One platform for every sensor, deployable entirely inside your network. Chain of custody, role-based access and signed reports are built in, and external models can be added later without changing the evidence trail.
[ 01 / Paradigm shift ]
Target vs Reality
Current
Evidence in Someone Else's Cloud
Sensitive material is uploaded to external services, with unclear retention and no control over where analysis runs.
Target
Evidence Stays Home
The full platform installs on hardware you control, runs without internet access and keeps its own tamper-evident record.
[ 02 / Method ]
Architecture
01Ingest
Files arrive by upload, watched folder or API.
02Seal
Originals are hashed and written to write-once storage.
03Analyse
Sensors run in isolated workers on your hardware.
04Report
Signed reports are exported with the custody log.
Evidence Analysis Platform
Control planeAnalysis plane
01Evidence Intake
FILE / STREAM
Files arrive by upload, watched folder or API. Nothing is trusted yet and nothing is altered.
02Seal & Hash
SHA-256 · WORM
The original is hashed and written to write-once storage. All later steps read copies.
03Sensor Bank
CLASSICAL · INDEPENDENT
Independent forensic sensors measure the file. Each reports what it observed, with its settings.
04Corroboration
EXPLAINABLE SCORE
Sensor results are combined into a score that shows which sensors agree and which do not.
05Signed Report
REPRODUCIBLE
A report lists inputs, software versions and parameters so another examiner can repeat the analysis.
Control plane / CUSTODY LOG
Case Ledger
Every action on a file is appended to a tamper-evident log: who, when, what, which version.
Control plane / ROLES · AUDIT
Access & Policy
Role-based access, case-level permissions and an audit trail that cannot be edited from the interface.
Optional / PHASE 2 · OFFLINE-SAFE
Model Adapters
Optional adapters let approved external models add evidence. The platform works fully without them.
Hover or tap a stage to inspect
[ 03 / Core systems ]
Core systems
01 / CUSTODY01 / 03
CHAIN OFCUSTODY
Every action on every file is recorded in an append-only log.
HASHING · LEDGER · TIMESTAMPS
Prove what happened to the evidence.
SEAL
Hash and timestamp the original before any processing.
TRACE
Log each access, analysis and export against a named user.
VERIFY
Re-check hashes at any time and show the result in the report.
02 / ACCESS02 / 03
ACCESSCONTROL
Examiners see the cases assigned to them and nothing else.
ROLES · CASE PERMISSIONS · AUDIT
Least access by default.
ROLES
Examiner, reviewer, administrator and read-only roles.
CASES
Permissions apply to cases, and reviewers can be added per case.
AUDIT
Administrator actions are logged in the same ledger and cannot be hidden.
03 / DEPLOYMENT03 / 03
ON-PREMISEDELIVERY
Designed to be installed and operated without any outside connection.
AIR-GAP · LOCAL LICENCE · SOURCE ACCESS
Install it, own it, run it offline.
INSTALL
Delivered for your hardware, including offline installation and updates.
LICENCE
Local licensing that does not require a call home.
EXTEND
Optional adapters let approved models contribute evidence, with outputs recorded like any other sensor.
[ 04 / Reference patterns ]
Where it applies
GOVERNMENT
National forensic laboratory
A central platform serving multiple examiners with case-level access.
LAW ENFORCEMENT
Field and unit deployments
Standalone installations that work with no connectivity.
FINANCIAL
Bank fraud operations
An on-premise service behind the bank's own case management.
[ 05 / Delivery & deployment ]
From design to delivery
We scope the hardware, install the platform, train your examiners and hand over documentation. Technology transfer and source-code delivery are available on request.
What does SpearTrace do for air-gapped forensics?+
One platform for every sensor, deployable entirely inside your network. Chain of custody, role-based access and signed reports are built in, and external models can be added later without changing the evidence trail.
What changes compared with the current approach?+
Sensitive material is uploaded to external services, with unclear retention and no control over where analysis runs. The full platform installs on hardware you control, runs without internet access and keeps its own tamper-evident record.
Can it run on-premise or air-gapped?+
Yes. Analysis runs on your own hardware, and the platform can be installed with no connectivity. Reports are exported as signed PDF and machine-readable JSON.
How do I start?+
Request a briefing by form, WhatsApp (+60 17-773 7302) or email (kumar@spearcompute.com). We scope a pilot on samples you provide.