Forensic incident capture

Every incident
is evidence.
Capture it that way.

TraceProof maintains a continuous screen buffer and seals a cryptographically-signed clip the moment something happens — before anyone can alter it.

HMAC‑SHA256 Package signing
3× NTP + DNS Timestamp verification
Hash‑linked Chain of custody
<1ms Trigger latency
TraceProof — Evidence Vault Dashboard
#041 3f8a2c1d-hotkey 14:32:01.847 bf59011d… ✓ verified
#042 a91f0e7b-ocr→"margin call" 14:32:03.201 9cef51f2… ✓ verified
#043 c4a64e58-rage-click 14:33:17.009 25db9cb4… ✓ verified
#044 60801e35-ocr→"connection lost" 14:41:55.512 a9994fc5… ✓ verified
#045 awaiting next incident… recording
Watch demo

From event to evidence
in under a second.

01

Continuous buffer

DXGI Desktop Duplication captures a rolling pre-trigger buffer. No gaps, no missed frames — including DirectX overlays invisible to conventional tools.

02

Instant trigger

Hotkey, OCR pattern match, rage-click detection, or mic activity. The trigger is configurable. The response is immediate.

03
🔒

Cryptographic seal

Dual SHA-256 hash (capture stream + export), HMAC-SHA256 package signing under DPAPI or TPM, timestamps from 3 NTP servers and DNS SOA cross-check.

04

Chain of custody

Each incident is linked to the previous by hash — blockchain-style. Deletion or modification of any entry is immediately detectable during verification.

05

Vault upload

The sealed package is automatically uploaded to your Evidence Vault before it can be tampered with locally. Server-side hash verification on receipt.

Built for investigation.
Not just recording.

🎬

DXGI Desktop Duplication

Captures the DWM-composited frame including DirectX overlays, HDR content, and hardware-accelerated windows. GDI BitBlt cannot see any of this.

Core
🔍

Multi-monitor OCR triggers

Windows.Media.Ocr (native, no Tesseract) scans per-monitor pattern sets. Fires on "margin call", "connection lost", "rejected" — whatever matters to your workflow.

Core

Multi-source timestamps

System time, Windows FILETIME, 3 parallel NTP servers, and DNS SOA serial as an independent source. Skew detection is logged and included in every incident package.

Forensic

Hash-linked chain of custody

Every incident extends a hash-linked chain. The standalone verifier produces JSON output that integrates directly into SIEM pipelines and investigation workflows.

Forensic
🖥

GPU-accelerated encoding

NVENC (NVIDIA), AMF (AMD), and QSV (Intel) with CPU fallback. Full 1080p60 capture with near-zero performance impact on the monitored workstation.

Core
🔑

DPAPI + TPM key protection

Signing keys are protected by Windows DPAPI (CurrentUser) or hardware TPM on Enterprise+. The key never leaves the machine in plaintext.

Forensic
🏢

Full enterprise integration

Group Policy (ADMX templates), registry policy, Windows Event Log integration for SIEM, MSI silent deployment. No UI required on managed endpoints.

Enterprise
🗄

Evidence Vault + Dashboard

Self-hosted Node.js vault with SQLite index, timeline view, chain integrity browser, ZIP export, and auto-generated PDF incident reports. Webhook on every new incident for Slack/Teams.

Enterprise

Offline + air-gap licensing

Machine-bound license activation without internet. Designed for air-gapped trading environments and high-security compliance deployments.

Enterprise

Who uses TraceProof.

Trading desks & brokers

Capture execution errors, margin calls, and disputed orders with a forensic record that holds up to regulatory scrutiny.

  • Automatic OCR trigger on "margin call", "rejected", "failed"
  • Millisecond-accurate timestamps cross-verified against NTP
  • Evidence package ready for compliance review in seconds

Compliance & internal investigations

Replace "he said / she said" with cryptographically-signed, tamper-evident video records.

  • Hash-linked chain detects any deletion or modification
  • PDF incident reports for HR and legal folders
  • Standalone verifier with JSON output for SIEM integration

Fintech support & outsourced compliance

Multi-machine Evidence Vault with per-user incident filtering. Real-time webhook to Slack or Teams on every trigger.

  • Evidence Vault dashboard across all monitored machines
  • Webhook integration for immediate incident notification
  • Retention policy and GDPR-compliant auto-purge

Game anti-fraud & privileged user monitoring

Rage-click and hotkey triggers catch behavior that rule-based monitoring misses entirely.

  • Rage-click and abnormal input pattern detection
  • OCR pattern sets per team or per role
  • Court-admissible audit trail with chain of custody
Capture API
DXGI Desktop Duplication
Encoding
NVENC / AMF / QSV / x264
OCR engine
Windows.Media.Ocr
Signing
HMAC-SHA256
Key storage
DPAPI / TPM
Timestamp sources
3× NTP + DNS SOA + FILETIME
Chain integrity
SHA-256 hash-linked
Platform
Windows 10 / 11
Deployment
MSI + GPO + Registry
Vault
Node.js + SQLite (self-hosted)

Forensic-grade evidence.
Priced for real teams.

Annual billing saves up to 30%. All plans include the standalone forensic verifier and lifetime access to updates within the tier.

Pro
$ 89 / month
$749 / year — save $319

Single workstation. One investigator. Full forensic capability.

  • Continuous DXGI capture, GPU encoding
  • Hotkey, OCR, rage-click triggers
  • Up to 15 OCR patterns
  • HMAC-SHA256 + DPAPI key protection
  • Multi-source timestamp verification
  • Hash-linked chain of custody
  • Standalone forensic verifier
  • Single monitor
  • Evidence Vault / dashboard
  • GPO / MSI deployment
Get started
Enterprise+
$ 749 / month
$6 500 / year — save $2 488

Unlimited scale. Dedicated support. Custom deployment and SLA.

  • Everything in Enterprise
  • Unlimited monitors per workstation
  • Unlimited OCR patterns
  • TPM hardware key binding
  • Priority support — 4h response SLA
  • Custom deployment & onboarding
  • Dedicated Slack channel
  • Custom OCR pattern sets per role
  • 99.5% uptime SLA for hosted vault
  • Volume licensing available
Get started

Ready to turn incidents
into evidence?

Request access or book a 30-minute technical demo. We'll walk through a live capture, chain verification, and Evidence Vault setup for your environment.