Edge Proof Network

You can't prevent every incident.
You can prove exactly what happened.

Lumra seals every event the moment it arrives, and at the source where the device supports it: gate, camera, sensor, dashcam. It chains each one into a record that courts, insurers, and auditors can verify independently, without needing our servers or cooperation. It's insurance for your operational truth.

Request a design-partner slot

No new hardware, nothing replaced, plugs into the systems you already run. Signing real events the same afternoon.

Incident record № 004-1187sha-256 digest check
eventgate.breach_detected
devicecam-east-04 (key #A2F1)
time
location33.9425, -118.4081
digestcomputing…
chain← №004-1186 · 9c41…e07b
Why now

Do the math your insurer already does

One incident

Legal defense, settlement pressure, denied claims, a lost contract: the cost of one incident you cannot prove usually dwarfs the cost of proving everything. Insurers run this math every day.

FRE 902

US federal evidence rules (902(13)/(14)) let hash-verified records self-authenticate through a written certification instead of live witness testimony. Lumra records and their export pack are built to support exactly that certification.

How it works

Sign. Chain. Verify. No new hardware.

01 · Sign

Sealed the instant it arrives

Every event is signed the moment Lumra receives it, with a production key held in a cloud HSM no one can extract. Edge-capable devices sign at the source themselves. Either way, the record is tamper-evident from that instant.

02 · Chain

Chained, not stored

Compact signed digests are hash-chained into a tamper-evident ledger. We never need your raw video or audio. Privacy is the architecture, not a setting.

03 · Verify

Verified by anyone

A standalone verifier re-checks any record with no PriviNet servers involved. The proof survives us. That's the point. Go try to break one in the demo above.

Integration: point a webhook from your VMS, telematics, or IoT platform at Lumra. Typical pilot is signing real events the same afternoon.

The product

The portal your team logs into

Live coverage, every record's proof status, and one-click ProofPacks. These are real screenshots of the live product with synthetic pilot data.

Portal coverage view: a green 4 of 4 ring reading All devices reporting, with records being signed and stored as they arrive

coverage at a glance · signed as they arrive

Portal incident records table: seven records, each with a green SIGNED proof chip, a record ID, and a ProofPack button

every record carries its proof status

Portal device table: four devices with last-report times, check-in schedules, and REPORTING status chips

device health, check-in schedules, offline alerts

The ProofPack dialog: a printable court-ready document, generated and downloaded from the record row in seconds

the ProofPack button on every record

See it run

Ninety seconds: seal, verify, alter, fail.

A record is sealed and verified; then one character changes and verification fails. That is the product.

Industries

The dispute you're one bad night away from

View through a rain-flecked truck windshield on a highway at dusk, tail lights ahead
fleets · every impact event signed
Rows of frosted refrigerated shipping containers in a port at dawn, cranes in the fog
cold chain · every temperature trail provable
A bright assisted-living corridor with wooden handrails, sunlit seating by a bay window
senior care · every response timeline beyond dispute
OperationThe incidentWhat the record settles
Senior & memory careA resident wanders; response timeline disputedSigned proof of when the alert fired and who was notified
Fleets & dashcamsCollision, "your driver ran the light"Impact event, time, and location, verifiable by the insurer, not just claimed
Ports & cargoContainer tampered somewhere along the chainWhich custody window it happened in
Airports & aviationPerimeter breach, ground-handling damageIndependently checkable sequence of events
Security & facilitiesGuard tour disputed, footage authenticity challengedEvent digests that survive vendor changes
Industrial & energyEquipment failure blame between operator and OEMSensor anomaly trail neither side can rewrite without detection
Cold chain & logisticsSpoilage claim: whose leg of the trip broke the temperatureSigned temperature and time trail showing which custody window breached the threshold
Construction & sitesSite-damage or safety claim: who was on site, whenSigned access, equipment, and check-in events neither side can backdate without detection once exported

Not on the list? If your operation already runs sensors, cameras, access logs, GPS, or staff check-ins, Lumra turns those events into proof before a dispute starts. Same signed record, same standalone verifier, whatever the sector.

