Kairos Forensics
Kairos Forensics
Home Solutions Services About Contact
Skip to main content

Kairos Forensics

K
Kairos Forensics Cryptographic Evidence Platform
Solutions: Kairos Forensics
The planned platform

Post-quantum evidence integrity,
from capture to verdict.

The evidentiary record in atrocity investigations, corruption prosecutions, and human rights cases fails at a structural level: prosecutors are forced to prove authenticity through human testimony because no cryptographic infrastructure exists to do it for them. That is not a minor gap in a $6.9 trillion accountability problem, and it is not solved by better testimony. Kairos is designing the infrastructure to close it. CAPTURE, CME, and CMIS are an internal MVP in active build, targeting external release Q1 2027, contingent on seed funding.

Kairos Capture
app concept
The structural gap

Evidence fails because authentication has no infrastructure

By the time evidence reaches a prosecutor in The Hague, Berlin, or Amsterdam, a defense attorney can ask: how do we know this photograph was not edited? Under current practice, the answer is usually human testimony.

That is a weak foundation for prosecuting heads of state, and it is a foundation defense counsel knows how to attack. Kairos is designing cryptographic infrastructure built to answer that question on its own terms, independent of any witness's memory. The cases below show the range of ways the current approach fails; not all of them are failures a signing system alone resolves, and each is described on its own terms.

Custody gap

Caesar Files (Syria)

53,275 photographs documenting torture in Assad detention facilities, transferred with a custody record based almost entirely on human testimony rather than technical verification. Defense challenged authenticity throughout proceedings in Germany and France. An illustration of the capture-and-transfer gap a cryptographic custody log is designed to address.

ECCHR Case Documentation; Syrian Justice and Accountability Centre, 2022
No standard

Ukraine: active conflict documentation

Over 100 organizations collecting evidence with incompatible systems and no common integrity standard. Eurojust (2023) publicly flagged that existing frameworks are inadequate for future ICC prosecution — a gap of the kind a shared cryptographic standard is designed to close, though adoption across 100+ independent organizations is a significant undertaking in its own right.

Eurojust, "Digital Evidence in ICC Proceedings," 2023
Scope reduced

Myanmar: Rohingya documentation

The UN Fact-Finding Mission (2018) found individual incident evidence "frequently lacked the forensic integrity standards required for individual criminal prosecution." The ICJ case has relied substantially on statistical evidence, which the Mission's finding suggests was in part a consequence of that authentication gap — alongside the broader access and documentation constraints inherent to the situation.

UN Human Rights Council, A/HRC/39/64, 2018

Three layers: collection, custody, submission

This is the intended architecture. Each layer is designed to close a distinct, documented failure mode, and together they are built to produce a self-verifying evidence package that a prosecutor, judge, or defense expert can check without Kairos, or any server, still being around decades later.

01
CAPTURE · MVP live: Ed25519 + SHA-3-256 + AES-256-GCM · v1.1+: ML-DSA-65 hybrid

Kairos Capture

Designed for post-quantum hybrid signing at the moment of capture, before any file is written to device storage: a SHA-3-256 content hash computed in memory, signed with ML-DSA-65 + Ed25519, and bound to device identifier, GPS coordinate, and UTC timestamp. The design calls for fully offline operation with no server dependency, deployable in any environment.

Intended to capture: photo · video · audio · GPS coordinates · documents

Design basis

  • ML-DSA-65 (NIST FIPS 204)
  • Ed25519 (RFC 8032)
  • SHA-3-256 (FIPS 202)
  • iOS Secure Enclave
  • Android StrongBox
  • Offline-first design
02
CME · MVP in build: chain log + custody service · v1.1+: multi-org federation, air-gap mode

Kairos Chain

Designed so that every access, transfer, review, redaction, export, and annotation would be appended to a tamper-evident chain log, each entry signed and referencing the prior entry's hash, so modification would be detectable. Multi-organization sharing and air-gap or classified-network operation are core design requirements for this layer, not yet built.

Design basis

  • Hash-linked entries (prev_hash)
  • Per-action signing
  • Multi-org federation
  • Air-gap server mode
  • Classified network mode
  • RFC 3161 timestamps
03
CMIS · v1.1+ planned: submission package generation

Evidence Package Generator

Intended to auto-generate submission packages formatted for each target jurisdiction, each self-verifying using open-source NIST post-quantum libraries with no Kairos software or proprietary infrastructure required. The design goal is to bundle the verification toolchain with each package — aimed at multi-decade prosecution timelines — with Berkeley Protocol methodology documentation included per package.

Target formats

  • ICC Rules of Procedure
  • UCMJ / MCM
  • German StPO
  • Dutch CCP
  • IIIM · UNITAD · MMP
  • NGO archive formats

Designed across major legal frameworks

The intent is for Kairos submission packages to reduce authentication delays by auto-formatting for each target jurisdiction's rules of evidence. The frameworks below reflect current design scope and are expected to expand as procurement engagement grows; none of the formatting has been built yet.

International criminal

ICC: Rules of Procedure and Evidence

Intended to be formatted per ICC RPE Rules 63–64 (general provisions on evidence and admissibility), with Berkeley Protocol methodology documentation per package.

