Proof that outlives the page
Phishing sites come down. Posts get edited. UniSeal captures what was there — the network record, the certificate chain, the page itself — seals it, and anchors that seal to Bitcoin, so it still checks out after the original is gone.
Self-hosted · Evidence stays on your own server
What a seal proves
That these exact bytes have not changed since they were sealed, and that they existed no later than the moment Bitcoin confirmed the anchor. Both are checkable by someone who assumes you are lying.
What it does not
That the page really said this, or that nothing was staged. No capture tool can prove that, and one claiming to would be worth less than one that says so. The work goes into making the capture itself hard to doubt.
How a capture becomes evidence
Paste a URL
Nothing to install. The capture runs on the server rather than in your browser, so the page never sees you and never gets to behave differently because of who is looking.
It is captured in a clean room
A fresh container each time, with no profile, no extensions and no local overrides — and the image digest is written into the record, so the environment is part of the evidence rather than a claim about it.
It is sealed
Everything captured is hashed into one manifest over an RFC 6962 tree. That is what lets a single artefact be proven part of the capture later without handing over the rest of it.
The seal is anchored
The manifest hash goes to Bitcoin through OpenTimestamps. From that point the time is attested by something nobody here controls, including us.
What a capture contains
The wire, not the pixels. A screenshot is the one part that is easy to fake and the only part most tools keep.
Which resolver answered, and what it said.
The full certificate chain the server presented.
Headers and body on the wire, both directions.
The page after its scripts ran, not only the markup sent.
What a person would have seen, recorded as it happened.
The container image digest, so the clean room is itself evidence.
Captured from a clean room
Every capture runs in a disposable container with no profile, no extensions and no local overrides, and the image digest is recorded inside the manifest — so the environment is part of the evidence rather than something you are asked to take on trust. What is kept is the wire, not the pixels: DNS resolution, the full certificate chain, request and response, the page as the browser built it, and video of the session.
Several points of view, one seal
Phishing infrastructure shows different pages to different visitors, by device, country and referrer. A single capture invites the reply that there was nothing there. UniSeal captures several vantage points under one seal, so cloaking becomes part of the record instead of a hole in it.
Redaction that leaves no gap
A full record goes to the registrar; a published version holds back whatever identifies a victim. There is no second sealing step: the manifest lists every artefact the capture produced, so a version that withholds some of them publishes the fact that it did, and still verifies. That is the difference between a redaction and a gap.
Verified without us
The tree is RFC 6962, the canonical form is RFC 8785, and the anchor is OpenTimestamps over Bitcoin. A recipient checks a seal with the artefact, its inclusion path and the anchored root — offline, with no call to this server and no account. If verifying required us to be online and honest, the whole point would be lost.
Who this is for
Abuse desks and takedowns
A phishing site is often gone within hours of being reported. A registrar needs to see what it was, not read a description of it.
Infringement
A listing, a post or a page that will be edited the moment anyone official notices it.
Records you may have to produce
A page you need to show later exactly as it stood on the day, to someone entitled to doubt you.
Built on published standards, so nobody has to take our word for the format either.