Services & fees · Same-day capture
Same-day capture
You name one public address; both witnesses fetch it today, independently of each other, and the bytes go into that day’s seal like every other observation. The extract for that single day comes with it.
If this is the first product page you have opened: this archive has recorded, every day since 22 July 2026, what around 128,000 EU domains serve to machines, sealing each day so nobody can alter it afterwards. This particular product does one thing, and it does it today: it puts one address you name into today’s record. Everything else here rests on a record that was already running. This one is for the matter already on your desk, the page still says it this morning, and you have no way of knowing whether it will still say it once the other side has heard from you.
Where this is used
Case 1A page that will not survive the first letter
Someone has published a statement that is going to be contested: a claim about a product, a price, a term of business, an assertion about a competitor. Right now it is there, in public, for anyone to read. The moment the first letter arrives, it may be edited, softened or taken down, and what remains is an argument about what it used to say.
A capture made before that letter goes out turns the question from recollection into record: the exact bytes the server delivered, the moment of retrieval to the second, the response headers, and the chain to a day that was sealed and handed out of this house before anyone knew there was a dispute.
Unfair competition · advertising claims · litigation counsel
Case 2The same capture, asked for by the side being accused
An allegation arrives with a screenshot attached. A screenshot is the other party’s own account of events, and it can be disputed for exactly that reason, but disputing it is not the same as showing what was really there.
Anyone may ask for this, including the side defending itself, at the same published fee and on the same terms. The address is fetched, the day is sealed, and the resulting document does not favour whoever paid for it. Where the page has already changed, that too is a fact this archive will state plainly rather than conceal.
Defence · pre-litigation · in-house counsel
Case 3Your own page, on the day before it is replaced
A site is about to be relaunched, a price list reissued, a set of terms superseded. Afterwards the old version exists only in a content management system that the company itself controls, which is precisely the reason an opponent will not accept it.
Capturing the page on its last day puts the old version outside your own control, where it can be produced later without anyone having to take your word for how it got there.
Relaunch · terms and price changes · company counsel
What you can use it for
A same-day capture answers these questions, for the day it was made:
- What exactly did this address serve on that day, byte for byte?
- At what moment was it fetched, to the second, in UTC?
- Was it publicly reachable at all, or did the server refuse the request?
- Was it fetched by an independent third party rather than by a party to the matter, and can that be checked without us?
- Did the same address already stand under observation before today, and if so, since when?
Typical use: filed as an exhibit to a pleading. If the method is challenged rather than the content, the technical procedure statement is filed alongside it.
- You name the addressOne public URL. We do not ask what the matter is.
- Both witnesses fetch it that dayTwo machines at two providers, each storing its own copy.
- The day is sealedThe bytes join that day’s fingerprint, alongside every other observation made.
- The extract followsPDF and ZIP for that one day, with the path to the root and the anchors.
The capture happens on the day we confirm your request in writing. The extract that documents it follows within five working days, or within 48 to 72 hours where a court deadline is running and you say so when you order.
What happens to the address afterwards. It stays in the daily record like every other, at no further charge, so a second capture weeks later is a matter of ordering another extract rather than starting again. The day already sealed stays sealed in any case: nothing here is ever withdrawn.
What is recorded, field by field
Each witness fetches the address you named and stores, separately from the other: the exact bytes the server delivered, their SHA-256 fingerprint, the complete response headers, the TLS certificate chain presented at delivery, the address the request finally resolved to after any redirects, and the moment of retrieval in UTC. Where the server refuses the request or does not answer at all, that fact is recorded with the same care as content and appears in the extract as what it is. A refusal on the day in question is itself a fact about that day, not a failed order.
Any public address, not only a front page. A page deep in a site, a document, a feed, a price list as JSON, if it answers a plain request without a login, it can be captured. What cannot be captured is anything a visitor only reaches after signing in.
Full field-by-field schema, with a worked example: what we store.
What is not recorded, and when this is the wrong tool
Bytes, not pixels. What the server sent, not how a browser would have drawn it. If your matter turns on what the page looked like (the placement of a notice, the size of a disclaimer, what a consumer would have seen above the fold), this is the wrong instrument, and we would rather say so before you pay than afterwards. A capture shows what was delivered; it does not show a rendering.
Pages assembled by script. Where the text only appears after JavaScript has run, the bytes we receive may be close to empty. We check this before confirming, and where it applies we decline the request with a reason instead of selling a capture of nothing.
A moment, not a whole day. The capture is evidence of what the address served at the moment stated in UTC. It says nothing about the hours before or after, and the extract does not pretend otherwise.
Also not recorded: anything behind a login, any rating, any comparison. And no notification: if something changes afterwards you will not hear from us, because a witness that alerts one side is no longer a witness to both.
What sealed means here
This block is the same on every page of this site, and it is repeated on purpose: it is the part you need in order to judge everything else.
- One fingerprint for the whole day. Every observation made that day, yours among hundreds of thousands, is reduced to a single hash through a Merkle tree. One changed byte anywhere in that day, and the fingerprint no longer matches. There is no version that could be quietly corrected.
- Published where anyone can see it. The fingerprint goes into the public log the same night, under a fixed, citable URL, together with the instructions for recomputing it.
