 todayPayment method requiredNo passwordOffline capture & sealing
See plans →
€0 today; payment method required; then the plan price unless canceled before day 14.
2signatures on every photo, scan & PDF — classical + post-quantum
0bytes of plaintext at rest
100%of in-app photo, scan & PDF captures sealed on the device — later changes are detectable
14-daytrial — €0 today; payment method required; then the plan price unless canceled before day 14
Get started

Your first sealed capture, two minutes from now

Sign up with your email, install the app, take a photo — then open its record and check it yourself. €0 today; payment method required; then the plan price unless canceled before day 14.

See plans →Try Proof Requests →
GET IT ONGoogle Play Other ways to install →

Android today. No desktop build yet — the web app runs in any browser with nothing to install.

Trust Center

Don't take our word for it — check it yourself

We publish what StateNull supports and, just as plainly, what it doesn't yet. No certification we don't hold.

🔎

Verify online

Drop any file in your browser — we check it against the live registry and tell you original, altered, or unknown, plus when and by whom. The quickest way to check a file.

🧮

Verify offline — no server

Check a StateNull file or proof bundle with pure math — Merkle inclusion + signed tree head — entirely in your browser, or on an air-gapped desktop. No upload, no server, no account. Don't trust us; verify it yourself.

🏷️

Content Credentials (C2PA), explained

An honestly-sourced explainer: what the industry's C2PA / Content Credentials standard proves, where it breaks — a screenshot or re-upload can strip it, and it proves origin, not truth — and how StateNull can embed a real C2PA 1.3 credential of its own into the JPEG on export (an opt-in setting) — signed by a StateNull claim-signer certificate that is not on the public C2PA trust list and holds no conformance listing, so stock validators show it as valid, from an unknown source — plus an independent, offline-provable registry so your provenance survives. ▶ Watch the film →

🛡️

Security disclosure policy

Coordinated-disclosure program, scope, safe-harbor, and response SLAs (RFC 9116 security.txt).

📈

System status & changelog

Live service status and a running changelog of what shipped, when.

📋

Standards & compliance matrix

An honest table of every standard — what we support vs. what is independently certified (and what's roadmap). Ask and we'll send it.

🧬

Supply chain & SBOM

A real CycloneDX SBOM with a deliberately minimal dependency graph. Available on request.

Proof Requests for field teams

Send one link, collect the required proof, review exact corrections, and deliver the current approved record. Start with a 14-day checkout trial — €0 today, payment method required.

StateNull is available now and is not independently audited today. If your procurement needs a specific artifact (pen-test summary, DPA, conformity status), tell us which and you'll get an exact, dated status — never a vague yes.