Evidence Streams

Operational evidence streams.
Make events useful after they happen.

Turn device, partner, and application events into records your operations team can investigate. Preserve source context, validation results, and continuity so downstream teams can understand what arrived and what happened next.

Event lineageCan you follow the original event?
  1. Source batch
  2. Admission checks
  3. Retained evidence
Illustrative workflow · availability and access controls apply
A familiar challenge

An incident investigation starts with thousands of machine events. Your team needs to locate the relevant records and inspect their provenance.

A more useful way forward

Preserve admitted event context and continuity. Integrity checks do not establish that a real-world assertion is true.

See a practical example ↓
Why it matters

Give investigations a dependable starting point.

For data-platform, industrial, and integration teams.

Attribute the input

Associate a submitted record with its source and the context needed to review it later.

Retain continuity

Follow accepted events through their sequence and integrity references instead of relying on mutable application logs alone.

Control what is disclosed

Keep sensitive payloads and attachments behind their required boundaries while sharing permitted evidence.

Core capabilities

The capabilities behind the outcome.

Match these capabilities to your workflow. Enabled operations and access are confirmed during integration planning.

  • Batch ingestion

    Evaluate supported event and batch inputs with their source context.

  • Schema and admission checks

    Validate incoming payloads against the configured contracts before downstream use.

  • Stream delivery and continuity

    Follow available live delivery and continuity references across an event sequence.

  • Retention and investigation

    Confirm retention and replay needs so a past event can be located and reviewed.

How Evidence Streams works

From a source event to retained evidence.

  1. 01
    Identify and submit

    Use the configured source identity, schema, and ingestion authority to submit an operational event.

  2. 02
    Validate and retain

    Apply the stream’s acceptance rules and retain the integrity and continuity references available for the record.

  3. 03
    Inspect and respond

    Use authorized views and verification material to investigate a sequence or trigger an appropriate downstream workflow.

A practical example · illustrative

An industrial team investigates a sensor alert.

The team needs to determine which source reported the event and whether the retained record has changed.

Attribute
Inspect the source and submitted event context.
Trace
Review acceptance, continuity, and the relevant integrity references.
Corroborate
Compare the record with device health and independent operational evidence.
What the team takes away

A stronger investigation trail—not a guarantee that the sensor measured reality correctly.

Scoped access

Plan your first deployment.

Confirm source enrollment, supported schemas, ingestion permissions, retention, and verification for the target stream. Design independent checks for the quality of the source’s claims.

Before your first integration

  • Choose an event source, schema, volume, and retention requirement.
  • Test rejected payloads, missing events, and delivery interruptions.
  • Demonstrate how an investigator retrieves the records needed for one incident.
Open workspace
Questions before you build

Evidence Streams, explained.

Does a signed event prove the physical event happened?

No. A signature can support attribution and integrity. Device quality, source compromise, and the truth of the observation require additional controls.

Where do large or confidential attachments belong?

Use the supported protected-storage boundary, such as Data Vault, and retain only the references or commitments appropriate for the stream’s disclosure policy.

What should we agree before starting a pilot?

Use the product-specific checklist above to define scope and acceptance tests. Ask the team to confirm the deployment environment, access, supported operations, integration responsibilities, support arrangements, and commercial terms. Availability labels are not a pricing quote or a service-level commitment.

Explore the technical architecture and walkthroughs

Optional deeper reading. Demonstrations are illustrative, not live operational status or a promise of activation. Use the availability guidance above and the current API contract for integration decisions.

SOURCE AUTHENTICATEDSCHEMA VALIDATEDPAYLOAD COMMITTEDWEBSOCKET DELIVERY READY

THE EVIDENCE PIPELINE

Six boundaries.
No silent shortcuts.

Explore the path from a device-signed JSON envelope to a public-safe proof. Each stage has a different responsibility and an explicit failure boundary.

STREAM CONTRACT · WATER-PLANT-07Signed telemetry evidence
CHAIN INTACT
01 · AUTHENTICATE

Know which machine spoke.