→ Found your row, or recognize the pattern? Run the 3-minute provability audit for your operation

Free mini audit

Which disputes can you prove today?

Pick your industry and the systems you run. In about two minutes you'll have a report of the events that decide disputes in your world, which ones you're capturing, which are provable, and where the gaps are. No email needed to see your results.

Which of these do you run? (tap all that apply)
Anything else worth knowing? (optional)
Has a dispute like these come up in the last 12 months?
~2 minutes · results shown right here, ungated
Proof stories

The day the record had to hold

Four ways this plays out. In every one, notice two things: the proof was created before anyone knew it would matter, and it's the other side who runs the verifier. Proof only exists where a signal was captured and signed, which is why every pilot starts by mapping your coverage. And when you would rather test us than believe us, bring the adversarial pilot script: ten ways to try to break the system during your pilot, with the expected result for each.

An 80-bed facility, GPS wearables on wander-risk residents. Eight months after a 2 a.m. incident, a lawsuit claims staff ignored the alert for 40 minutes. How the data got in: the facility's existing wearable platform posts each alert to Lumra over a webhook; nothing was replaced.

02:14:09 · signed at source · chainedgps.geofence_exit, resident crosses the boundary
02:14:11 · decision record + input digestsrisk: CRITICAL → escalate, with the explanation factors recorded
02:14:12 · signedstaff notification dispatched
02:19:47 · signed · chainedstaff acknowledgment
02:31:02 · signedresident located, safe
8 months laterThe dispute: "That acknowledgment was added to the log afterward."

The verification: plaintiff's own expert runs the free verifier. Inserting the 02:19 record later breaks every following link; the receipt-ordered chain and the export-time independent timestamps bracket when it could have existed. The 40-minute theory now has to contend with a verifiable timeline instead of a mutable log, and the dispute can center on what actually happened (17 minutes, protocol followed) instead of a jury guessing whose logs to believe.

Illustrative scenario, how the system is designed to work.

A 40-truck fleet with dashcams. Intersection collision; the other driver's insurer demands the footage, and hints it will challenge the video's authenticity. How the data got in: the fleet's existing telematics platform sent the impact event and the clip hashes to the Lumra API over a webhook; the video itself never left the recorder.

14:47:04 · signed at sourcefleet.impact. G-force spike, GPS, speed
14:47:05 · signed window referenceevidence exists: 14:47:03-:23, four segments, hashes h1…h4, the video itself never leaves the recorder
+3 weeks · appended to same chainrecall request from the insurer → access decision → time-limited token → retrieval receipt
the dispute"Dashcam clips get edited all the time."

The verification: the opposing expert hashes the video file they received against h1…h4, hashes committed and signed the day of the crash, weeks before anyone knew there'd be a fight. They match; any edit after that day would have broken the match. With authenticity off the table, the claim turns on what the clip shows: a green light. And the chained recall log shows exactly who has ever viewed the footage.

Illustrative scenario, how the system is designed to work.

A container terminal. A pharmaceutical container reaches the consignee with a broken seal and product missing, and five custody parties blame each other. How the data got in: each party's own gate, yard, and seal systems send their events to Lumra as they happen, over webhooks or the events API.

06:02 · signed by gate sensorgate-in, seal intact
06:40-10:55 · signedyard position events
11:18 · signedgate-out to drayage, seal intact
the disputeThe adjuster trusts none of the five parties' logs. Ordinarily, whoever has the weakest paperwork eats the loss.

The verification: the adjuster, who trusts nobody, runs the verifier on each party's records. The terminal's verify cleanly and bracket the incident to a custody window after gate-out. The terminal didn't win by being more believable; it won by being checkable. Five suspects narrow to one custody window, and the investigation starts there instead of in competing paperwork.

Illustrative scenario, how the system is designed to work.

An energy facility with vibration and temperature sensors on critical pumps. A pump fails catastrophically, a week of downtime. The OEM denies warranty: "your operators ignored the early warnings." How the data got in: the plant's existing IoT hub forwards sensor readings to Lumra over the events API; no sensor was touched.

