Kairos Forensics
Kairos Forensics
Home Solutions Services About Contact
Skip to main content

Kairos Forensics

K
Kairos Forensics Cryptographic Evidence Platform
   
Internal MVP in active build · Pre-seed

Truth,by design.

Investigators collect the evidence. Whether it holds up depends on proving it wasn’t altered, and today that’s almost always a person’s word, not a technical record. Kairos is the cryptographic architecture designed to close that gap: evidence bound to the moment of capture, verifiable independent of Kairos. CAPTURE, CME, and CMIS are an internal MVP in active build today.

96%
No provenance metadataOf conflict-zone digital images carry no verifiable chain of custody. Source: Content Authenticity Initiative, 2024
268+
Cases tied to lab misconductFBI hair-analysis testimony was found flawed in over 268 criminal cases across two decades, a systemic audit-trail and methodology failure, not a capture-integrity one. Source: DOJ, 2015
2030–35
Projected quantum decryption horizonIntelligence community consensus estimate. A factor in why long-running prosecutions may need cryptography designed for decade-plus relevance.
100+
Organizations, one conflict, no shared standardCollecting Ukraine war crimes evidence on incompatible systems with no common integrity framework. Source: Eurojust, HRMMU, 2023
Design basis: NIST FIPS 203/204
Target standard: Berkeley Protocol
Target users: ICC · UCMJ · StPO · UN mechanisms
Planned: air-gap architecture

Where evidence fails by domain

Documented evidentiary failures across four domains, each costing real convictions, delayed accountability, or years of contested proceedings. Some trace directly to a capture-integrity gap the design below is built to close; others involve deliberate destruction or institutional failure that no signing system alone resolves. The distinction matters, and each case is described on its own terms.

Evidence tampered or fabricated
Chain of custody broken
Authentication standard absent
CB

Caesar Files — Syria

53,275 photographs documenting torture in Assad detention facilities, transferred with a custody record based entirely on human testimony rather than technical verification. Defense challenged authenticity in German and French proceedings throughout; convictions in Koblenz (2021–22) relied on witness testimony to establish what a technical record did not. An illustration of the capture-and-transfer gap a cryptographic custody log is designed to address.
ECCHR Case Documentation; Syrian Justice and Accountability Centre, 2022
Custody gap
AS

Ukraine — ongoing conflict documentation

Over 100 organizations collecting digital evidence with incompatible systems and no common integrity standard. Eurojust (2023) and the HRMMU publicly flagged that existing frameworks are inadequate for ICC prosecution. A gap of the kind a shared cryptographic standard is designed to close, though adoption across 100+ independent organizations is itself a significant undertaking, not a software feature.
Eurojust, “Digital Evidence in ICC Proceedings,” 2023; HRMMU Ukraine Report, 2023
No standard
AS

Gaza — ICC preliminary examination

The 2024 arrest warrant applications relied on open-source material collected across dozens of organizations with no unified custody framework, meaning long-term authenticity cannot currently be independently, cryptographically verified.
ICC Pre-Trial Chamber I Decision, 2024; Human Rights Watch Digital Evidence Project, 2024
At risk
CB

Brazil — Operation Car Wash / Lula acquittal

The largest corruption investigation in Latin American history. The Brazilian Supreme Court annulled convictions of former President Lula in 2021 primarily on judicial-impartiality grounds; evidence-handling concerns, including around communications intercepts, were also raised during the proceedings. A mixed case: part judicial process, part evidentiary handling, not a pure custody-integrity failure.
Brazilian Supreme Court (STF) ruling, April 2021; Folha de São Paulo, 2021
Conviction overturned
TB

South Africa — Zondo State Capture Commission

The Commission (2018–2022) found the evidentiary record weakened by deliberate deletion and modification of government digital records by state actors with legitimate system access: a custodian-side destruction problem. A tamper-evident access and chain-of-custody log is designed to make this kind of deletion detectable after the fact; it would not, on its own, have prevented a custodian from destroying records in the first place.
Zondo Commission Final Report, vol. VI, 2022, pp. 312–318
Tampering documented
AS

Mexico — enforced disappearances

Over 100,000 documented enforced disappearances since 2006 (OHCHR 2023). Digital evidence from citizen investigators is routinely challenged for lack of forensic authentication, a capture-authentication gap. Separately, official records are in some cases destroyed by state actors, which is a deliberate-destruction problem that authentication of citizen-collected evidence does not address.
OHCHR, “Enforced Disappearances in Mexico,” 2023; IACHR Annual Report, 2022
Authentication gap
TB