A registered device presents its scoped source credential and signs the canonical delivery envelope.

EVIDENCE CREATED
Device identity, credential key ID, nonce, signature result, and source timestamp.
FAIL-CLOSED BOUNDARY
Unknown, revoked, replayed, or incorrectly signed sources never enter the event chain.
SOURCEAUTHENTICATEDSCHEMAVALIDSEQUENCE0001842DELIVERYRETAINED

APPEND-ONLY INTEGRITY

Change one event.
Break every link after it.

Each accepted event commits to its payload and the preceding chain state. A later verifier can replay the same derivation and detect deletion, substitution, reordering, or duplication.

Verify an event chain
EVENT 1841PREVIOUS CHAIN HASH4d71…ca82RETAINED
+
EVENT 1842PAYLOAD COMMITMENT883d…a45eSCHEMA VALID
=
NEW TIPCHAIN HASHbf09…17c4INTACT

PUBLIC-SAFE PROOF CLASSES

Reveal integrity.
Keep protected data protected.

Evidence Streams can expose enough to verify origin, validation, sequence, and retention without publishing device secrets, customer-only metadata, encrypted attachments, or private payloads.

01 · SOURCE PROOF

Who produced it.

Registered device identity, credential key ID, signed envelope, timestamp, and replay-resistant nonce.

Inspect proof output
02 · DATA PROOF

What was accepted.

Schema version, validation outcome, event type, payload commitment, size, and canonical event sequence.

Inspect proof output
03 · RETENTION PROOF

What remains available.

Encrypted attachment manifest, content hash, retention deadline, redaction state, and surviving commitment.

Inspect proof output
04 · CHAIN PROOF

Where it belongs.

Previous event hash, current payload hash, derived chain hash, Core receipt, and public verification state.

Inspect proof output

ENCRYPTED ATTACHMENTS & RETENTION

Let content expire.
Keep the audit trail.

Images, reports, calibration files, certificates, and other supporting evidence can be encrypted and bound to an event. Retention maintenance removes eligible protected content while preserving the manifest, content commitment, and redaction record needed to explain what happened.

ENCRYPTED AT RESTEVENT-BOUND MANIFESTPOLICY EXPIRYCOMMITMENT SURVIVES

OPERATIONAL DELIVERY

Ingest once.
Operate in real time.

REST and authenticated WebSocket transport serve different device and application profiles, but both converge on the same canonical ingestion rules. Downstream consumers receive accepted evidence—not an unaudited parallel feed.

01DEVICE FLEET

Signed JSON, batches, and supporting attachments.

→
02CANONICAL STREAM

Authenticate, validate, sequence, commit, alert, and meter.

→
03LIVE CONSUMERS

API, WebSocket, retained replay, analytics, and public proof.

WHERE IT FITS

One evidence fabric.
Every machine estate.

Turn high-volume JSON and sensor data into auditable evidence. Start with one project or use the same verifiable ingestion boundary across an entire partner and device ecosystem.

01WATER & ENERGY

Retain flow, pressure, quality, generation, storage, and maintenance evidence across distributed infrastructure.

02MANUFACTURING

Bind machine state, production metrics, quality checks, and operator interventions into one auditable sequence.

03SUPPLY CHAINS

Prove custody changes, environmental conditions, location events, and supporting documentation across partners.

04SCIENCE & CLIMATE

Preserve instrument observations and dataset provenance so later analysis can be traced to its source conditions.

05AI DATA PROVENANCE

Give models a signed record of the machine data, policy, and event sequence used to train or trigger them.

06REGULATED OPERATIONS

Produce a clear operational trail without placing source credentials or protected payloads in a public database.

Start with one useful result

Make it work for your team.

Bring your workflow. We’ll help identify the scope, access, and acceptance checks for a practical pilot.

Discuss your deployment
Build the next part of your workflow

Connected products.

Start with Evidence Streams. Review these adjacent capabilities when your requirements call for them.