Lumra receives operational event metadata from systems you already use, seals it on receipt, and verifies an enrolled source signature when one is present. It produces portable evidence records that another party can check without needing our servers or cooperation. The proof covers integrity and the recorded workflow, not whether a sensor told the truth.
No new hardware for systems that can send a webhook. TTN and other IoT feeds are onboarded through a controlled pilot.
Legal defense, settlement pressure, denied claims, a lost contract: the cost of one incident you cannot prove usually dwarfs the cost of proving everything. Insurers run this math every day.
US federal evidence rules 902(13) and 902(14) provide procedures for authenticating certain electronic evidence through a qualified person's written certification. A Lumra export can support that process; it does not make evidence automatically admissible.
Lumra seals the received event with a non-extractable cloud HSM key. If an enrolled device or sending platform already signed the payload, Lumra also preserves and verifies that source signature. The two states are labelled separately.
Compact signed digests are hash-chained into a tamper-evident ledger. We never need your raw video or audio. Privacy is the architecture, not a setting.
A standalone verifier re-checks any record with no PriviNet servers involved. The proof survives us. That's the point. Go try to break one in the demo above.
Integration: a controlled pilot connects one webhook or API feed, confirms tenant isolation and retry behavior, and then produces sample records for your own technical or claims reviewer to verify.
Lumra's production service, isolated staging candidate, and research branches are not the same thing. A pilot proposal identifies the exact revision, trust roots, data path, and success checks before any customer traffic is connected.
The current candidate accepts the complete original The Things Stack uplink JSON and derives a tenant-scoped identity for ordinary TTN retries. Production activation remains controlled, with PostgreSQL concurrency and tenant checks included in release acceptance.
The standalone verifier checks the package without contacting PriviNet, fails on altered signed content, and requires trust to be supplied separately for non-production keys. OpenSSL is required for RFC 3161 timestamp verification.
An optional batch-root profile is implemented on a review branch. No real qualified token has been validated, so qualification remains INDETERMINATE. Lumra does not currently claim an EU-qualified ProofPack or eIDAS compliance.
What the evidence can show: which bytes were sealed, which enrolled key signed them, how included records relate, and what external timestamp evidence is present. It cannot prove physical-world truth, complete capture, or a guaranteed legal outcome.
Live coverage, every record's proof status, and one-click ProofPacks. These are real screenshots of the live product with synthetic pilot data.
coverage at a glance · signed as they arrive
every record carries its proof status
device health, check-in schedules, offline alerts
the ProofPack button on every record
See how Lumra preserves, seals, timestamps, and independently verifies operational evidence, including the limits of what each proof establishes.



| Operation | The incident | What the record settles |
|---|---|---|
| Senior & memory care | A resident wanders; response timeline disputed | Signed proof of when the alert fired and who was notified |
| Fleets & dashcams | Collision, "your driver ran the light" | Impact event, time, and location, verifiable by the insurer, not just claimed |
| Ports & cargo | Container tampered somewhere along the chain | Which custody window it happened in |
| Airports & aviation | Perimeter breach, ground-handling damage | Independently checkable sequence of events |
| Security & facilities | Guard tour disputed, footage authenticity challenged | Event digests that survive vendor changes |
| Industrial & energy | Equipment failure blame between operator and OEM | Sensor anomaly trail neither side can rewrite without detection |
| Cold chain & logistics | Spoilage claim: whose leg of the trip broke the temperature | Signed temperature and time trail showing which custody window breached the threshold |
| Construction & sites | Site-damage or safety claim: who was on site, when | Signed access, equipment, and check-in events neither side can backdate without detection once exported |
Not on the list? If your operation already runs sensors, cameras, access logs, GPS, or staff check-ins, Lumra turns those events into proof before a dispute starts. Same signed record, same standalone verifier, whatever the sector.
→ Found your row, or recognize the pattern? Run the 3-minute provability audit for your operation
Pick your industry and the systems you run. In about two minutes you'll have a report of the events that decide disputes in your world, which ones you're capturing, which are provable, and where the gaps are. No email needed to see your results.
Four ways this plays out. In every one, notice two things: the proof was created before anyone knew it would matter, and it's the other side who runs the verifier. Proof only exists where a signal was captured and signed, which is why every pilot starts by mapping your coverage. And when you would rather test us than believe us, bring the adversarial pilot script: ten ways to try to break the system during your pilot, with the expected result for each.
An 80-bed facility, GPS wearables on wander-risk residents. Eight months after a 2 a.m. incident, a lawsuit claims staff ignored the alert for 40 minutes. How the data got in: the facility's existing wearable platform posts each alert to Lumra over a webhook; nothing was replaced.
