Lumra seals every event the moment it arrives, and at the source where the device supports it: gate, camera, sensor, dashcam. It chains each one into a record that courts, insurers, and auditors can verify independently, without needing our servers or cooperation. It's insurance for your operational truth.
No new hardware, nothing replaced, plugs into the systems you already run. Signing real events the same afternoon.
Legal defense, settlement pressure, denied claims, a lost contract: the cost of one incident you cannot prove usually dwarfs the cost of proving everything. Insurers run this math every day.
US federal evidence rules (902(13)/(14)) let hash-verified records self-authenticate through a written certification instead of live witness testimony. Lumra records and their export pack are built to support exactly that certification.
Every event is signed the moment Lumra receives it, with a production key held in a cloud HSM no one can extract. Edge-capable devices sign at the source themselves. Either way, the record is tamper-evident from that instant.
Compact signed digests are hash-chained into a tamper-evident ledger. We never need your raw video or audio. Privacy is the architecture, not a setting.
A standalone verifier re-checks any record with no PriviNet servers involved. The proof survives us. That's the point. Go try to break one in the demo above.
Integration: point a webhook from your VMS, telematics, or IoT platform at Lumra. Typical pilot is signing real events the same afternoon.
Live coverage, every record's proof status, and one-click ProofPacks. These are real screenshots of the live product with synthetic pilot data.
coverage at a glance · signed as they arrive
every record carries its proof status
device health, check-in schedules, offline alerts
the ProofPack button on every record
A record is sealed and verified; then one character changes and verification fails. That is the product.



| Operation | The incident | What the record settles |
|---|---|---|
| Senior & memory care | A resident wanders; response timeline disputed | Signed proof of when the alert fired and who was notified |
| Fleets & dashcams | Collision, "your driver ran the light" | Impact event, time, and location, verifiable by the insurer, not just claimed |
| Ports & cargo | Container tampered somewhere along the chain | Which custody window it happened in |
| Airports & aviation | Perimeter breach, ground-handling damage | Independently checkable sequence of events |
| Security & facilities | Guard tour disputed, footage authenticity challenged | Event digests that survive vendor changes |
| Industrial & energy | Equipment failure blame between operator and OEM | Sensor anomaly trail neither side can rewrite without detection |
| Cold chain & logistics | Spoilage claim: whose leg of the trip broke the temperature | Signed temperature and time trail showing which custody window breached the threshold |
| Construction & sites | Site-damage or safety claim: who was on site, when | Signed access, equipment, and check-in events neither side can backdate without detection once exported |
Not on the list? If your operation already runs sensors, cameras, access logs, GPS, or staff check-ins, Lumra turns those events into proof before a dispute starts. Same signed record, same standalone verifier, whatever the sector.
→ Found your row, or recognize the pattern? Run the 3-minute provability audit for your operation
Pick your industry and the systems you run. In about two minutes you'll have a report of the events that decide disputes in your world, which ones you're capturing, which are provable, and where the gaps are. No email needed to see your results.
Four ways this plays out. In every one, notice two things: the proof was created before anyone knew it would matter, and it's the other side who runs the verifier. Proof only exists where a signal was captured and signed, which is why every pilot starts by mapping your coverage. And when you would rather test us than believe us, bring the adversarial pilot script: ten ways to try to break the system during your pilot, with the expected result for each.
An 80-bed facility, GPS wearables on wander-risk residents. Eight months after a 2 a.m. incident, a lawsuit claims staff ignored the alert for 40 minutes. How the data got in: the facility's existing wearable platform posts each alert to Lumra over a webhook; nothing was replaced.
The verification: plaintiff's own expert runs the free verifier. Inserting the 02:19 record later breaks every following link; the receipt-ordered chain and the export-time independent timestamps bracket when it could have existed. The 40-minute theory now has to contend with a verifiable timeline instead of a mutable log, and the dispute can center on what actually happened (17 minutes, protocol followed) instead of a jury guessing whose logs to believe.
Illustrative scenario, how the system is designed to work.
A 40-truck fleet with dashcams. Intersection collision; the other driver's insurer demands the footage, and hints it will challenge the video's authenticity. How the data got in: the fleet's existing telematics platform sent the impact event and the clip hashes to the Lumra API over a webhook; the video itself never left the recorder.
The verification: the opposing expert hashes the video file they received against h1…h4, hashes committed and signed the day of the crash, weeks before anyone knew there'd be a fight. They match; any edit after that day would have broken the match. With authenticity off the table, the claim turns on what the clip shows: a green light. And the chained recall log shows exactly who has ever viewed the footage.