India — Bhima Koregaon planted evidence

Arsenal Consulting found malware was used to plant fabricated incriminating documents on 16 activists’ computers (2018–2021), which were then accepted by prosecutors without independent cryptographic authentication. An authentication-at-capture standard is designed to make the class of problem, evidence with no genuine chain back to an identified collector, visible; it does not address device compromise that occurs before or outside any collection event.
Arsenal Consulting Digital Forensics Reports, 2021; The Washington Post, 2021
Fabricated evidence
CB

UK — Post Office Horizon scandal

Faulty output from the Horizon accounting system led to the wrongful prosecution of 736 sub-postmasters (1999–2015), the largest miscarriage of justice in British legal history. This was fundamentally a software-reliability and institutional-conduct failure (the Post Office asserted system accuracy that was false) rather than a field-capture custody gap; it illustrates why independent verifiability of any evidence-generating system matters, a broader problem than capture-time signing alone solves.
Court of Appeal, Hamilton & Others v Post Office Ltd [2021] EWCA Crim 577; UK Post Office Horizon Inquiry, 2024
736 wrongful prosecutions
TB

US — FBI forensic lab misconduct

A DOJ review (2015) found FBI examiners gave flawed hair-comparison testimony in at least 268 criminal cases over two decades, a methodology and oversight failure. The review also noted the absence of verifiable audit trails for evidence handling and testing records as a compounding factor; cryptographic logging is designed to address that compounding factor, not the underlying analytical error itself.
DOJ/FBI, “Microscopic Hair Comparison Analysis Review,” 2015; National Registry of Exonerations
268+ cases affected

Every block designed to link cryptographically to the last

This is the architecture Kairos is designing, engineered so tampering at any point breaks the entire chain and the break is detectable at any future moment, including years later in court. Click each block to explore the design.

01
Field capture
02
PQ signature
03
Timestamp
04
Chain log
05
Self-verify
06
Court package
Stage 1 of 6 — Field capture
Hashing the file before it reaches storage
The design calls for a SHA-3-256 content hash to be computed in memory the moment a photograph, video, audio recording, GPS coordinate, or document is captured, before the file is written to device storage. That hash would be the fingerprint of the file in its original, unmodified state; any subsequent edit would produce a different hash. The device identifier, GPS coordinate, and UTC timestamp are intended to be embedded alongside it.
SHA-3-256 content hashDevice identifier embeddingGPS + UTC timestampPre-storage capture

Quantum decryption and AI forgery require separate mitigations

These are not variations of the same problem. They operate on different timelines, exploit different vulnerabilities, and demand different cryptographic responses, which is why Kairos is designed to address both from the outset, not bolt one on later.

Threat model 1: Harvest-now, decrypt-later

Adversaries are collecting encrypted evidence today for future quantum decryption

State-level adversaries have been documented collecting encrypted digital evidence under a “harvest now, decrypt later” strategy. Intelligence community consensus places the point at which large-scale quantum decryption becomes practical at roughly 2030–2035, a projection, not a certainty. Evidence currently under collection in active ICC investigations (Ukraine, Sudan, Myanmar) may still be in proceedings by then, which is the practical reason for designing with post-quantum algorithms now rather than waiting. Planned mitigation: ML-DSA-65 hybrid signing alongside Ed25519 at the moment of capture, before the file enters any transmission channel.
NSA CNSA 2.0, 2022; NIST IR 8413, 2022
Threat model 2: Retroactive AI authenticity challenge

Authentic evidence challenged as AI-generated in court

A structurally separate attack: defense counsel challenges authentic evidence as AI-generated because no cryptographic timestamp predating the relevant generative capability exists. This is not a decryption problem. It is a provenance problem. A 2024 Content Authenticity Initiative study found 96% of conflict-zone digital images carry no verifiable provenance metadata. A Pakistani court in 2024 was unable to resolve whether audio evidence was AI-generated for precisely this reason. Planned mitigation: RFC 3161 trusted timestamp and PQ signature at capture, predating any generative model’s capability to have produced the file.
Content Authenticity Initiative / Adobe, 2024; Dawn Media Group, 2024; Berkman Klein Center, “AI and Legal Evidence,” 2024