The verification: plaintiff's own expert runs the free verifier. Inserting the 02:19 record later breaks every following link; the receipt-ordered chain and the export-time independent timestamps bracket when it could have existed. The 40-minute theory now has to contend with a verifiable timeline instead of a mutable log, and the dispute can center on what actually happened (17 minutes, protocol followed) instead of a jury guessing whose logs to believe.
Illustrative scenario, how the system is designed to work.
A 40-truck fleet with dashcams. Intersection collision; the other driver's insurer demands the footage, and hints it will challenge the video's authenticity. How the data got in: the fleet's existing telematics platform sent the impact event and the clip hashes to the Lumra API over a webhook; the video itself never left the recorder.
The verification: the opposing expert hashes the video file they received against h1…h4, hashes committed and signed the day of the crash, weeks before anyone knew there'd be a fight. They match; any edit after that day would have broken the match. With authenticity off the table, the claim turns on what the clip shows: a green light. And the chained recall log shows exactly who has ever viewed the footage.
Illustrative scenario, how the system is designed to work.
A container terminal. A pharmaceutical container reaches the consignee with a broken seal and product missing, and five custody parties blame each other. How the data got in: each party's own gate, yard, and seal systems send their events to Lumra as they happen, over webhooks or the events API.
The verification: the adjuster, who trusts nobody, runs the verifier on each party's records. The terminal's verify cleanly and bracket the incident to a custody window after gate-out. The terminal didn't win by being more believable; it won by being checkable. Five suspects narrow to one custody window, and the investigation starts there instead of in competing paperwork.
Illustrative scenario, how the system is designed to work.
An energy facility with vibration and temperature sensors on critical pumps. A pump fails catastrophically, a week of downtime. The OEM denies warranty: "your operators ignored the early warnings." How the data got in: the plant's existing IoT hub forwards sensor readings to Lumra over the events API; no sensor was touched.
The verification: the OEM's engineers replay the decision, recorded inputs through the recorded algorithm version reproduce the recorded output, byte for byte. The "obvious early warning" was scored low-risk by analytics both sides can now inspect; the operators were never told to act. The negligence theory now has to contend with a replayable record showing the warnings were scored low-risk, and the warranty conversation restarts on inspectable facts.
Illustrative scenario, how the system is designed to work.
Host the database, hold the keys, run the script, and you've built a closed loop: the party that benefits from the records controls every piece of the machinery that produced them.
In a deposition, the other side asks one question of a closed loop: could someone with a stake in this case have edited a row and re-run the script? There is no good answer. That is self-audited paperwork, and opposing counsel will say exactly that.
Lumra breaks the loop with separation of duties: events sealed as they arrive, chained beyond your administrative reach, and verified by a standalone open tool that never contacts PriviNet.
An in-house script produces a self-audited trail. Lumra produces records neither side has to take on faith.
Because anyone with admin access can edit them, and that's why adjusters and opposing counsel discount them. Lumra records are sealed the instant they arrive and chained; altering one breaks verification, as you saw above.
If your platform can send a webhook or an HTTPS request, yes: telematics platforms such as Samsara, Motive, and Geotab support webhooks, as do most VMS and IoT hubs, and anything custom can call the events API directly. Consumer devices with no webhook output need a small bridge; ask us and we will point you at the shortest path. No hardware is replaced and no media is uploaded.
They can, and it will read as self-audited paperwork the day it matters: when your company controls the database, the keys, and the script, there is no good answer to "could the hashing have been re-run after an edit?" Lumra provides the separation of duties: records sealed the instant they arrive, signed at the source where the device supports it, chained outside your administrative reach, and verifiable by the other side with open tools that never contact PriviNet.
Object Lock protects retained objects from later change. Lumra adds signed records, explicit receipt ordering, package manifests, and a verifier another party can run without access to your cloud account. When an RFC 3161 token is present, the verifier checks what digest it covers and reports its timing scope. These controls complement locked storage; neither one proves that the source event was true or that every expected event was captured.
No. Lumra works from compact signed metadata. Raw media stays yours; it can only be recalled under an audited, logged process. We can't leak footage we never receive.
Your records outlive us. The verifier is a standalone open tool that never phones home; anyone can re-check any record for as long as they keep it, with no PriviNet server involved. Proof that requires trusting the vendor isn't proof.
No tokens, no mining, no consensus fees. Just the boring, court-tested cryptography (ECDSA and Ed25519 signatures, SHA-256 hash chains) that federal evidence rules already recognize.
Dashcam footage holds up when you can prove nobody edited it after the fact. Your video platform hashes each segment; Lumra seals those hashes the moment they arrive into a tamper-evident chain. Under Federal Rules of Evidence 902(13) and 902(14), hash-verified records like these can self-authenticate through a qualified person's written certification rather than live testimony. Weeks later, anyone can hash the file they received and match it against the hashes committed on the day of the incident.
