User manual
Evidence
Dronetrake does not keep just any log: it keeps evidence. The difference is concrete. A log can be corrected by whoever has access to the database, and nobody notices. Evidence is built so that tampering shows, and so that the date of a fact is vouched for by someone who is not us. This chapter explains what is in evidence, how it works, what it costs and — just as important — what evidence does not prove.
What it means, in one sentence
A fact is in evidence when three things hold together:
- it is written in an entry that cannot be rewritten (or that leaves a trace if it is deleted);
- the entry carries a fingerprint (SHA-256) computed on its content plus the fingerprint of the previous entry: that is the chain;
- the head of the chain receives, at regular intervals, a timestamp from an independent provider.
From that moment anyone, even without trusting us, can recompute the chain and establish that the fact existed, as it is, before that time. The question "who did what, and when?" has a documentary answer, not one from memory.
The chains
Every organization has five chains, one per family of facts:
- Flights: the logbook. Drone, pilot, take-off and landing, places, VLOS/BVLOS, anomalies (see the Flights chapter).
- Recordings: the encrypted recordings of live streams, with the file fingerprint and the start time.
- Mission files: deliverables, documents, NOTAMs. What goes into the chain is the bytes (fingerprint, size, type) and the upload time; the file name, the deliverable kind and the mission it is attached to are labels you can correct without breaking anything.
- Checklist records: every signed checklist produces, at the instant of signing, a record with the ticked items, who signed and when. The record is the chain entry, and it outlives the mission.
- Training attestations: for schools, the dossier of a delivered task (see Team and the schools guide).
There is also a sixth chain, platform-wide: the register of acts — successful and failed logins, role changes, people joining and leaving organizations, plan changes, suspensions, revoked links and keys, staff acts. It is a single chain, ours, sealed every night, and we produce it on request when someone needs to reconstruct who did what.
Facts go into the fingerprint; correctable labels stay out of it. Correcting a label breaks nothing; touching a fact does, visibly.
The two levels
Level 1 — the chain and the nightly seal. The chain is there always and for everyone, at no cost and with no choice: from the free plan up, every entry is born with its link. The nightly seal is switched on from the organization profile, with the "Nightly seal with timestamp" toggle: it is free, and from then on every night the head of every chain receives the timestamp of an independent provider. It is a non-qualified timestamp: it proves that at that time the chain was that one, and it is more than enough for your own archive, for a client, for an internal report. With the toggle on, the Evidence page appears in the panel.
Level 2 — the qualified eIDAS timestamp. This is the date enforceable against third parties: it is applied by a qualified trust service provider under the European eIDAS regulation, independent of us, and its name appears on the Evidence page as soon as the first timestamp is issued. This is a choice, with counted timestamps, and it is expressed in three ways:
- "Mark as evidence" on a flight, from the flight register: when that flight will have to hold up before someone;
- marking a recording as evidence, from the recordings list;
- the mission switch "Must hold up before third parties": from then on the mission's flights, the recordings on its channel within the operation window (up to two hours after the end), the checklist records and the files are born already marked. If you switch it on after the fact, what already exists catches up.
One qualified timestamp covers everything that was marked that day on that chain: the cost is per night and per chain, not per entry. The monthly cap depends on the plan: Solo and School no qualified timestamps, Pilot fifteen per month, Crew and Ops no cap (the nightly run itself is the limit). If the timestamps run out, nothing is lost: the flight, recording or file stays at level 1, and the Evidence page shows the pending request.
The Evidence page
You find it in the Compliance cluster, when the nightly seal is on. It shows:
- Who sets the date: the qualified provider, once at least one timestamp has been issued; otherwise the sentence explaining how to get one. And how many qualified timestamps remain this month.
- Marked flights, each with its state: Waiting for timestamp (covered tonight) or Timestamped on … by ….
- Marked recordings, with the state of the off-site copy.
- Signed checklists, mission files and, for schools, attestations: each with the seal that covers it or Waiting for the nightly seal.
One rule applies to everything: a timestamp covers what existed before it. What is born afterwards waits for the next one. That is why the page always states the window: the timestamp comes with the nightly run, not instantly.
Recordings marked as evidence
A recording marked as evidence changes nature: retention no longer prunes it, it receives an off-site copy (the page says whether it is done or in progress), and it cannot be deleted from the panel. To delete it, it must first be downgraded to ordinary, and it stays on record who did that and when. It is the case where automation protects from chance, and the model protects from people.
Signed checklists
A checklist is filled in, corrected and signed. After signing it is not modified and does not get deleted on its own: by no path, not even from the console. At signing the record is born — the ticked items, the signer, the time, the mission — and enters the chain. If one day the mission is deleted, the checklist goes with it leaving a tombstone, but the record stays, with its fingerprint and the seal that covers it.
Deleting, and what remains
Deleting is possible, except where evidence forbids it: logbook entries younger than three years, recordings marked as evidence, checklist records, attestations. But nothing disappears silently: every deletion leaves a tombstone with what it was, when, under which rule (manual, retention, purge) and by whose hand. The tombstone also keeps the link of the deleted entry: that is why the chain holds even without it, and verification keeps passing.
A deletion made covertly, outside the product, leaves no tombstone: the chain breaks, and verification says so. That is exactly the job it has to do.
Verifying
From inside: the Evidence page, and in every flight's detail the full fingerprint, ready to copy.
From outside, without an account: the QR code on mission reports opens a public page that recomputes the chain from zero on every visit, flight by flight, and shows the fingerprints of the delivered files. The same goes for a drone's history certificate, a pilot's attestation and a student's training attestation: whoever receives the document verifies it themselves, and sees the result, not your internal data.
On our side: every night the system re-verifies all the seals ever issued, recomputing every chain up to the timestamped head; if something does not add up, we know before anyone else. And every eighteen months the timestamps are renewed — a tree of fingerprints over all the tokens, and a single timestamp on the root — because the validity of a timestamp is not eternal.
At closure
If the organization closes, it receives the handover dossier: the complete logbook with fingerprints and signed contents, the seals with the timestamp tokens, and a README explaining how to re-verify everything offline, with standard tools, without Dronetrake. Then a window opens to download it; once the window expires, the data is deleted — keeping the records is the operator's obligation, and from that moment it is in their hands. On our side, the seals and the tombstones of the deleted entries remain: they attest that the register existed, up to which head and when it was deleted, without holding your data. You may choose custody instead: the records stay with us, sealed, read-only, verified every night and with renewed timestamps, as long as custody is paid; when it stops, the 90-day window opens and the cycle resumes from there.
What evidence is not
- It does not certify compliance: it lines up the facts and makes them verifiable; the judgement stays with whoever has to give it.
- It does not say a fact is true: it says it was recorded like that, and before that time. A wrong value entered by a person stays in the chain, wrong and verifiable — and it is corrected with a rectification, not by rewriting it.
- The free timestamp is not a qualified timestamp: it proves the sequence and the time with the guarantee of an independent provider, but the date enforceable against third parties, in the sense of the eIDAS regulation, is only the qualified one.
- The archive is yours: if you delete with a tombstone, if you close, if you let a retention expire, the evidence tells it without embellishment. That is the reason it is worth anything.