The Three Claims
A Lumethic record is two documents: an offload receipt for a memory card, and a verification report for an individual image. Between them they make three claims. Everything else on this page explains the words in those claims and the limits around them. Lumethic builds software and does not give legal advice; how a court weighs any of this is for the people running the matter. Version of this page: 2026-09-03.
- Existence by a date. Every file listed in the card's hash manifest existed no later than the anchor time printed on the receipt, countersigned by an independent RFC 3161 timestamp authority. With a content-binding checksum the claim is byte for byte; with a speed checksum it is only that the offload took place by that time. The grade is printed on the receipt.
- Receipt and custody. The manifest was received unchanged, and anyone holding the receipt can re-verify it against the certificates embedded in it, without Lumethic.
- Derivation consistency. A delivered JPEG is consistent with the RAW file it was paired with: capture metadata agree, and structural, perceptual and tonal comparisons against a reference rendered from that RAW fall within stated thresholds. The report states the methodology version, the scores, the thresholds, and which checks ran or were skipped. Manipulations below what those comparisons resolve are not excluded, and no examiner opinion is given.
In the vocabulary of the Scientific Working Group on Digital Evidence, the first two claims are integrity records: the files and the hash list are unchanged since the anchor. The third is a consistency check between a derivative and its claimed camera original, an input to an authentication examination rather than an authentication opinion, which that body reserves to a trained practitioner. None of the three says whether the scene was what it appeared to be. A hash cannot show that. Only the person who vouches for the photograph can.
The Checksum Grade
The receipt carries one of two grades, decided by the hash algorithm the offload tool used when it wrote the manifest.
Content-bound means the manifest used a cryptographic hash: C4 (the content identifier in the ASC Media Hash List standard, published as SMPTE ST 2114, which is SHA-512 in a different encoding) or SHA-256 from a hashdeep run. Producing a different file with the same value is not feasible with any known technique, so the receipt binds the contents of every file.
Event-only means the manifest used xxHash, MD5 or SHA-1. xxHash is a speed checksum with no resistance to deliberate collisions, and MD5 and SHA-1 have known collision attacks. An event-only receipt proves that an offload of a manifest with these values took place by the anchor time; it does not prove what the files contained. Most offload tools default to xxHash, so a photographer who has not changed the setting will produce an event-only receipt; the checksum settings guide shows the change.
The Timestamp Authority
The anchor is an RFC 3161 timestamp token. Lumethic signs the receipt, computes a hash of that signed receipt, and sends only the hash to the authority, which is currently DigiCert's public timestamp service. The authority signs the hash together with the time from its own audited clock and returns the token. The authority never sees the files or the manifest, and Lumethic cannot set the time.
"Independent" therefore means: a separate company, with its own signing key under its own certificate hierarchy and its own published timestamp practice statement, in a protocol where Lumethic supplies a hash and nothing else. The authority does not vouch for the files and has no relationship with the parties. It is a public service that Lumethic chose to trust and that anyone can verify against.
The token is not an eIDAS qualified electronic time stamp. In the European Union, Article 41(1) of the eIDAS Regulation provides that an electronic time stamp may not be denied legal effect or admissibility as evidence solely because it is electronic or is not qualified; the presumption of accuracy of date and time and of integrity of the bound data in Article 41(2) is reserved to qualified time stamps, which these are not. In Germany a non-qualified time stamp is weighed under the free evaluation of evidence in § 286 ZPO, and § 371a ZPO, which concerns qualified electronic signatures, is not engaged. Elsewhere, local counsel states the rule.
Lumethic's own signature on the receipt uses an S/MIME certificate issued to Lumethic. It identifies the issuer, and the timestamp covers it regardless of the certificate type.
What the Record Does Not Cover
The record starts at the first backup. Nothing in it covers the memory card between the shutter and the moment the hash list was written, and nothing in it states when the photographs were taken; the camera clock is the photographer's setting, and the receipt dates the offload, not the exposure. Backing up on the shoot day narrows that gap to hours. Backing up a week later leaves a week the record does not cover.
