Skip to content
SPEARTRACEMedia Forensics
[ CAPABILITY 05 / 05 · DEPLOYMENT ]

AIR-GAPPEDPLATFORM.

One platform for every sensor, deployable entirely inside your network. Chain of custody, role-based access and signed reports are built in, and external models can be added later without changing the evidence trail.

[ 01 / Paradigm shift ]

Target vs Reality

Current

Evidence in Someone Else's Cloud

Sensitive material is uploaded to external services, with unclear retention and no control over where analysis runs.

Target

Evidence Stays Home

The full platform installs on hardware you control, runs without internet access and keeps its own tamper-evident record.

[ 02 / Method ]

Architecture

  1. 01Ingest

    Files arrive by upload, watched folder or API.

  2. 02Seal

    Originals are hashed and written to write-once storage.

  3. 03Analyse

    Sensors run in isolated workers on your hardware.

  4. 04Report

    Signed reports are exported with the custody log.

Evidence Analysis Platform

Control planeAnalysis plane

  1. 01Evidence Intake

    FILE / STREAM

    Files arrive by upload, watched folder or API. Nothing is trusted yet and nothing is altered.

  2. 02Seal & Hash

    SHA-256 · WORM

    The original is hashed and written to write-once storage. All later steps read copies.

  3. 03Sensor Bank

    CLASSICAL · INDEPENDENT

    Independent forensic sensors measure the file. Each reports what it observed, with its settings.

  4. 04Corroboration

    EXPLAINABLE SCORE

    Sensor results are combined into a score that shows which sensors agree and which do not.

  5. 05Signed Report

    REPRODUCIBLE

    A report lists inputs, software versions and parameters so another examiner can repeat the analysis.

  6. Control plane / CUSTODY LOG

    Case Ledger

    Every action on a file is appended to a tamper-evident log: who, when, what, which version.

  7. Control plane / ROLES · AUDIT

    Access & Policy

    Role-based access, case-level permissions and an audit trail that cannot be edited from the interface.

  8. Optional / PHASE 2 · OFFLINE-SAFE

    Model Adapters

    Optional adapters let approved external models add evidence. The platform works fully without them.

[ 03 / Core systems ]

Core systems

01 / CUSTODY01 / 03

CHAIN OFCUSTODY

Every action on every file is recorded in an append-only log.

HASHING · LEDGER · TIMESTAMPS

Prove what happened to the evidence.

SEAL
Hash and timestamp the original before any processing.
TRACE
Log each access, analysis and export against a named user.
VERIFY
Re-check hashes at any time and show the result in the report.
02 / ACCESS02 / 03

ACCESSCONTROL

Examiners see the cases assigned to them and nothing else.

ROLES · CASE PERMISSIONS · AUDIT

Least access by default.

ROLES
Examiner, reviewer, administrator and read-only roles.
CASES
Permissions apply to cases, and reviewers can be added per case.
AUDIT
Administrator actions are logged in the same ledger and cannot be hidden.
03 / DEPLOYMENT03 / 03

ON-PREMISEDELIVERY

Designed to be installed and operated without any outside connection.

AIR-GAP · LOCAL LICENCE · SOURCE ACCESS

Install it, own it, run it offline.

INSTALL
Delivered for your hardware, including offline installation and updates.
LICENCE
Local licensing that does not require a call home.
EXTEND
Optional adapters let approved models contribute evidence, with outputs recorded like any other sensor.
[ 04 / Reference patterns ]

Where it applies

GOVERNMENT

National forensic laboratory

A central platform serving multiple examiners with case-level access.

LAW ENFORCEMENT

Field and unit deployments

Standalone installations that work with no connectivity.

FINANCIAL

Bank fraud operations

An on-premise service behind the bank's own case management.

[ 05 / Delivery & deployment ]

From design to delivery

We scope the hardware, install the platform, train your examiners and hand over documentation. Technology transfer and source-code delivery are available on request.

[ 06 / Questions ]

Common questions

What does SpearTrace do for air-gapped forensics?

One platform for every sensor, deployable entirely inside your network. Chain of custody, role-based access and signed reports are built in, and external models can be added later without changing the evidence trail.

What changes compared with the current approach?

Sensitive material is uploaded to external services, with unclear retention and no control over where analysis runs. The full platform installs on hardware you control, runs without internet access and keeps its own tamper-evident record.

Can it run on-premise or air-gapped?

Yes. Analysis runs on your own hardware, and the platform can be installed with no connectivity. Reports are exported as signed PDF and machine-readable JSON.

How do I start?

Request a briefing by form, WhatsApp (+60 17-773 7302) or email (kumar@spearcompute.com). We scope a pilot on samples you provide.

Bring the footage.Let’s verify.

Tell us what media you need to trust and where it has to be analysed. We will scope a briefing or a pilot on your own samples.

Request a briefing