Three-tier encryption, blockchain anchoring, immutable storage, traceable chain of custody, legal compliance, and open source — from the capture click to courtroom presentation.
Data in transit, at rest, and at signing — each state has a dedicated algorithm, with no blind spot.
Most secure protocol available for data in transit
Standard of governments and financial institutions for data at rest
Post-quantum digital signature approved by NIST (FIPS 140-3)
Every evidence is anchored simultaneously in three independent public blockchain networks.
Primary network — SHA-256 hash registered on-chain
Secondary network — redundancy and cross-verification
Tertiary network — independent of Lexato for verification
Infrastructure designed to physically prevent any alteration or deletion of data.
Prevents deletion even by system administrators
Servers located in Brazil — compliance with national legislation
Multiple copies in geographically distinct data centers
Complete and inviolable tracking of every action on the evidence, from registration to access.
Trail with IP, timestamp, and user identification
Log of every view, download, and share
Compliance with chain of custody under the Anti-Crime Package (Brazil)
Operation in full compliance with Brazilian data protection and digital evidence standards.
Law 13.709/2018 — personal data protection
Guidelines for identification and preservation of digital evidence
RFC 3161 timestamp — public faith recognized nationally
Total transparency. The application code is open and auditable by any expert.
Public source code — auditable by forensic experts and developers
No hidden dependencies — every line of code is verifiable
Vulnerabilities identified and fixed quickly
How each control works in practice — certifications, encryption, infrastructure, access, audit, response, and retention.
Compliance with leading international information security standards.
TLS 1.3 protects communication, AES-256 protects storage, and ML-DSA-87 signs each capture — three algorithms, three states, no overlap.
AWS and Vercel host the operation — providers already audited for SOC 2 and ISO 27001, no need to reinvent controls from scratch.
Robust authentication and granular permission controls to protect data access.
Every operation on the platform is logged with IP, timestamp, and user — immutable records, exportable for forensics or compliance.
Structured security incident response plan with continuous monitoring.
Clear data retention and deletion policies in compliance with LGPD.
Create your account and capture your first piece of evidence with encryption, blockchain, and chain of custody already in place.