Invented content with a perfect timestamp
A timestamp doesn't turn a false account into a true one. Mitigation: say so in the manifest, never submit the dossier on its own, and leave the right to challenge intact.
Applied research · not a service
A threat on a phone looks like evidence. In court, the defence can raise three equally plausible objections: the image was edited, the phone's clock can be changed in two taps, and nobody can verify the conversation existed in those terms. Coercive control, threats and economic abuse leave traces mostly in the digital world, and those traces collapse without a date and integrity.
One thing, done rigorously, useful from day one: the victim — or whoever supports her — records the incident and a qualified trust service provider (FNMT-RCM, Uanataca or another) timestamps its date and integrity. RFC 3161 protocol, SHA-256 hash, a daily Merkle-style chain anchored without personal data, and a PDF/A dossier that an expert can verify outside the app.
Incident
Text, photo, audio or screenshot. Location only if she turns it on.
Hash
SHA-256 of the content. The operator doesn't need to read it.
Timestamp
Qualified eIDAS timestamp, Art. 41.2 of Regulation 910/2014. Rebuttable presumption.
Chain
Daily Merkle tree. The public root contains no personal data.
Dossier
PDF/A plus manifest. The court weighs the account on its merits.
End-to-end encryption
Key derived from the user. The operator cannot read the content.
Zero knowledge
The server checks hashes and timestamps, never the account.
EU residency
Infrastructure in the EU, at the high level of Spain's National Security Framework.
Real deletion
On request, with proof of deletion. Granular, revocable consent. GDPR and Spanish LOPDGDD.
The limit stated in the manifest
Date and integrity. Not truth.
The defence can still challenge the content, request an expert opinion and bring counter-evidence. What it can no longer claim is that the file was fabricated afterwards. That sentence belongs in the dossier itself, not in the small print.
A timestamp doesn't turn a false account into a true one. Mitigation: say so in the manifest, never submit the dossier on its own, and leave the right to challenge intact.
Coercive control can reach the tool itself. Planned mitigation: discreet mode, emergency wipe of local traces and digital safety training. It isn't built here.
If it fails, the service fails. Mitigation: at least two (for example FNMT and Uanataca) and migration without breaking the chain.
The research itself recommends that the operator be a social cooperative or a foundation: a commercial company is pushed to grow and monetise users, the opposite of what this service needs. Governance with criminal-law, lived-experience and technical voices; an annual public audit; a ban on advertising and on exploiting the data. K&D LEGALTECH, S.L. is the consultancy. It is not that operator and should not be.
The Comprehensive Violence Prevention System is the research's broader framework: federated data rather than a single database; alerts; and an engine that only advises. Connecting families to anticipate risk comes close to surveillance. The answer isn't technical. Artificial intelligence complements professional judgement; it doesn't replace it. KD does not sell risk scores or identify people who haven't reported. That question stays open, and open it will remain.
Demo
SHA-256 in your browser. Nothing leaves your device. This is not a qualified timestamp or a Merkle tree. Don't enter real data.
Training or FRIA, not this toolStatus: empty