Kairos Forensics
Kairos Forensics
Home Solutions Services About Contact
Skip to main content

Kairos Forensics

K
Kairos Forensics Cryptographic Evidence Platform
Solutions: Kairos Forensics
The planned platform

Post-quantum evidence integrity,
from capture to verdict.

The evidentiary record in atrocity investigations, corruption prosecutions, and human rights cases fails at a structural level: prosecutors are forced to prove authenticity through human testimony because no cryptographic infrastructure exists to do it for them. That is not a minor gap in a $6.9 trillion accountability problem, and it is not solved by better testimony. Kairos is designing the infrastructure to close it, alongside active forensic consulting and buyer validation work; engineering build is planned to begin Q1 2027, contingent on seed funding.

Kairos Capture app concept
The structural gap

Evidence fails because authentication has no infrastructure

By the time evidence reaches a prosecutor in The Hague, Berlin, or Amsterdam, a defense attorney can ask: how do we know this photograph was not edited? Under current practice, the answer is usually human testimony.

That is a weak foundation for prosecuting heads of state, and it is a foundation defense counsel knows how to attack. Kairos is designing cryptographic infrastructure built to answer that question on its own terms, independent of any witness's memory. The cases below show the range of ways the current approach fails; not all of them are failures a signing system alone resolves, and each is described on its own terms.

Custody gap

Caesar Files (Syria)

53,275 photographs documenting torture in Assad detention facilities, transferred with a custody record based almost entirely on human testimony rather than technical verification. Defense challenged authenticity throughout proceedings in Germany and France. An illustration of the capture-and-transfer gap a cryptographic custody log is designed to address.

ECCHR Case Documentation; Syrian Justice and Accountability Centre, 2022
No standard

Ukraine: active conflict documentation

Over 100 organizations collecting evidence with incompatible systems and no common integrity standard. Eurojust (2023) publicly flagged that existing frameworks are inadequate for future ICC prosecution — a gap of the kind a shared cryptographic standard is designed to close, though adoption across 100+ independent organizations is a significant undertaking in its own right.

Eurojust, "Digital Evidence in ICC Proceedings," 2023
Scope reduced

Myanmar: Rohingya documentation

The UN Fact-Finding Mission (2018) found individual incident evidence "frequently lacked the forensic integrity standards required for individual criminal prosecution." The ICJ case has relied substantially on statistical evidence, which the Mission's finding suggests was in part a consequence of that authentication gap — alongside the broader access and documentation constraints inherent to the situation.

UN Human Rights Council, A/HRC/39/64, 2018

Three layers: collection, custody, submission

This is the intended architecture. Each layer is designed to close a distinct, documented failure mode, and together they are built to produce a self-verifying evidence package that a prosecutor, judge, or defense expert can check without Kairos, or any server, still being around decades later.

01
Planned: Free + Professional tiers

Kairos Capture

Designed for post-quantum hybrid signing at the moment of capture, before any file is written to device storage: a SHA-3-256 content hash computed in memory, signed with ML-DSA-65 + Ed25519, and bound to device identifier, GPS coordinate, and UTC timestamp. The design calls for fully offline operation with no server dependency, deployable in any environment.

Intended to capture: photo · video · audio · GPS coordinates · documents

Design basis

  • ML-DSA-65 (NIST FIPS 204)
  • Ed25519 (RFC 8032)
  • SHA-3-256 (FIPS 202)
  • iOS Secure Enclave
  • Android StrongBox
  • Offline-first design
02
Planned: Professional tier

Kairos Chain

Designed so that every access, transfer, review, redaction, export, and annotation would be appended to a tamper-evident chain log, each entry signed and referencing the prior entry's hash, so modification would be detectable. Multi-organization sharing and air-gap or classified-network operation are core design requirements for this layer, not yet built.