30 days of telemetry · signedvibration / temperature events
day −14 · decision recordanomaly scored LOW risk, recorded with algorithm version and the digests of its exact inputs
day 0 · signedcatastrophic failure event
the disputeNegligence or defect? $2M rides on what the operators were actually told.

The verification: the OEM's engineers replay the decision, recorded inputs through the recorded algorithm version reproduce the recorded output, byte for byte. The "obvious early warning" was scored low-risk by analytics both sides can now inspect; the operators were never told to act. The negligence theory now has to contend with a replayable record showing the warnings were scored low-risk, and the warranty conversation restarts on inspectable facts.

Illustrative scenario, how the system is designed to work.

The in-house question

Your IT team could hash logs in a weekend. Here is why it reads as self-audited paperwork in a deposition.

Host the database, hold the keys, run the script, and you've built a closed loop: the party that benefits from the records controls every piece of the machinery that produced them.

In a deposition, the other side asks one question of a closed loop: could someone with a stake in this case have edited a row and re-run the script? There is no good answer. That is self-audited paperwork, and opposing counsel will say exactly that.

Lumra breaks the loop with separation of duties: events sealed as they arrive, chained beyond your administrative reach, and verified by a standalone open tool that never contacts PriviNet.

An in-house script produces a self-audited trail. Lumra produces records neither side has to take on faith.

More objections, answered →

The two architectures, side by sideforensic view
Closed loop versus separation of duties ✗ IN-HOUSE SCRIPT: A CLOSED LOOP your database your keys your script your admins "could an admin re-run the hashing after an edit?" ✓ LUMRA: SEPARATION OF DUTIES signed on arrival keys you never hold chained beyond your admin reach verified offline by anyone, open tools no single party controls the machinery your side cannot rewrite it · our side cannot fake your check
The party with a stake in the dispute controls none of the machinery. That is the difference between an exhibit and an argument.
Objections, answered

Questions buyers ask. Straight answers.

We already have logs. Why isn't that enough?

Because anyone with admin access can edit them, and that's why adjusters and opposing counsel discount them. Lumra records are sealed the instant they arrive and chained; altering one breaks verification, as you saw above.

Will this work with the systems we already have?

If your platform can send a webhook or an HTTPS request, yes: telematics platforms such as Samsara, Motive, and Geotab support webhooks, as do most VMS and IoT hubs, and anything custom can call the events API directly. Consumer devices with no webhook output need a small bridge; ask us and we will point you at the shortest path. No hardware is replaced and no media is uploaded.

Why can't our IT team just hash and sign our own logs?

They can, and it will read as self-audited paperwork the day it matters: when your company controls the database, the keys, and the script, there is no good answer to "could the hashing have been re-run after an edit?" Lumra provides the separation of duties: records sealed the instant they arrive, signed at the source where the device supports it, chained outside your administrative reach, and verifiable by the other side with open tools that never contact PriviNet.

Why isn't a WORM bucket (S3 Object Lock) enough?

Object Lock does one thing well: nothing in the bucket changes during the lock. That is storage immutability inside a closed loop you administer. No signature says who created the record or when. No independent timestamp fixes it in time. And the other side can only check it by being handed access to your cloud account. Lumra adds what the bucket cannot: records signed at intake, two independent third-party timestamps sought from unrelated authorities, and a ProofPack anyone verifies offline, no access to your systems required. The two compose: our own evidence archive is retention-locked WORM storage, and a pack stays just as verifiable archived in your own locked bucket.

Do you see our video or audio?

No. Lumra works from compact signed metadata. Raw media stays yours; it can only be recalled under an audited, logged process. We can't leak footage we never receive.

What if PriviNet disappears?

Your records outlive us. The verifier is a standalone open tool that never phones home; anyone can re-check any record for as long as they keep it, with no PriviNet server involved. Proof that requires trusting the vendor isn't proof.

Is this blockchain?