Illustrative scenario, how the system is designed to work.
A container terminal. A pharmaceutical container reaches the consignee with a broken seal and product missing, and five custody parties blame each other. How the data got in: each party's own gate, yard, and seal systems send their events to Lumra as they happen, over webhooks or the events API.
The verification: the adjuster, who trusts nobody, runs the verifier on each party's records. The terminal's verify cleanly and bracket the incident to a custody window after gate-out. The terminal didn't win by being more believable; it won by being checkable. Five suspects narrow to one custody window, and the investigation starts there instead of in competing paperwork.
Illustrative scenario, how the system is designed to work.
An energy facility with vibration and temperature sensors on critical pumps. A pump fails catastrophically, a week of downtime. The OEM denies warranty: "your operators ignored the early warnings." How the data got in: the plant's existing IoT hub forwards sensor readings to Lumra over the events API; no sensor was touched.
The verification: the OEM's engineers replay the decision, recorded inputs through the recorded algorithm version reproduce the recorded output, byte for byte. The "obvious early warning" was scored low-risk by analytics both sides can now inspect; the operators were never told to act. The negligence theory now has to contend with a replayable record showing the warnings were scored low-risk, and the warranty conversation restarts on inspectable facts.
Illustrative scenario, how the system is designed to work.
Host the database, hold the keys, run the script, and you've built a closed loop: the party that benefits from the records controls every piece of the machinery that produced them.
In a deposition, the other side asks one question of a closed loop: could someone with a stake in this case have edited a row and re-run the script? There is no good answer. That is self-audited paperwork, and opposing counsel will say exactly that.
Lumra breaks the loop with separation of duties: events sealed as they arrive, chained beyond your administrative reach, and verified by a standalone open tool that never contacts PriviNet.
An in-house script produces a self-audited trail. Lumra produces records neither side has to take on faith.
Because anyone with admin access can edit them, and that's why adjusters and opposing counsel discount them. Lumra records are sealed the instant they arrive and chained; altering one breaks verification, as you saw above.
If your platform can send a webhook or an HTTPS request, yes: telematics platforms such as Samsara, Motive, and Geotab support webhooks, as do most VMS and IoT hubs, and anything custom can call the events API directly. Consumer devices with no webhook output need a small bridge; ask us and we will point you at the shortest path. No hardware is replaced and no media is uploaded.
They can, and it will read as self-audited paperwork the day it matters: when your company controls the database, the keys, and the script, there is no good answer to "could the hashing have been re-run after an edit?" Lumra provides the separation of duties: records sealed the instant they arrive, signed at the source where the device supports it, chained outside your administrative reach, and verifiable by the other side with open tools that never contact PriviNet.
Object Lock does one thing well: nothing in the bucket changes during the lock. That is storage immutability inside a closed loop you administer. No signature says who created the record or when. No independent timestamp fixes it in time. And the other side can only check it by being handed access to your cloud account. Lumra adds what the bucket cannot: records signed at intake, two independent third-party timestamps sought from unrelated authorities, and a ProofPack anyone verifies offline, no access to your systems required. The two compose: our own evidence archive is retention-locked WORM storage, and a pack stays just as verifiable archived in your own locked bucket.
No. Lumra works from compact signed metadata. Raw media stays yours; it can only be recalled under an audited, logged process. We can't leak footage we never receive.
Your records outlive us. The verifier is a standalone open tool that never phones home; anyone can re-check any record for as long as they keep it, with no PriviNet server involved. Proof that requires trusting the vendor isn't proof.
No tokens, no mining, no consensus fees. Just the boring, court-tested cryptography (ECDSA and Ed25519 signatures, SHA-256 hash chains) that federal evidence rules already recognize.
Dashcam footage holds up when you can prove nobody edited it after the fact. Your video platform hashes each segment; Lumra seals those hashes the moment they arrive into a tamper-evident chain. Under Federal Rules of Evidence 902(13) and 902(14), hash-verified records like these can self-authenticate through a qualified person's written certification rather than live testimony. Weeks later, anyone can hash the file they received and match it against the hashes committed on the day of the incident.
A tamper-evident audit log is a record of alerts, notifications, and responses that cannot be edited after the fact without detection. Lumra signs each event the instant it arrives, such as a geofence exit or a staff acknowledgment, and chains it to the previous record. If an entry is altered or inserted later, verification fails. Opposing experts can check the timeline themselves with a free standalone verifier.