US Military Justice

UCMJ / Manual for Courts-Martial

Intended to be formatted per Military Rules of Evidence 901–902, with JAG, NCIS, OSI, and AFOSI workflows and an air-gap mode for classified environments as design targets.

Universal Jurisdiction: Germany

German StPO: Federal Prosecutor

Intended to be formatted for German Code of Criminal Procedure digital evidence standards, with BKA and Federal Prosecutor workflow compatibility as a design target.

Universal Jurisdiction: Netherlands

Dutch Code of Criminal Procedure

Intended to be formatted for Netherlands PNAT and Dutch CCP requirements, with Europol and Eurojust evidence-exchange compatibility as a design target.

UN Investigative Mechanisms

IIIM · UNITAD · MMP · IIMM

Intended to be formatted for UN investigative mechanism evidence submission standards, with ICMP identification workflow compatibility as a design target.

Human rights documentation

NGO and institutional archive

Design target: compatibility with PHR, HRW, Amnesty International, and similar documentation organizations' workflows, alongside a planned no-cost citizen tier requiring no account registration.

Internal MVP in build now, external launch targeted Q1 2027

CAPTURE, CME, and CMIS are an internal MVP in active build: classical signing (Ed25519 + SHA-3-256 + AES-256-GCM) is live internally. External platform access is contingent on seed funding closing on this timeline. Field-informed design work continues throughout development, grounded in real operational conditions across military, human rights, and investigative work.

Now, 2026
Internal MVP
  • Ed25519 + SHA-3-256 + AES-256-GCM signing (live internally)
  • Buyer validation interviews
  • Delaware C-Corp established
  • Cryptographic architecture finalized
  • SBIR application in progress
  • Seed round open
Q1–Q2 2027
v1.0 Foundation
  • Mobile app: all capture modalities
  • ML-DSA-65 hybrid signing added
  • Chain of custody MVP
  • Berkeley Protocol alignment
  • First field pilot deployed
Q3–Q4 2027
v1.1 LE + Military
  • UCMJ / NATO package formats
  • Enforcement + battlefield modules
  • Air-gap server mode
  • Axon + DEMS integration
  • First LE + JAG pilots
  • Target: first paid license
Q1–Q2 2028
v1.2 Multi-domain
  • ICC + UJ package formats
  • Mass grave module
  • Multi-language UI
  • HSM + FIPS 140-3
  • ICMP compatibility
  • First UN mechanism pilot
Q3–Q4 2028
v2.0 Enterprise
  • Full case management
  • Gov cloud deployment
  • Cellebrite + Relativity + SIEM
  • General availability
  • Framework agreements active
  • Path to sustainability

What the design is built around

Each priority below is built to close a specific, documented failure mode. These are firm design commitments for the planned platform, not claims about a product that ships today.

01 / POST-QUANTUM FIRST

Built around NIST FIPS 203/204 from day one

Hybrid ML-DSA-65 + Ed25519 signing is designed to defeat harvest-now-decrypt-later attacks, a documented strategy already attributed to state-level adversaries collecting encrypted evidence today, before their targets' cryptography catches up.

02 / AIR-GAP CAPABLE

Designed for no server dependency

The architecture calls for all cryptographic functions to operate offline — intended for forward operating bases, mass grave excavation sites, conflict zones without connectivity, and classified military networks.

03 / BERKELEY PROTOCOL

Built toward full Protocol alignment

The UN/Berkeley Protocol has set the field's evidentiary bar since 2020, and no platform fully implements it yet. Kairos is designed to cover its full requirements end to end, which is intended to become a durable procurement advantage with institutional buyers who already evaluate against it.

04 / VENDOR-INDEPENDENT

Built to outlast Kairos itself

Packages are designed to be authenticated using liboqs and public NIST libraries, with no proprietary software, account, or Kairos infrastructure required. A 20-year prosecution shouldn't depend on a startup staying in business; the verification toolchain is meant to be bundled with the evidence, not hosted by Kairos.

05 / DOMAIN MODULES

Informed by field operations

Planned modules for mass grave excavation, battlefield forensic exploitation, and enforcement-action workflows are informed by field applications across military, human rights, and investigative work.

06 / INTEROPERABLE BY DESIGN

Built to extend existing tools, not replace them

The design includes an import pathway for evidence originated in other field-capture tools, preserving original signatures while extending them with Kairos's custody and packaging layer — complementary infrastructure for organizations already using established collection tools, not a wholesale replacement.

CAPTURE, CME, and CMIS are in active internal build.

We’re in buyer validation today, shaping the platform ahead of a Q1 2027 external launch. If you evaluate digital evidence for a living, we want your read on the design.

Discuss the architecture
Platform
Solutions overview Field collection Chain of custody Court packages Post-quantum security
Services
Services overview Forensic consulting Institutional integration Pilot programs Expert witness
Company
About Resources Contact contact@kairosforensics.com Khthon — operational validator
© 2026 Kairos Forensics Inc. — kairosforensics.com
Kairos Forensics Inc. — Delaware C-Corp