No tokens, no mining, no consensus fees. Just the boring, court-tested cryptography (ECDSA and Ed25519 signatures, SHA-256 hash chains) that federal evidence rules already recognize.

How do dashcam videos hold up as evidence?

Dashcam footage holds up when you can prove nobody edited it after the fact. Your video platform hashes each segment; Lumra seals those hashes the moment they arrive into a tamper-evident chain. Under Federal Rules of Evidence 902(13) and 902(14), hash-verified records like these can self-authenticate through a qualified person's written certification rather than live testimony. Weeks later, anyone can hash the file they received and match it against the hashes committed on the day of the incident.

What is a tamper-evident audit log?

A tamper-evident audit log is a record of alerts, notifications, and responses that cannot be edited after the fact without detection. Lumra signs each event the instant it arrives, such as a geofence exit or a staff acknowledgment, and chains it to the previous record. If an entry is altered or inserted later, verification fails. Opposing experts can check the timeline themselves with a free standalone verifier.

How do you prove chain of custody for cargo?

Chain of custody is proven by signed records at each handoff. Lumra seals gate-in, yard moves, seal checks, and gate-out events the moment they arrive, verifies the device's own signature where source keys are enrolled, then chains the records so any rewrite is detectable. When a container arrives damaged, an adjuster who trusts no party can verify each record independently and narrow the loss to a specific custody window instead of relying on competing paperwork.

What is a cryptographically verifiable event record?

A cryptographically verifiable event record is an event that is digitally signed where it happens when the device supports signing, or sealed on arrival when it does not, and linked by hash to the record before it. The signature proves which enrolled device or person created it, or that Lumra sealed it on arrival, and the hash chain proves nothing was altered, inserted, or deleted afterward. Verification requires only the exported records and open cryptographic checks, not access to the vendor's systems.

How is this different from evidence vaults, photo apps, or free timestamping?

Different job. Evidence-management platforms are vaults: you upload media and trust whoever runs the vault. Photo-verification apps authenticate media captured through their own camera flow, and nothing outside it. Free timestamping proves a hash existed by a certain time, with no event, no custody, no paperwork. Lumra signs the operational events themselves, from the systems you already run, never takes your media, and hands you records anyone can verify plus the certification template to use them. And unlike most of the category, the pricing is on this page.

What stops PriviNet itself from rewriting history?

Three things, all live today. First, checking records never runs through us: the standalone verifier works offline, so any change to a sealed value fails in front of whoever runs it. Second, every export freezes the record: a ProofPack in your hands stays verifiable whatever happens to our servers. Third, our production signing key lives in a hardware security module we cannot extract, and every ProofPack seeks two independent third-party timestamps from unrelated authorities, the second sealed inside the pack, so the record and its place in time do not rest on our word or our clock, or on any single timestamp authority.

What is a ProofPack, and is verification free?

Verifying your records is always free and needs no PriviNet servers. A ProofPack is the assembled, court-ready file for a single incident: the signed records, a verification transcript, standalone verifier instructions, and a pre-filled FRE 902(13)/(14) certification template for your qualified person to sign. It is the assembled deliverable you request when a dispute lands; design-partner pilots include a court-ready ProofPack for every record we sign.

What is the Evidence Trust Assessment in a ProofPack?

A fixed, versioned checklist that runs on every record and reports only what it found: whether the source signature was present and verified, whether the timing lines up, the chain of custody, and, across a multi-source incident, whether independent vendors' records agree. It is enumerated facts, not a score and not an opinion about what happened. When nothing is flagged it says so by name, listing the checks that ran. It rides inside the sealed pack, so altering it breaks verification like any other sealed value. It is there to help a reader weigh the evidence, never to decide fact or liability.

Who's behind this

Don't take our word for it. We insist.

Origin

Privacy wasn't enough

PriviNet began as a private network for IoT devices. Our engineers kept hitting the same wall: privacy protects data; it doesn't prove anything. Safety lives in verification.

Founders

Encryption people

Founder Brad Listermann spent years consulting on the sale of high-end encryption, work he still can't say much about. Lumra is that obsession rebuilt as software anyone can check; Decern, our sister project, extends it toward a post-quantum world.

