Kairos Forensics
Kairos Forensics
Home Solutions Services About Contact
Skip to main content

Kairos Forensics

K
Kairos Forensics Cryptographic Evidence Platform
   
Platform in design · Consulting active now

Truth,by design.

Investigators collect the evidence. Whether it holds up depends on proving it wasn’t altered — and today, that proof is almost always a person’s word, not a technical record. Kairos is the cryptographic architecture designed to close that gap: evidence bound to the moment of capture, verifiable independent of Kairos, for the 15-to-20-year span a real prosecution can run. Forensic consulting and buyer validation are active today; the platform itself is in design.

96%
No provenance metadataOf conflict-zone digital images carry no verifiable chain of custody. Source: Content Authenticity Initiative, 2024
268+
Cases tied to lab misconductFBI hair-analysis testimony was found flawed in over 268 criminal cases across two decades — a systemic audit-trail and methodology failure, not a capture-integrity one. Source: DOJ, 2015
2030–35
Projected quantum decryption horizonIntelligence community consensus estimate. A factor in why long-running prosecutions may need cryptography designed for decade-plus relevance.
100+
Organizations, one conflict, no shared standardCollecting Ukraine war crimes evidence on incompatible systems with no common integrity framework. Source: Eurojust, HRMMU, 2023
Design basis: NIST FIPS 203/204
Target standard: Berkeley Protocol
Target users: ICC · UCMJ · StPO · UN mechanisms
Planned: air-gap architecture

Where evidence fails by domain

Documented evidentiary failures across four domains, each costing real convictions, delayed accountability, or years of contested proceedings. Some trace directly to a capture-integrity gap the design below is built to close; others involve deliberate destruction or institutional failure that no signing system alone resolves. The distinction matters, and each case is described on its own terms.

Evidence tampered or fabricated
Chain of custody broken
Authentication standard absent
CB

Caesar Files — Syria

53,275 photographs documenting torture in Assad detention facilities, transferred with a custody record based entirely on human testimony rather than technical verification. Defense challenged authenticity in German and French proceedings throughout; convictions in Koblenz (2021–22) relied on witness testimony to establish what a technical record did not. An illustration of the capture-and-transfer gap a cryptographic custody log is designed to address.
ECCHR Case Documentation; Syrian Justice and Accountability Centre, 2022
Custody gap
AS

Ukraine — ongoing conflict documentation

Over 100 organizations collecting digital evidence with incompatible systems and no common integrity standard. Eurojust (2023) and the HRMMU publicly flagged that existing frameworks are inadequate for ICC prosecution. A gap of the kind a shared cryptographic standard is designed to close — though adoption across 100+ independent organizations is itself a significant undertaking, not a software feature.
Eurojust, “Digital Evidence in ICC Proceedings,” 2023; HRMMU Ukraine Report, 2023
No standard
AS

Gaza — ICC preliminary examination

The 2024 arrest warrant applications relied on open-source material collected across dozens of organizations with no unified custody framework, meaning long-term authenticity cannot currently be independently, cryptographically verified.
ICC Pre-Trial Chamber I Decision, 2024; Human Rights Watch Digital Evidence Project, 2024
At risk
CB

Brazil — Operation Car Wash / Lula acquittal

The largest corruption investigation in Latin American history. The Brazilian Supreme Court annulled convictions of former President Lula in 2021 primarily on judicial-impartiality grounds; evidence-handling concerns, including around communications intercepts, were also raised during the proceedings. A mixed case — part judicial process, part evidentiary handling — not a pure custody-integrity failure.
Brazilian Supreme Court (STF) ruling, April 2021; Folha de São Paulo, 2021
Conviction overturned
TB

South Africa — Zondo State Capture Commission

The Commission (2018–2022) found the evidentiary record weakened by deliberate deletion and modification of government digital records by state actors with legitimate system access — a custodian-side destruction problem. A tamper-evident access and chain-of-custody log is designed to make this kind of deletion detectable after the fact; it would not, on its own, have prevented a custodian from destroying records in the first place.
Zondo Commission Final Report, vol. VI, 2022, pp. 312–318
Tampering documented
AS

Mexico — enforced disappearances

Over 100,000 documented enforced disappearances since 2006 (OHCHR 2023). Digital evidence from citizen investigators is routinely challenged for lack of forensic authentication — a capture-authentication gap. Separately, official records are in some cases destroyed by state actors, which is a deliberate-destruction problem that authentication of citizen-collected evidence does not address.
OHCHR, “Enforced Disappearances in Mexico,” 2023; IACHR Annual Report, 2022
Authentication gap
TB