Design basis

  • Hash-linked entries (prev_hash)
  • Per-action signing
  • Multi-org federation
  • Air-gap server mode
  • Classified network mode
  • RFC 3161 timestamps
03
Planned: Professional tier

Evidence Package Generator

Intended to auto-generate submission packages formatted for each target jurisdiction, each self-verifying using open-source NIST post-quantum libraries with no Kairos software or proprietary infrastructure required. The design goal is to bundle the verification toolchain with each package — aimed at multi-decade prosecution timelines — with Berkeley Protocol methodology documentation included per package.

Target formats

  • ICC Rules of Procedure
  • UCMJ / MCM
  • German StPO
  • Dutch CCP
  • IIIM · UNITAD · MMP
  • NGO archive formats

Every block designed to link cryptographically to the last

This is the architecture Kairos is designing, engineered so tampering at any point breaks the entire chain and the break is detectable at any future moment, including years later in court. Click each block to explore the design.

01
Field capture
02
PQ signature
03
Timestamp
04
Chain log
05
Self-verify
06
Court package

Designed for evidence that must survive the quantum transition

A war crimes prosecution can take 20 years. Evidence encrypted with classical algorithms today may not survive that window intact. Kairos's cryptographic design is built around the NIST post-quantum standards finalized in August 2024, so evidence collected now doesn't need to be re-secured later. The platform itself is not yet built.

2020
NSA warns that classical public-key cryptography will eventually be broken by quantum computers. NIST begins formal post-quantum standardization.
2022
NSA CNSA 2.0 published. Mandates post-quantum migration for all National Security Systems. Deadline: January 1, 2030.
2024
NIST FIPS 203, 204, and 205 finalized, the first internationally recognized post-quantum standards. Kairos's planned cryptographic stack is designed around these.
2030
CNSA 2.0 deadline. All National Security Systems must be PQ-capable — a key reason the design targets post-quantum algorithms from the outset.
2030–35
Intelligence community consensus quantum threshold, a projection rather than a certainty. RSA and ECDSA-encrypted evidence may become retroactively decryptable and alterable within this window.
Planned cryptographic stack (design specification)
ML-DSA-65
Primary signing
FIPS 204
Ed25519
Classical co-signature — civilian/non-NSS. CNSA 2.0 mandates ECDSA P-384 for NSS; the design accounts for DoD customers separately.
RFC 8032
ML-KEM-768
Key encapsulation
FIPS 203
SHA-3-256/384
Content hashing
FIPS 202
RFC 3161 TSA
Trusted timestamping
IETF
PKCS#11 / HSM
Key storage, planned v1.2+
FIPS 140-3
liboqs
Reference PQ library
Open Quantum Safe
Hybrid signing (ML-DSA + Ed25519) is designed to protect against both quantum and classical attacks simultaneously — if either algorithm is ever compromised, the other is intended to hold.

Designed across major legal frameworks

The intent is for Kairos submission packages to reduce authentication delays by auto-formatting for each target jurisdiction's rules of evidence. The frameworks below reflect current design scope and are expected to expand as procurement engagement grows; none of the formatting has been built yet.

International criminal

ICC: Rules of Procedure and Evidence

Intended to be formatted per ICC RPE Rules 68–70, with Berkeley Protocol methodology documentation per package.

US Military Justice

UCMJ / Manual for Courts-Martial

Intended to be formatted per Military Rules of Evidence 901–902, with JAG, NCIS, OSI, and AFOSI workflows and an air-gap mode for classified environments as design targets.

Universal Jurisdiction: Germany

German StPO: Federal Prosecutor

Intended to be formatted for German Code of Criminal Procedure digital evidence standards, with BKA and Federal Prosecutor workflow compatibility as a design target.

Universal Jurisdiction: Netherlands

Dutch Code of Criminal Procedure

Intended to be formatted for Netherlands PNAT and Dutch CCP requirements, with Europol and Eurojust evidence-exchange compatibility as a design target.

UN Investigative Mechanisms

IIIM · UNITAD · MMP · IIMM

Intended to be formatted for UN investigative mechanism evidence submission standards, with ICMP identification workflow compatibility as a design target.

