Post-quantum evidence integrity,
from capture to verdict.
The evidentiary record in atrocity investigations, corruption prosecutions, and human rights cases fails at a structural level: prosecutors are forced to prove authenticity through human testimony because no cryptographic infrastructure exists to do it for them. That is not a minor gap in a $6.9 trillion accountability problem, and it is not solved by better testimony. Kairos is designing the infrastructure to close it, alongside active forensic consulting and buyer validation work; engineering build is planned to begin Q1 2027, contingent on seed funding.
Evidence fails because authentication has no infrastructure
By the time evidence reaches a prosecutor in The Hague, Berlin, or Amsterdam, a defense attorney can ask: how do we know this photograph was not edited? Under current practice, the answer is usually human testimony.
That is a weak foundation for prosecuting heads of state, and it is a foundation defense counsel knows how to attack. Kairos is designing cryptographic infrastructure built to answer that question on its own terms, independent of any witness's memory. The cases below show the range of ways the current approach fails; not all of them are failures a signing system alone resolves, and each is described on its own terms.
Caesar Files (Syria)
53,275 photographs documenting torture in Assad detention facilities, transferred with a custody record based almost entirely on human testimony rather than technical verification. Defense challenged authenticity throughout proceedings in Germany and France. An illustration of the capture-and-transfer gap a cryptographic custody log is designed to address.
Ukraine: active conflict documentation
Over 100 organizations collecting evidence with incompatible systems and no common integrity standard. Eurojust (2023) publicly flagged that existing frameworks are inadequate for future ICC prosecution — a gap of the kind a shared cryptographic standard is designed to close, though adoption across 100+ independent organizations is a significant undertaking in its own right.
Myanmar: Rohingya documentation
The UN Fact-Finding Mission (2018) found individual incident evidence "frequently lacked the forensic integrity standards required for individual criminal prosecution." The ICJ case has relied substantially on statistical evidence, which the Mission's finding suggests was in part a consequence of that authentication gap — alongside the broader access and documentation constraints inherent to the situation.
Three layers: collection, custody, submission
This is the intended architecture. Each layer is designed to close a distinct, documented failure mode, and together they are built to produce a self-verifying evidence package that a prosecutor, judge, or defense expert can check without Kairos, or any server, still being around decades later.
Kairos Capture
Designed for post-quantum hybrid signing at the moment of capture, before any file is written to device storage: a SHA-3-256 content hash computed in memory, signed with ML-DSA-65 + Ed25519, and bound to device identifier, GPS coordinate, and UTC timestamp. The design calls for fully offline operation with no server dependency, deployable in any environment.
Intended to capture: photo · video · audio · GPS coordinates · documents
Design basis
- ML-DSA-65 (NIST FIPS 204)
- Ed25519 (RFC 8032)
- SHA-3-256 (FIPS 202)
- iOS Secure Enclave
- Android StrongBox
- Offline-first design
Kairos Chain
Designed so that every access, transfer, review, redaction, export, and annotation would be appended to a tamper-evident chain log, each entry signed and referencing the prior entry's hash, so modification would be detectable. Multi-organization sharing and air-gap or classified-network operation are core design requirements for this layer, not yet built.
Design basis
- Hash-linked entries (prev_hash)
- Per-action signing
- Multi-org federation
- Air-gap server mode
- Classified network mode
- RFC 3161 timestamps
Evidence Package Generator
Intended to auto-generate submission packages formatted for each target jurisdiction, each self-verifying using open-source NIST post-quantum libraries with no Kairos software or proprietary infrastructure required. The design goal is to bundle the verification toolchain with each package — aimed at multi-decade prosecution timelines — with Berkeley Protocol methodology documentation included per package.
Target formats
- ICC Rules of Procedure
- UCMJ / MCM
- German StPO
- Dutch CCP
- IIIM · UNITAD · MMP
- NGO archive formats
Every block designed to link cryptographically to the last
This is the architecture Kairos is designing, engineered so tampering at any point breaks the entire chain and the break is detectable at any future moment, including years later in court. Click each block to explore the design.
Designed for evidence that must survive the quantum transition
A war crimes prosecution can take 20 years. Evidence encrypted with classical algorithms today may not survive that window intact. Kairos's cryptographic design is built around the NIST post-quantum standards finalized in August 2024, so evidence collected now doesn't need to be re-secured later. The platform itself is not yet built.
