Every item is sealed with a cryptographic fingerprint the moment it is captured. When a Project Record is produced, it carries those fingerprints and, where a timestamping authority is configured, an independent RFC 3161 timestamp from a source outside our control.
The register is a numbered, dated, attributed list of what was said and done, with no interpretation in it at all. The written account is generated from that register, and every statement in it cites a numbered entry. You can read the facts without the story, and check the story against the facts.
Messages referenced in the correspondence but never captured. Fragments excluded from the chronology and why. Records without a hash of the original. This section appears whether or not anything is missing, so you know what you are deciding on before you act.
Where the same email reaches the record twice and the two copies differ, the difference is surfaced rather than silently resolved in favour of one of them.
The written position is generated once, stored as a numbered version with its own SHA-256, and printed with that version and hash on the page. Regenerating creates a new version rather than overwriting the old one.
A client, an auditor, a subcontractor or another party can recompute the hashes themselves and check the RFC 3161 timestamp where one is present. Without a timestamp token, the recorded time is asserted by the platform.
Timestamps are issued by a public RFC 3161 authority. This is not a qualified eIDAS timestamp, and every project record states its own timestamp status.
What this proves is precise: that a record is unaltered since capture and tied to a time. It does not claim to prove that an event happened as described.
Platform controls (residency, access, encryption, logging, subprocessors and independent assurance) are documented separately: Security & Trust