India — Bhima Koregaon planted evidence

Arsenal Consulting found malware was used to plant fabricated incriminating documents on 16 activists’ computers (2018–2021), which were then accepted by prosecutors without independent cryptographic authentication. An authentication-at-capture standard is designed to make the class of problem — evidence with no genuine chain back to an identified collector — visible; it does not address device compromise that occurs before or outside any collection event.
Arsenal Consulting Digital Forensics Reports, 2021; The Washington Post, 2021
Fabricated evidence
CB

UK — Post Office Horizon scandal

Faulty output from the Horizon accounting system led to the wrongful prosecution of 736 sub-postmasters (1999–2015), the largest miscarriage of justice in British legal history. This was fundamentally a software-reliability and institutional-conduct failure — the Post Office asserted system accuracy that was false — rather than a field-capture custody gap; it illustrates why independent verifiability of any evidence-generating system matters, a broader problem than capture-time signing alone solves.
Court of Appeal, Hamilton & Others v Post Office Ltd [2021] EWCA Crim 577; UK Post Office Horizon Inquiry, 2024
736 wrongful prosecutions
TB

US — FBI forensic lab misconduct

A DOJ review (2015) found FBI examiners gave flawed hair-comparison testimony in at least 268 criminal cases over two decades — a methodology and oversight failure. The review also noted the absence of verifiable audit trails for evidence handling and testing records as a compounding factor; cryptographic logging is designed to address that compounding factor, not the underlying analytical error itself.
DOJ/FBI, “Microscopic Hair Comparison Analysis Review,” 2015; National Registry of Exonerations
268+ cases affected

Every block designed to link cryptographically to the last

This is the architecture Kairos is designing, engineered so tampering at any point breaks the entire chain and the break is detectable at any future moment, including years later in court. Click each block to explore the design.

01
Field capture
02
PQ signature
03
Timestamp
04
Chain log
05
Self-verify
06
Court package

Quantum decryption and AI forgery require separate mitigations

These are not variations of the same problem. They operate on different timelines, exploit different vulnerabilities, and demand different cryptographic responses — which is why Kairos is designed to address both from the outset, not bolt one on later.

Threat model 1: Harvest-now, decrypt-later

Adversaries are collecting encrypted evidence today for future quantum decryption

State-level adversaries have been documented collecting encrypted digital evidence under a “harvest now, decrypt later” strategy. Intelligence community consensus places the point at which large-scale quantum decryption becomes practical at roughly 2030–2035 — a projection, not a certainty. Evidence currently under collection in active ICC investigations — Ukraine, Sudan, Myanmar — may still be in proceedings by then, which is the practical reason for designing with post-quantum algorithms now rather than waiting. Planned mitigation: ML-DSA-65 + ML-KEM-768 hybrid signing at the moment of capture, before the file enters any transmission channel.
NSA CNSA 2.0, 2022; NIST IR 8413, 2022
Threat model 2: Retroactive AI authenticity challenge

Authentic evidence challenged as AI-generated in court

A structurally separate attack: defense counsel challenges authentic evidence as AI-generated because no cryptographic timestamp predating the relevant generative capability exists. This is not a decryption problem. It is a provenance problem. A 2024 Content Authenticity Initiative study found 96% of conflict-zone digital images carry no verifiable provenance metadata. A Pakistani court in 2024 was unable to resolve whether audio evidence was AI-generated for precisely this reason. Planned mitigation: RFC 3161 trusted timestamp and PQ signature at capture, predating any generative model’s capability to have produced the file.
Content Authenticity Initiative / Adobe, 2024; Dawn Media Group, 2024; Berkman Klein Center, “AI and Legal Evidence,” 2024
Active / Ukraine

Both threats converging in active conflict documentation

Russian information operations have deployed AI-synthesized footage alongside systematic encryption of real communications, exploiting both vulnerabilities simultaneously. Ukrainian prosecutors face the challenge of authenticating genuine atrocity documentation against deliberate synthetic confusion, while that same documentation is being collected without cryptographic signing standards that would resolve either challenge.
EU DisinfoLab, 2023; Stanford Internet Observatory, “Synthetic Media in Conflict,” 2023

Evidence that survives the quantum transition

A war crimes prosecution can take 20 years. Evidence encrypted with classical algorithms today may not survive that window intact. Kairos’s cryptographic design is built around the NIST post-quantum standards finalized in August 2024, so evidence collected now doesn’t need to be re-secured later. The platform itself is not yet built.