Designed across major legal frameworks
The intent is for Kairos submission packages to reduce authentication delays by auto-formatting for each target jurisdiction's rules of evidence. The frameworks below reflect current design scope and are expected to expand as procurement engagement grows; none of the formatting has been built yet.
ICC: Rules of Procedure and Evidence
Intended to be formatted per ICC RPE Rules 68–70, with Berkeley Protocol methodology documentation per package.
UCMJ / Manual for Courts-Martial
Intended to be formatted per Military Rules of Evidence 901–902, with JAG, NCIS, OSI, and AFOSI workflows and an air-gap mode for classified environments as design targets.
German StPO: Federal Prosecutor
Intended to be formatted for German Code of Criminal Procedure digital evidence standards, with BKA and Federal Prosecutor workflow compatibility as a design target.
Dutch Code of Criminal Procedure
Intended to be formatted for Netherlands PNAT and Dutch CCP requirements, with Europol and Eurojust evidence-exchange compatibility as a design target.
IIIM · UNITAD · MMP · IIMM
Intended to be formatted for UN investigative mechanism evidence submission standards, with ICMP identification workflow compatibility as a design target.
NGO and institutional archive
Design target: compatibility with PHR, HRW, Amnesty International, and similar documentation organizations' workflows, alongside a planned no-cost citizen tier requiring no account registration.
Pre-development now, build begins Q1 2027
The platform does not yet exist as software. Cryptographic architecture and field requirements are complete; engineering build is contingent on seed funding closing on this timeline. Field-informed design work continues throughout development, grounded in real operational conditions across military, human rights, and investigative work.
- Buyer validation interviews
- Delaware C-Corp established
- Cryptographic architecture finalized
- SBIR application in progress
- Seed round open
- Core technical leadership in place
- Mobile app: all capture modalities
- ML-DSA + Ed25519 signing
- Chain of custody MVP
- Berkeley Protocol alignment
- First field pilot deployed
- UCMJ / NATO package formats
- Enforcement + battlefield modules
- Air-gap server mode
- Axon + DEMS integration
- First LE + JAG pilots
- Target: first paid license
- ICC + UJ package formats
- Mass grave module
- Multi-language UI
- HSM + FIPS 140-3
- ICMP compatibility
- First UN mechanism pilot
- Full case management
- Gov cloud deployment
- Cellebrite + Relativity + SIEM
- General availability
- Framework agreements active
- Path to sustainability
What the design is built around
Each priority below is built to close a specific, documented failure mode. These are firm design commitments for the planned platform, not claims about a product that ships today.
Built around NIST FIPS 203/204 from day one
Hybrid ML-DSA-65 + Ed25519 signing is designed to defeat harvest-now-decrypt-later attacks, a documented strategy already attributed to state-level adversaries collecting encrypted evidence today, before their targets' cryptography catches up.
Designed for no server dependency
The architecture calls for all cryptographic functions to operate offline — intended for forward operating bases, mass grave excavation sites, conflict zones without connectivity, and classified military networks.
Built toward full Protocol alignment
The UN/Berkeley Protocol has set the field's evidentiary bar since 2020, and no platform fully implements it yet. Kairos is designed to cover its full requirements end to end, which is intended to become a durable procurement advantage with institutional buyers who already evaluate against it.
Built to outlast Kairos itself
Packages are designed to be authenticated using liboqs and public NIST libraries, with no proprietary software, account, or Kairos infrastructure required. A 20-year prosecution shouldn't depend on a startup staying in business; the verification toolchain is meant to be bundled with the evidence, not hosted by Kairos.
Informed by field operations
Planned modules for mass grave excavation, battlefield forensic exploitation, and enforcement-action workflows are informed by field applications across military, human rights, and investigative work.
Built to extend existing tools, not replace them
The design includes an import pathway for evidence originated in other field-capture tools, preserving original signatures while extending them with Kairos's custody and packaging layer — complementary infrastructure for organizations already using established collection tools, not a wholesale replacement.
The architecture is designed. The gap it closes is real now.
We're in buyer validation and active forensic consulting today, shaping the platform ahead of a Q1 2027 build. If you evaluate digital evidence for a living, we want your read on the design.