Chain of custody is proven by signed records at each handoff. Lumra seals gate-in, yard moves, seal checks, and gate-out events the moment they arrive, verifies the device's own signature where source keys are enrolled, then chains the records so any rewrite is detectable. When a container arrives damaged, an adjuster who trusts no party can verify each record independently and narrow the loss to a specific custody window instead of relying on competing paperwork.
A cryptographically verifiable event record is an event that is digitally signed where it happens when the device supports signing, or sealed on arrival when it does not, and linked by hash to the record before it. The signature proves which enrolled device or person created it, or that Lumra sealed it on arrival, and the hash chain proves nothing was altered, inserted, or deleted afterward. Verification requires only the exported records and open cryptographic checks, not access to the vendor's systems.
Different job. Evidence-management platforms are vaults: you upload media and trust whoever runs the vault. Photo-verification apps authenticate media captured through their own camera flow, and nothing outside it. Free timestamping proves a hash existed by a certain time, with no event, no custody, no paperwork. Lumra signs the operational events themselves, from the systems you already run, never takes your media, and hands you records anyone can verify plus the certification template to use them. And unlike most of the category, the pricing is on this page.
Three things, all live today. First, checking records never runs through us: the standalone verifier works offline, so any change to a sealed value fails in front of whoever runs it. Second, every export freezes the record: a ProofPack in your hands stays verifiable whatever happens to our servers. Third, our production signing key lives in a hardware security module we cannot extract, and every ProofPack seeks two independent third-party timestamps from unrelated authorities, the second sealed inside the pack, so the record and its place in time do not rest on our word or our clock, or on any single timestamp authority.
Verifying your records is always free and needs no PriviNet servers. A ProofPack is the assembled, court-ready file for a single incident: the signed records, a verification transcript, standalone verifier instructions, and a pre-filled FRE 902(13)/(14) certification template for your qualified person to sign. It is the assembled deliverable you request when a dispute lands; design-partner pilots include a court-ready ProofPack for every record we sign.
A fixed, versioned checklist that runs on every record and reports only what it found: whether the source signature was present and verified, whether the timing lines up, the chain of custody, and, across a multi-source incident, whether independent vendors' records agree. It is enumerated facts, not a score and not an opinion about what happened. When nothing is flagged it says so by name, listing the checks that ran. It rides inside the sealed pack, so altering it breaks verification like any other sealed value. It is there to help a reader weigh the evidence, never to decide fact or liability.
PriviNet began as a private network for IoT devices. Our engineers kept hitting the same wall: privacy protects data; it doesn't prove anything. Safety lives in verification.
Founder Brad Listermann spent years consulting on the sale of high-end encryption, work he still can't say much about. Lumra is that obsession rebuilt as software anyone can check; Decern, our sister project, extends it toward a post-quantum world.
Every record Lumra signs verifies independently. No PriviNet login, no PriviNet goodwill required. Scroll up and try to forge one. That's the whole pitch.
Your records stay signed and chained in the background. ProofPack is what you request the day it matters: one incident, assembled into a single court-ready file your insurer, adjuster, or counsel can verify themselves.
It is not a database export. It is the finished artifact a records custodian signs and forwards, with the verification already done and the paperwork already drafted.
A design-partner pilot includes a court-ready ProofPack for every record we sign, generated from your own operation. You see exactly what lands on your desk before you ever need it.
Not a mockup: generated by the live engine from a demonstration incident. Want to check it yourself? Download the machine JSON and run the standalone verifier; every hash reproduces and the signature checks.
Lumra is taking on a limited number of design partners in 2026. Fixed scope, written success criteria, and a court-ready ProofPack for every record we sign.
One line of business, one data source, up to 500 monitored assets.
Production programs start at $30,000/year. Multi-region or multi-carrier deployments are scoped individually.
Send us one day of telematics or sensor data and we'll return a signed ProofPack, free.
Verification of your records is always free; a ProofPack is the assembled, certification-ready deliverable. Insurer and platform programs (VMS, dashcam, telematics, and wearable providers embedding Lumra): custom annual terms.
Five slots for 2026. Sixty days at fixed scope: one line of business, one data source, up to 500 monitored assets, and a court-ready ProofPack for every record we sign.
Request a design-partner slot →
Not ready for a pilot? Send us one day of telematics or sensor data and we'll return a signed ProofPack, free. We reply within one business day either way.
Not sure what you'd even need to capture? Run the 3-minute audit first →