2020
NSA warns that classical public-key cryptography will eventually be broken by quantum computers. NIST begins formal post-quantum standardization.
2022
NSA CNSA 2.0 published. Mandates post-quantum migration for all National Security Systems. Deadline: January 1, 2030.
2024
NIST FIPS 203, 204, and 205 finalized, the first internationally recognized post-quantum standards. Kairos’s planned cryptographic stack is designed around these.
2030
CNSA 2.0 deadline. All National Security Systems must be PQ-capable. A key reason the design targets post-quantum algorithms from the outset rather than adding them later.
2030–35
Intelligence community consensus quantum threshold. RSA and ECDSA-encrypted evidence may become retroactively decryptable and alterable.
Kairos’s planned cryptographic stack (design specification)
ML-DSA-65
Primary signing algorithm
FIPS 204
Ed25519
Classical co-signature — civilian and non-NSS deployment. CNSA 2.0 mandates ECDSA P-384 for NSS contexts; P-384 is available for DoD/UCMJ customers.
RFC 8032
ML-KEM-768
Key encapsulation
FIPS 203
SHA-3-256 / SHA-3-384
Content hashing
FIPS 202
RFC 3161 TSA
Trusted timestamping
IETF
PKCS#11 / HSM
Key storage (v1.2+)
FIPS 140-3
liboqs
Open-source PQ implementation
Open Quantum Safe
Hybrid signing (ML-DSA + Ed25519) protects against both quantum and classical attacks simultaneously. If either algorithm is ever compromised, the other holds.

What Kairos provides, and when

Kairos is building in three phases, deliberately: forensic consulting active today, generating the field requirements that shape a planned SaaS evidence platform next, followed by institutional system integration once that platform is proven. Each phase earns the next.

Stage: pre-development. SaaS build planned for Q1 2027, contingent on seed funding. The cryptographic architecture below reflects design work informed by 30 countries of consulting deployment — no platform code has been written yet. Forensic consulting and buyer validation interviews are active now; engineering build is planned to begin Q1 2027 if seed funding closes on that timeline.
PHASE 1 — ACTIVE NOW

Forensic consulting

Field deployment support, evidence authentication review, expert witness services, and Berkeley Protocol compliance guidance, active today. Kairos’s consultants have direct operational experience in mass grave documentation, battlefield forensic exploitation, and conflict-zone evidence collection across 30 countries, and apply Berkeley Protocol methodology in that field work. This is the company’s current, revenue-generating activity and the source of the requirements behind the planned platform below.

Retained · Per-investigation · Expert witness · Active now
PHASE 2 — PLANNED, Q1 2027

Evidence platform (SaaS)

A planned standalone system for post-quantum cryptographic signing, chain-of-custody logging, and court-ready package generation, intended for law enforcement, military justice, human rights investigators, and international tribunal practitioners. Engineering build is planned to begin Q1 2027, contingent on seed funding. Not yet built; see Post-Quantum Cryptography and How It Works above for the design.

Planned · Build begins Q1 2027
PHASE 3 — LATER, POST-LAUNCH

Institutional integration

Once the SaaS platform is built and validated, the roadmap calls for integration with systems investigative units already use — Cellebrite, DEMS, Axon body camera evidence, and SIEM overlays for classified network environments — along with a pathway toward DoD ATO/STIG authorization. This phase follows platform launch; none of these integrations or authorizations exist yet.

Planned · Follows SaaS launch

The architecture is designed. The gap it closes is real now.

Kairos is pre-development and pre-seed, in buyer validation and active forensic consulting today, building toward a Q1 2027 platform launch. If you evaluate digital evidence for a living, or you’re backing what comes after — we want the conversation now, not platform access, which doesn’t exist yet.

Field experience
Kairos’s design requirements are shaped by field applications across military, human rights, and investigative work.
Investors
Deck available on request. Pre-seed stage. Seed round open.
Buyer validation
We’re conducting buyer validation interviews with law enforcement, prosecutors, human rights investigators, and military justice practitioners to shape the platform design ahead of build.
Send a message
Platform
Solutions overview Field collection Chain of custody Court packages Post-quantum security
Services
Services overview Forensic consulting Institutional integration Pilot programs Expert witness
Company
About Resources Contact contact@kairosforensics.com Khthon — operational validator
© 2026 Kairos Forensics Inc. — kairosforensics.com
Kairos Forensics Inc. — Delaware C-Corp