Applied research · not a service

Evidential logbook and timestamping

From the master's thesis by Camelia Dicu Baican, Master's in Criminal Law and Criminal Procedure (UC3M, supervised by María Rocío Zafra Espinosa de los Monteros, 2026). KD designs the approach. It does not handle victims' data or conduct legal proceedings.

Why a screenshot isn't enough

A threat on a phone looks like evidence. In court, the defence can raise three equally plausible objections: the image was edited, the phone's clock can be changed in two taps, and nobody can verify the conversation existed in those terms. Coercive control, threats and economic abuse leave traces mostly in the digital world, and those traces collapse without a date and integrity.

  • 1The image may have been altered on the device.
  • 2The on-screen time proves nothing.
  • 3Nobody can verify the chat existed as shown.

What the research proposes

One thing, done rigorously, useful from day one: the victim — or whoever supports her — records the incident and a qualified trust service provider (FNMT-RCM, Uanataca or another) timestamps its date and integrity. RFC 3161 protocol, SHA-256 hash, a daily Merkle-style chain anchored without personal data, and a PDF/A dossier that an expert can verify outside the app.

  1. 1

    Incident

    Text, photo, audio or screenshot. Location only if she turns it on.

  2. 2

    Hash

    SHA-256 of the content. The operator doesn't need to read it.

  3. 3

    Timestamp

    Qualified eIDAS timestamp, Art. 41.2 of Regulation 910/2014. Rebuttable presumption.

  4. 4

    Chain

    Daily Merkle tree. The public root contains no personal data.

  5. 5

    Dossier

    PDF/A plus manifest. The court weighs the account on its merits.

Legal framework (Spain/EU): Law 6/2020, Arts. 299.2, 326 and 384 of the Civil Procedure Act, the Budapest Convention, and eIDAS 2 (Regulation 2024/1183). It is not an investigative measure under Art. 588 bis of the Criminal Procedure Act: it does not examine anyone else's phone. It is the victim's own safeguarding of her digital trail.

Four data principles

  • End-to-end encryption

    Key derived from the user. The operator cannot read the content.

  • Zero knowledge

    The server checks hashes and timestamps, never the account.

  • EU residency

    Infrastructure in the EU, at the high level of Spain's National Security Framework.

  • Real deletion

    On request, with proof of deletion. Granular, revocable consent. GDPR and Spanish LOPDGDD.

The limit stated in the manifest

Date and integrity. Not truth.

The defence can still challenge the content, request an expert opinion and bring counter-evidence. What it can no longer claim is that the file was fabricated afterwards. That sentence belongs in the dossier itself, not in the small print.

Three risks the research doesn't hide

1

Invented content with a perfect timestamp

A timestamp doesn't turn a false account into a true one. Mitigation: say so in the manifest, never submit the dossier on its own, and leave the right to challenge intact.

2

Shared or monitored phone

Coercive control can reach the tool itself. Planned mitigation: discreet mode, emergency wipe of local traces and digital safety training. It isn't built here.

3

A single qualified provider

If it fails, the service fails. Mitigation: at least two (for example FNMT and Uanataca) and migration without breaking the chain.

Who should run it. Not this company.

The research itself recommends that the operator be a social cooperative or a foundation: a commercial company is pushed to grow and monetise users, the opposite of what this service needs. Governance with criminal-law, lived-experience and technical voices; an annual public audit; a ban on advertising and on exploiting the data. K&D LEGALTECH, S.L. is the consultancy. It is not that operator and should not be.

SIPREV remains under debate

The Comprehensive Violence Prevention System is the research's broader framework: federated data rather than a single database; alerts; and an engine that only advises. Connecting families to anticipate risk comes close to surveillance. The answer isn't technical. Artificial intelligence complements professional judgement; it doesn't replace it. KD does not sell risk scores or identify people who haven't reported. That question stays open, and open it will remain.

Demo

Try just the chaining

SHA-256 in your browser. Nothing leaves your device. This is not a qualified timestamp or a Merkle tree. Don't enter real data.

Training or FRIA, not this tool
Genesis0000000000000000000000000000000000000000000000000000000000000000

    Status: empty