The trust answer

Don't trust us. Check.

Every record Lumra signs verifies independently. No PriviNet login, no PriviNet goodwill required. Scroll up and try to forge one. That's the whole pitch.

Meet the full team and board →

ProofPack

When the dispute lands, this is what you hand over.

Your records stay signed and chained in the background. ProofPack is what you request the day it matters: one incident, assembled into a single court-ready file your insurer, adjuster, or counsel can verify themselves.

It is not a database export. It is the finished artifact a records custodian signs and forwards, with the verification already done and the paperwork already drafted.

  • The signed event, analysis, and evidence-window records for that incident
  • A verification transcript: every hash recomputed, the signature checked, at export time
  • Standalone verifier instructions, so the other side confirms it with open tools and no PriviNet servers
  • A pre-filled FRE 902(13)/(14) certification template, ready for your qualified person (typically an IT director, records custodian, or forensics expert) to review and sign

A design-partner pilot includes a court-ready ProofPack for every record we sign, generated from your own operation. You see exactly what lands on your desk before you ever need it.

The day it happens:
  1. The incident occurs. Its records are already signed and chained; nothing to remember in the moment.
  2. You request the ProofPack for that incident from your portal or by email, in one line.
  3. It is assembled and delivered, typically the same business day; included in your design-partner pilot or production program.
ProofPack · incident 004-11877 sections · v1.1
01Incident record, signed at sourceEd25519 device signature · key metalert-smartsole-002 · 02:14:09Z
02Analysis recordrisk score, escalation decision, explanation factors, ruleset version
03Evidence-window referencessegment digests h1…h4 · media never leaves your systems
04Canonical inputsevery byte needed to reproduce every hash, independently
05Verification transcript4 digests recomputed · all match · signature valid
06Standalone verifier instructionsopen tools only · no PriviNet servers involved
07FRE 902(13)/(14) certificationpre-filled declaration · awaiting your qualified person's signature
Summary view. The full pack is a complete, machine-verifiable file. Verification is always free.
Real document · live engine

Not a mockup: generated by the live engine from a demonstration incident. Want to check it yourself? Download the machine JSON and run the standalone verifier; every hash reproduces and the signature checks.

Design partners

Five design-partner slots for 2026.

Lumra is taking on a limited number of design partners in 2026. Fixed scope, written success criteria, and a court-ready ProofPack for every record we sign.

Design-partner pilot
$7,500
60 days · fixed scope

One line of business, one data source, up to 500 monitored assets.

  • A court-ready ProofPack for every record we sign
  • Half on signature, half when we hit the success criteria we agree in writing on day one
  • Your own broker, adjuster, or counsel scores the result
  • Verification of your records is always free, for you and for the other side
Request a design-partner slot (5 available for 2026)
Production programs
$30,000+
per year

Production programs start at $30,000/year. Multi-region or multi-carrier deployments are scoped individually.

  • Scoped from your pilot's written success criteria
  • Sealed records, incident assemblies, and ProofPacks per your agreement
  • Platform and white-label programs: custom annual terms
Talk to the founder
Prove it first
Free
one day of your data · one signed ProofPack

Send us one day of telematics or sensor data and we'll return a signed ProofPack, free.

  • Your own events, sealed and verifiable offline
  • Run the verifier yourself; change one character and watch it fail
  • No credentials, no commitment
Send one day of data

Verification of your records is always free; a ProofPack is the assembled, certification-ready deliverable. Insurer and platform programs (VMS, dashcam, telematics, and wearable providers embedding Lumra): custom annual terms.

Request a design-partner slot.

Five slots for 2026. Sixty days at fixed scope: one line of business, one data source, up to 500 monitored assets, and a court-ready ProofPack for every record we sign.

Request a design-partner slot →

Not ready for a pilot? Send us one day of telematics or sensor data and we'll return a signed ProofPack, free. We reply within one business day either way.

Not sure what you'd even need to capture? Run the 3-minute audit first →