A tamper-evident audit log is a record of alerts, notifications, and responses that cannot be edited after the fact without detection. Lumra signs each event the instant it arrives, such as a geofence exit or a staff acknowledgment, and chains it to the previous record. If an entry is altered or inserted later, verification fails. Opposing experts can check the timeline themselves with a free standalone verifier.
Chain of custody is proven by signed records at each handoff. Lumra seals gate-in, yard moves, seal checks, and gate-out events the moment they arrive, verifies the device's own signature where source keys are enrolled, then chains the records so any rewrite is detectable. When a container arrives damaged, an adjuster who trusts no party can verify each record independently and narrow the loss to a specific custody window instead of relying on competing paperwork.
A cryptographically verifiable event record is an event that is digitally signed where it happens when the device supports signing, or sealed on arrival when it does not, and linked by hash to the record before it. The signature proves which enrolled device or person created it, or that Lumra sealed it on arrival, and the hash chain proves nothing was altered, inserted, or deleted afterward. Verification requires only the exported records and open cryptographic checks, not access to the vendor's systems.
Different job. Evidence-management platforms are vaults: you upload media and trust whoever runs the vault. Photo-verification apps authenticate media captured through their own camera flow, and nothing outside it. Free timestamping proves a hash existed by a certain time, with no event, no custody, no paperwork. Lumra signs the operational events themselves, from the systems you already run, never takes your media, and hands you records anyone can verify plus the certification template to use them. And unlike most of the category, the pricing is on this page.
The exported package is checked outside PriviNet: the standalone verifier recomputes signed content, checks the package structure and trust root, and fails if protected content was changed. Production signing uses a non-extractable cloud HSM key. External timestamp evidence is reported separately and only proves the digest existed by the token time; missing or unconfirmed trust is shown instead of rounded up.
Verifying a supported ProofPack is free and needs no PriviNet server. A ProofPack is a portable evidence package containing signed records, package metadata, verification instructions, and, where applicable, timestamp and certification material. It can support a legal or insurance evidence workflow, but it is not itself a legal conclusion or guarantee of admissibility.
A fixed, versioned checklist that runs on every record and reports only what it found: whether the source signature was present and verified, whether the timing lines up, the chain of custody, and, across a multi-source incident, whether independent vendors' records agree. It is enumerated facts, not a score and not an opinion about what happened. When nothing is flagged it says so by name, listing the checks that ran. It rides inside the sealed pack, so altering it breaks verification like any other sealed value. It is there to help a reader weigh the evidence, never to decide fact or liability.
PriviNet began as a private network for IoT devices. Our engineers kept hitting the same wall: privacy protects data; it doesn't prove anything. Safety lives in verification.
Founder Brad Listermann spent years consulting on the sale of high-end encryption, work he still can't say much about. Lumra is that obsession rebuilt as software anyone can check; Decern, our sister project, extends it toward a post-quantum world.
Every record Lumra signs verifies independently. No PriviNet login, no PriviNet goodwill required. Scroll up and try to forge one. That's the whole pitch.
Your records stay signed and chained in the background. ProofPack is the portable package you request when the record matters: one incident assembled so your insurer, adjuster, counsel, or technical reviewer can run the verification themselves.
It is not a database export. It is the finished artifact a records custodian signs and forwards, with the verification already done and the paperwork already drafted.
A design-partner pilot includes portable ProofPacks generated from the agreed pilot workflow. Your own reviewer tests what each package proves, what it does not prove, and whether it would improve an actual dispute or investigation.
Not a mockup: generated by the live engine from a demonstration incident. Want to check it yourself? Download the machine JSON and run the standalone verifier; every hash reproduces and the signature checks.
Lumra is taking on a limited number of design partners in 2026. Fixed scope, written success criteria, controlled onboarding, and portable ProofPacks from the agreed workflow.
One line of business, one data source, up to 500 monitored assets.
Production programs start at $30,000/year. Multi-region or multi-carrier deployments are scoped individually.
Send us one day of telematics or sensor data and we'll return a signed ProofPack, free.
Verification of your records is always free; a ProofPack is the assembled, certification-ready deliverable. Insurer and platform programs (VMS, dashcam, telematics, and wearable providers embedding Lumra): custom annual terms.
Five slots for 2026. Sixty days at fixed scope: one line of business, one data source, up to 500 monitored assets, and portable ProofPacks from the agreed pilot workflow.
Request a design-partner slot →
Not ready for a pilot? Send us one day of telematics or sensor data and we'll return a signed ProofPack, free. We reply within one business day either way.
Not sure what you'd even need to capture? Run the 3-minute audit first →