Digital evidence · Digital twins · Access silicon

Proof, all the way down.

Most systems ask you to trust them. Ours are built so you don’t have to. Every claim we make about a piece of evidence, a model, or a chip can be recomputed by someone who has no reason to believe us.

INTAKE VERIFY
SEQ 0147 Evidence sealed at intakesha256 342b0a4212e73014b7654e20236b4b4fcdd65866608bbe6007e11f155d56a269 SEALED
SEQ 0149 Re-hashed from stored bytes — matchprev 181555434a1652c62314ff6e2577e1b6b9568051e873e76afbe4e7ac381180f3 VERIFIED

Fig. 01 — custody chain, illustrative

The through-line

One idea, four disciplines.

Digital forensics, ledgers, twins and silicon look like four different companies’ worth of work. They are one argument, carried through four layers: a fact is only useful if a stranger can check it.

  1. 01 · Prove

    Establish the fact

    Acquire from disk, memory, mobile, mail and network. Every artefact is hashed four ways at intake and worked on only as a derived copy whose digest provably matches the master.

  2. 02 · Preserve

    Make it unfalsifiable

    Each custody event joins an append-only hash chain, batched into a Merkle tree and anchored to a permissioned ledger. Alteration is not prevented — it is made visible.

  3. 03 · See

    Render it in space and time

    Scenes, networks and assets reconstructed as navigable twins — where each element still carries the provenance of the record it was built from. Visualisation that cannot quietly invent.

  4. 04 · Trust

    Anchor it in hardware

    Software integrity ends where the boot chain begins. Our access silicon carries a verified boot path, signed firmware with anti-rollback, and tamper-evident logging in the die itself.

Trust is not a claim. It is a computation somebody else can repeat.

4×Independent digests computed on every file at intake — SHA-256, SHA3-256, MD5 and SHA-1
77Workspaces and tools shipping across eight functional wings of the digital forensics portal
2Independent storage backends per artefact — content-addressed and region-routed
10GSymmetric line rate targeted by the XGS-PON member of the access SoC family

The substrate

Integrity is a pipeline, not a badge.

Five operations stand between a file arriving and an exhibit that survives cross-examination. Each leaves a cryptographic record the next one chains over — so the question “has this changed since you took it?” has an arithmetic answer rather than a procedural one.

  • Ingest. The device-computed digest is compared against one the server recomputes independently. Divergence is flagged into the custody trail, never quietly accepted.
  • Seal. Four digests at intake; the original is sealed and examiners work only on derived copies.
  • Encrypt. Per-file AES-256-GCM under a wrapped data key, written to two independent backends.
  • Anchor. Custody events join an append-only chain, Merkle-batched with per-record inclusion proofs.
  • Verify. Stored bytes are pulled back and re-hashed from scratch, on demand and continuously.
01 INGEST digest compared, divergence flagged 02 SEAL 4 digests, master sealed 03 ENCRYPT AES-256-GCM, 2 backends 04 ANCHOR merkle root committed 05 VERIFY re-hashed from stored bytes EVIDENCE IN

Fig. 02 — custody pipeline

Down at the bottom of the stack

The last place trust can be assumed away.

India is running the largest fibre build-out in its history on entirely imported access silicon, from a supply base that is narrowing rather than widening. Our access SoC family exists to close that gap — and to put a verified boot chain under the network the rest of this work depends on.

XRV-PONMAC1

PON MAC & OMCI core

GPON and XGS-PON media access control, ranging, dynamic bandwidth allocation, PON-layer encryption and an ONU management engine. Licensable as IP.

XRV-TRUST2

Trust subsystem

Verified secure boot from an immutable root, signed firmware update with anti-rollback, protected credential storage and tamper-evident logging.

XRV-ONT100

GPON terminal SoC

40 nm CMOS optical network terminal SoC with an indigenous RISC-V applications processor, integrated Ethernet switch and DDR interface.

XRV-ONT200

XGS-PON 10G variant

Symmetric 10 Gbit/s terminal SoC reusing the proven platform, adding a 10G-class SerDes and burst-mode optical interface.

Built against published specifications

Standards, implemented.

Listed because the work is written against them — not because a slide says so.

NIST FIPS 203 / 204ML-KEM and ML-DSA post-quantum key encapsulation and signatures
Electronic evidence certificationStatutory electronic-record certificates generated as signed, re-verifiable documents
ISO 19566-5 JUMBF · C2PAByte-level media provenance parsing with signing-chain validation
ITU-T G.984 · G.9807GPON and XGS-PON media access control and framing
Broadband Forum TR-069 / TR-369Remote management and provisioning agent in the terminal SoC
MITRE ATT&CKTechnique mapping across investigation findings and network analysis
SAML 2.0 XML-DSig · OIDCFederated identity with signature verification on assertion
Permissioned ledger anchoringMerkle-batched commitment with per-record inclusion proofs

Bring us something you need to be able to prove.

Investigation workflows, evidence integrity architecture, twin reconstruction, or access silicon integration — we will tell you plainly what we can and cannot do.