Both threats converging in active conflict documentation

Russian information operations have deployed AI-synthesized footage alongside systematic encryption of real communications, exploiting both vulnerabilities simultaneously. Ukrainian prosecutors face the challenge of authenticating genuine atrocity documentation against deliberate synthetic confusion, while that same documentation is being collected without cryptographic signing standards that would resolve either challenge.
EU DisinfoLab, 2023; Stanford Internet Observatory, “Synthetic Media in Conflict,” 2023

Evidence that survives the quantum transition

A war crimes prosecution can take 20 years. Evidence encrypted with classical algorithms today may not survive that window intact. Kairos’s cryptographic design is built around the NIST post-quantum standards finalized in August 2024, so evidence collected now doesn’t need to be re-secured later. The platform itself is an internal MVP in active build; the hybrid post-quantum layer below is designed and flag-gated, not yet the default.

2020
NSA warns that classical public-key cryptography will eventually be broken by quantum computers. NIST begins formal post-quantum standardization.
2022
NSA CNSA 2.0 published. Mandates post-quantum migration for all National Security Systems. Deadline: January 1, 2030.
2024
NIST FIPS 203, 204, and 205 finalized, the first internationally recognized post-quantum standards. Kairos’s planned cryptographic stack is designed around these.
2030
CNSA 2.0 deadline. All National Security Systems must be PQ-capable. A key reason the design targets post-quantum algorithms from the outset rather than adding them later.
2030–35
Intelligence community consensus quantum threshold. RSA and ECDSA-encrypted evidence may become retroactively decryptable and alterable.
Kairos’s cryptographic stack (from the architecture design)
Ed25519 (libsodium)
Primary signing algorithm, MVP, live now
RFC 8032
ML-DSA-65 (liboqs)
Hybrid post-quantum signature, added alongside Ed25519, v1.1+, flag-gated
FIPS 204
SHA-3-256
Content hashing
FIPS 202
AES-256-GCM
Evidence bundle encryption, MVP, live now
FIPS 197
RFC 3161 TSA
Trusted timestamping, DigiCert / Sectigo, queued if offline
IETF
Secure Enclave / StrongBox
Field-device key storage, non-exportable, biometric-gated, MVP, live now
iOS / Android
PKCS#11 / HSM
Backend key storage, v1.1+
FIPS 140-3
liboqs
Open-source PQ implementation
Open Quantum Safe
MVP signing is Ed25519 + SHA-3-256, live today. ML-DSA-65 lands in v1.1+ as a hybrid co-signature alongside Ed25519, not the default yet. If either algorithm is ever compromised once hybrid signing ships, the other holds.
PHASE 1 — IN BUILD NOW

Internal MVP

CAPTURE, CME, and CMIS are in active internal development, grounded in the team’s direct operational experience in mass grave documentation, battlefield forensic exploitation, and conflict-zone evidence collection across 30 countries, applying Berkeley Protocol methodology to shape the platform’s design requirements.

Internal build · Buyer validation · Active now
PHASE 2 — IN BUILD, TARGETING Q1 2027

Evidence platform (SaaS)

A planned standalone system for post-quantum cryptographic signing, chain-of-custody logging, and court-ready package generation, intended for law enforcement, military justice, human rights investigators, and international tribunal practitioners. Engineering build is underway now, targeting external availability in Q1 2027, contingent on seed funding. Internal MVP status; see Post-Quantum Cryptography and How It Works above for the design.

In build · Targeting Q1 2027
PHASE 3 — LATER, POST-LAUNCH

Institutional integration

Once the SaaS platform is built and validated, the roadmap calls for integration with systems investigative units already use: Cellebrite, DEMS, Axon body camera evidence, and SIEM overlays for classified network environments, along with a pathway toward DoD ATO/STIG authorization. This phase follows platform launch; none of these integrations or authorizations exist yet.

Planned · Follows SaaS launch

Contact

Kairos is in active internal MVP development and pre-seed fundraising, in buyer validation today, targeting a Q1 2027 external platform launch. If you evaluate digital evidence for a living, or you’re backing what comes after, we want the conversation now, while it can still shape what we build.

Send a message
Platform
Solutions overview Field collection Chain of custody Court packages Post-quantum security
Services
Services overview Forensic consulting Institutional integration Pilot programs Expert witness
Company
About Resources Contact contact@kairosforensics.com Khthon — operational validator
© 2026 Kairos Forensics Inc. — kairosforensics.com
Kairos Forensics Inc. — Delaware C-Corp