- Handed out of the house three times on the same day. An RFC 3161 time-stamp service, a decentralised OpenTimestamps anchor in the Bitcoin blockchain, and a qualified eIDAS time-stamp from GLOBALTRUST (e-commerce monitoring GmbH, Austria), a qualified trust service provider listed on the EU Trusted List. The third of these is paid for and supervised, and it is worth saying so plainly: only the qualified time-stamp carries the presumption laid down in Article 41(2) eIDAS. A free anchor establishes that the data existed and has not changed, but it carries no presumption laid down by law.
- Twice over, by two witnesses that cannot write to each other. Two machines at two providers in two countries, with separate keys. Each seals its own day and takes its own anchors.
In plain words, two sentences. We cannot change a byte afterwards, because the day's fingerprint would no longer match. And we cannot backdate one, because that fingerprint has been in other people's hands since the night it was made. No one has to believe us: every step can be repeated with standard tools.
Further: how it works · what we store · glossary.
Does this stand up in court?
We cannot promise that, and nobody can promise it honestly: what a court accepts is for the court to decide. What we can tell you is what the document is made of, and each of the four facts below can be checked before you buy anything.
- It comes from a third party, not from you. Not your screenshot, not your server log. You ask for the capture, but you do not make it: the bytes are fetched and stored by a third party that does not know your matter and does not ask about it. That is the difference between a record and an account of events. Where the address already stood under observation before you asked, the record is stronger still, because it then predates the dispute, and the extract states plainly which of the two applies, rather than leaving the stronger reading to be assumed.
- A presumption laid down by law. Every sealed day since 31 July 2026 carries a qualified electronic time-stamp from a qualified trust service provider on the EU Trusted List. Under Article 41(2) of Regulation (EU) No 910/2014 (eIDAS), such a time-stamp enjoys a presumption of the accuracy of the date and time it indicates and of the integrity of the data it is linked to. Article 41(1) says something much narrower, namely that a time-stamp may not be denied legal effect merely because it is electronic. The two paragraphs are routinely confused; the one that matters here is the second.
- Two independent witnesses. Two machines, two providers, two countries, separate keys. Each one seals its own day and anchors it externally on its own. Neither can write to the other, so neither can be corrected to match the other after the fact.
- Verifiable without us. An appointed expert repeats every step with standard tools: recompute the hash of the file, rebuild the path from that hash to the day's root, check the root against the public log and against the external anchors. We do not have to be believed, and that is the point of the whole construction.
What follows from this in your particular matter is for your lawyer to say. We do not advise, do not rate and do not take a side, and the other side can order the same document on the same published terms. That is not a weakness of the document. It is the reason it is worth anything.
How to order
- By e-mail to contact@machinewitness.eu, or through the form on this site. Name the address, and your billing address with a VAT number if you have one. We do not ask what the matter is.
- We confirm in writing what we received and name the fee for your request. Nothing is charged before you have that in writing.
- You receive a payment link.
- Delivery normally within five working days of a complete request; if a court deadline is running, say so when you order and we handle it within 48–72 hours instead, ahead of the normal queue.
- The capture is made on the day we confirm. The extract documenting it follows, and the address appears in the public record with the date it entered.
We answer in German, English or Spanish.
Fee
150 € for one address, with the extract for that day included, as set out in the fee table. Each further address on the same domain in the same request: 50 €. Where the address already stands under observation, the capture costs nothing extra, only the extract is charged, and the coverage check tells you which case you are in before you ask.
Form of the result
A PDF and a ZIP for the day in question. The PDF states what was fetched, when, by which witness, with what result. The ZIP carries the delivered bytes themselves, the response headers, the certificate chain, the path from the file’s hash to that day’s root, the anchors, and a plain-text description of how to recompute each step without us. Both witnesses appear in it, separately, so the two can be held against each other.
The method sheet is included. Every extract comes with the general method sheet at no extra charge, including the one covering a single day. It describes how this archive observes, seals and anchors, and it carries a version and a date. It is not written for your matter, and it does not have to be: it is the same for everyone, which is precisely what makes it checkable.
The technical procedure statement is a different document, written for this particular observation, signed and addressed to a court or an appointed expert. You do not need it in order to file the extract. It becomes relevant when the other side disputes the method rather than the content. See the fee table.
What becomes public, and what does not
Visible to anyone
- that the domain or URL is observed, and from which date
- the dated entry in the public record of admissions
- the daily roots and anchors, as for every other observation
Never published
- who applied, in no document
- why: we do not ask what the matter is
- what the files said: content is issued only as an extract, at the published fee, to anyone
The other side can see that the URL is observed, and since when. That is the price of a witness that belongs to no party, and it belongs here, before the purchase, not in the small print. Where a look-alike domain is observed as a precaution, an opponent may infer that someone is preparing. Whoever does not want that buys a capture of a single day instead of a standing observation.
Neutrality. This archive records; it does not rate, rank or advise. Three conditions hold for everything on this page: it is visible to everyone in the same way; the fee is published and depends neither on who asks nor on how a matter ends; and whoever pays receives nothing a third party would not also receive, which means no notification, no mention as the applicant, no priority, and no content without an extract that anyone else could order too.
Further reading: how it works · evidence extract · terms, section 5.