Lumethic Offloads
A timestamped receipt for every card you back up
Offload your card as usual. Lumethic takes the hash manifest your transfer tool writes, has it countersigned by an independent timestamp authority, and returns a receipt stating that every file on the card existed, exactly as it is, no later than that day.
How it works
One extra step after the backup you already do
Professional transfer tools write a manifest during every card backup: a list of each copied file with its checksum. Anchoring that manifest turns it into a fixed point in time.
Offload the card
Back up with OffShoot, Silverstack, ShotPut Pro, YoYotta or any tool that writes a hash manifest. Supported formats include ASC MHL, hashdeep output and plain JSON hash lists.
Upload the manifest
Upload the manifest file to your account, or let a post-transfer script submit it automatically over the API. The manifest is a few kilobytes even for a full card. The photographs never leave your drives.
Keep the receipt
Lumethic signs the manifest and has it countersigned by an independent timestamp authority under RFC 3161. The receipt is self-contained JSON that you can file with your project or case documentation.
What the receipt says
Narrow claims that hold up under scrutiny
A valid receipt proves
- The manifest, and with it the fingerprint of every file on the card, existed no later than the anchor date.
- The date comes from an independent timestamp authority, not from Lumethic and not from you.
- The receipt can be checked with standard cryptographic tools, without a Lumethic account and without trusting Lumethic.
It deliberately claims nothing else
The receipt does not say the photographs are authentic, name who uploaded the manifest, or vouch for the camera's clock. Every statement in it can be checked cryptographically, so none of it depends on anyone's credibility. Authenticity of individual images is a separate question, answered by RAW verification.
Anyone with the receipt can verify it on the public receipt checker, including an opposing expert.
Open the receipt checkerChecksum grades
Your transfer tool's checksum setting decides what the anchor covers
Most tools default to xxHash, a checksum built for speed. An anchor built on xxHash proves the offload happened at the anchored time, but it cannot bind the file contents. MD5 and SHA-1 land in the same grade because both have known collision attacks.
C4, the content-addressing checksum in the ASC MHL standard, can bind contents. Switch the checksum type to C4 and every future offload earns the content-bound grade, where the anchor covers what the files contained rather than only that a copy took place.
How to change the checksum setting in your toolFor contested work
The first link in a chain of custody
For evidence, documentation and litigation support photography, the offload receipt answers the question that challenges usually start with: when did these files first exist, and who besides the photographer can confirm it. A hash log kept on your own disk answers with your word. An anchored manifest answers with a third-party timestamp.
When selected frames later go to a legal team or become exhibits, verifying them against the RAW closes the chain: on the card by the anchor date, verified unchanged in this state. Receipts and verification reports can be shared via link, and recipients do not need an account.
Offload questions
Are my photos uploaded to Lumethic?
No. Only the manifest is uploaded, the hash list your offload tool writes during the backup. The photographs stay on your drives.
Can Lumethic lock the files on my memory card?
No software can make files on a memory card immutable, ours included. The working practice is to flip the card's write-protect switch after the shoot, offload with a tool that writes a manifest, and anchor that manifest. Anchoring does not prevent later changes. It makes them detectable, which is what a dispute requires.
Which checksum should my transfer tool use?
C4. It is the one checksum in the ASC MHL standard that binds file contents, so anchors built on it receive the content-bound grade. xxHash, MD5 and SHA-1 lead to offload-event-only anchors. The setting sits in the tool's transfer or verification preferences and takes a minute to change.
What does an offload cost?
Both paid plans include 50 card offloads per month, and one receipt covers the whole card regardless of how many files are on it. Offloads and verifications are metered separately, so anchoring cards does not use up verifications.
What is the difference between an offload and a verification?
An offload receipt proves that every file on a card existed unchanged from the anchor date. A verification is the forensic analysis of an individual RAW and JPEG pair and answers whether that image is an unedited camera original. The receipt covers every frame cheaply; verification is for the selects that actually get used.
Can someone check a receipt without a Lumethic account?
Yes. Receipts are self-contained JSON and verify on the public receipt checker without signing in. Receipts stay valid even if the offload is later deleted from the account, because they verify against the manifest bytes wherever those are held.
Anchor your next card
Offloads are included in both paid plans. Upload a manifest from your account, or set up automatic submission so every backup carries an independent timestamp.