The record does not state that the scene was real, that the photograph is true, or that a file is admissible anywhere. It does not lock a card, and it cannot verify a print. A verification report is not an opinion about authenticity. It is a set of comparisons with their results.
The Verification Checks and Their Validation Status
A verification compares a delivered JPEG with the RAW file it was paired with. The checks are: sensor-noise and structure analysis of the RAW, metadata consistency between RAW and JPEG, structural similarity and a perceptual hash between the JPEG and a reference rendered from the RAW, a tonal comparison of histograms, recapture detection (a photograph of a screen or print), and face detection used only to locate regions for comparison. Each check has a threshold at the current methodology version, and the report lists the scores against those thresholds and marks any check that did not run.
"Verified RAW" means a RAW file whose sensor-noise statistics, bit-depth structure and metadata passed these consistency checks. It does not mean the file is proven to be the first recording of the scene. Verification assumes that fabricating a sensor-consistent RAW file is beyond the adversary as of the current methodology version; that assumption is stated here with a date and revisited quarterly.
Validation status as of this page's date: the checks were calibrated on 397 genuine images of one class, and recapture detection was evaluated on twelve files. Error rates for manipulated RAW and JPEG pairs have not yet been published. Until then, read a report as a consistency screen with stated thresholds. Any contested question of authenticity belongs to a qualified examiner.
Which Edits Pass
Cropping, exposure and white balance changes, lens and perspective correction, dust removal and annotation are expected to pass. Compositing, object removal and generative fill are expected to fail. The exact behaviour depends on the methodology version and is published with it; the report records which checks ran and which were skipped, so a borderline result can be read in context.
How to Reproduce the Checks
Every receipt can be checked on the public receipt page without an account. For an independent check with standard tools:
- Recompute the hash of any file on the card with the algorithm named in the manifest (
c4idfor C4,shasum -a 256orhashdeep -c sha256for SHA-256) and compare it with the manifest entry. - Confirm the manifest bytes match the hash recorded in the receipt.
- Verify Lumethic's signature over the receipt core and the timestamp token over the signed core, using the certificates embedded in the receipt, with
openssl ts -verifyor an equivalent.
The receipt embeds the certificates it was signed with. Certificate chain-path building and revocation status are not checked by the hosted page and are listed there under "Not checked"; an examiner who wants them performs them against the authority's published chain.
How Long a Receipt Can Be Checked
A receipt verifies with standard tools for as long as the timestamp authority's certificate can be validated. Timestamp authorities rotate their certificates, and the receipt does not currently embed a revocation snapshot or carry a renewed timestamp, so the practical horizon is the validity of the authority's certificate and of the signature algorithms. Download every receipt and report on delivery and keep them together with the manifest and the originals. Long-term re-anchoring for multi-year matters, which would renew the timestamp before the authority's certificate expires, is in development and is not a feature of any plan.
Receipts are never revoked. Deleting a record at Lumethic does not invalidate a receipt that has already been downloaded, because the receipt verifies against its own contents.
Contested Findings and Who to Ask
If a verification result is disputed, start from the scores and thresholds in the report. A contested authenticity opinion is the work of a qualified forensic image examiner, who can treat the record as chain-of-custody substrate and perform their own examination on the originals. Lumethic will answer technical questions about the checks by email, and states what it can and cannot say about a specific record; it does not offer opinions on the scene.
Reliance Statement
Every receipt and report should be read with this statement, which is what Lumethic itself says about them:
This document records the checks performed and their results. It does not state that the scene depicted is real, and it does not state that any file is admissible in any proceeding. Anyone relying on it should re-verify it with the public receipt check or with standard cryptographic tools, and should read the checksum grade and the methodology version before drawing any conclusion.