Human rights documentation

NGO and institutional archive

Design target: compatibility with PHR, HRW, Amnesty International, and similar documentation organizations' workflows, alongside a planned no-cost citizen tier requiring no account registration.

Pre-development now, build begins Q1 2027

The platform does not yet exist as software. Cryptographic architecture and field requirements are complete; engineering build is contingent on seed funding closing on this timeline. Field-informed design work continues throughout development, grounded in real operational conditions across military, human rights, and investigative work.

Now, 2026
Pre-Development
  • Buyer validation interviews
  • Delaware C-Corp established
  • Cryptographic architecture finalized
  • SBIR application in progress
  • Seed round open
  • Core technical leadership in place
Q1–Q2 2027
v1.0 Foundation
  • Mobile app: all capture modalities
  • ML-DSA + Ed25519 signing
  • Chain of custody MVP
  • Berkeley Protocol alignment
  • First field pilot deployed
Q3–Q4 2027
v1.1 LE + Military
  • UCMJ / NATO package formats
  • Enforcement + battlefield modules
  • Air-gap server mode
  • Axon + DEMS integration
  • First LE + JAG pilots
  • Target: first paid license
Q1–Q2 2028
v1.2 Multi-domain
  • ICC + UJ package formats
  • Mass grave module
  • Multi-language UI
  • HSM + FIPS 140-3
  • ICMP compatibility
  • First UN mechanism pilot
Q3–Q4 2028
v2.0 Enterprise
  • Full case management
  • Gov cloud deployment
  • Cellebrite + Relativity + SIEM
  • General availability
  • Framework agreements active
  • Path to sustainability

What the design is built around

Each priority below is built to close a specific, documented failure mode. These are firm design commitments for the planned platform, not claims about a product that ships today.

01 / POST-QUANTUM FIRST

Built around NIST FIPS 203/204 from day one

Hybrid ML-DSA-65 + Ed25519 signing is designed to defeat harvest-now-decrypt-later attacks, a documented strategy already attributed to state-level adversaries collecting encrypted evidence today, before their targets' cryptography catches up.

02 / AIR-GAP CAPABLE

Designed for no server dependency

The architecture calls for all cryptographic functions to operate offline — intended for forward operating bases, mass grave excavation sites, conflict zones without connectivity, and classified military networks.

03 / BERKELEY PROTOCOL

Built toward full Protocol alignment

The UN/Berkeley Protocol has set the field's evidentiary bar since 2020, and no platform fully implements it yet. Kairos is designed to cover its full requirements end to end, which is intended to become a durable procurement advantage with institutional buyers who already evaluate against it.

04 / VENDOR-INDEPENDENT

Built to outlast Kairos itself

Packages are designed to be authenticated using liboqs and public NIST libraries, with no proprietary software, account, or Kairos infrastructure required. A 20-year prosecution shouldn't depend on a startup staying in business; the verification toolchain is meant to be bundled with the evidence, not hosted by Kairos.

05 / DOMAIN MODULES

Informed by field operations

Planned modules for mass grave excavation, battlefield forensic exploitation, and enforcement-action workflows are informed by field applications across military, human rights, and investigative work.

06 / INTEROPERABLE BY DESIGN

Built to extend existing tools, not replace them

The design includes an import pathway for evidence originated in other field-capture tools, preserving original signatures while extending them with Kairos's custody and packaging layer — complementary infrastructure for organizations already using established collection tools, not a wholesale replacement.

The architecture is designed. The gap it closes is real now.

We're in buyer validation and active forensic consulting today, shaping the platform ahead of a Q1 2027 build. If you evaluate digital evidence for a living, we want your read on the design.

Discuss the architecture
Platform
Solutions overview Field collection Chain of custody Court packages Post-quantum security
Services
Services overview Forensic consulting Institutional integration Pilot programs Expert witness
Company
About Resources Contact contact@kairosforensics.com Khthon — operational validator
© 2026 Kairos Forensics Inc. — kairosforensics.com
Kairos Forensics Inc. — Delaware C-Corp