SIDR

Honesty

What SIDR does not do.

Every control on this product has an edge, and a buyer who finds the edge after signing has been sold something. Here is each limit we know about, in plain words, with what we do instead. The same list is inside the product, and the reader sees the first item on it before they agree to anything.

The six limits

1 · We cannot stop a camera.

A person sitting in front of a screen can photograph it with the phone in their other hand. Nothing delivered to a web browser prevents that — not ours, and not anyone’s. A product that claims otherwise is describing a wish.

What we do instead. We make the photograph attributable. The reader’s address, the deal, the time and a code unique to their copy are rendered into the page before it is displayed, so they are in the photograph by construction rather than as a layer that could be switched off. We can’t stop a camera. We can name the photo.

One caveat on that, because it matters: we have measured how well the mark survives a screenshot, a crop and a re-compression. We have not yet completed the real-device test for a photograph taken with a phone camera at an angle, and until we have, we make no claim at all about camera survival rates. When that test runs, the result goes here whether or not we like it.

2 · A visible mark can be cropped, and the invisible one is probabilistic.

The tiled mark is spread across the whole page so that a fragment still carries it, but someone determined enough can crop to a region that misses it, or retype the numbers into a new document. A second, invisible per-copy mark is designed to survive that; it is a statistical technique, which means it returns a likelihood, not a certainty, and it can be defeated by enough degradation.

What we do instead. We treat both marks as attribution evidence rather than prevention, and we say so in the agreement the reader accepts. Attribution is what actually changes behaviour: the reader knows their name is on the copy before they open it.

3 · A step-up proves control of a credential and a device, not who is in the room.

When a reader confirms with Face ID or a fingerprint to open a level, the check happens on their own device and we receive a cryptographic assertion that a verification succeeded. That is strong evidence that the enrolled credential and the enrolled device were both present. It is not evidence about which human being was looking at the screen, and it cannot be. Someone can be handed an unlocked phone.

What we do instead. We record precisely what we can defend: that a user-verified assertion was produced by a named credential on a named device at a stated time. The certificate says the same thing in the same words, so nobody reading it later can mistake it for a claim about presence. No biometric image or template ever reaches our servers, and there is no camera in this product.

4 · Our OpenTimestamps proofs are calendar commitments until a Bitcoin attestation is observed.

Every batch of events is timestamped by three independent authorities. Two are RFC 3161 tokens from DigiCert and FreeTSA and they are complete on issue. The third, OpenTimestamps, commits to a calendar server first and is upgraded later when it is included in a block — and we have not yet observed one of our proofs upgraded.

What we do instead. The verifier and the certificate both print the state they actually read: calendar, not bitcoin. A row that has not reached an anchored batch yet says pending. We would rather show you a weaker word that is true. Separately, nothing inside a package chains a timestamp authority’s certificate to a trusted root — the verifier states that on its face too.

5 · There is no write-once store yet.

The evidence chain is append-only and tamper-evident: altering a past entry breaks the chain and the verifier detects it and identifies the entry. That is detection, not prevention. A write-once, read-many store, which would make the underlying bytes physically unalterable for a retention period, is designed but not built.

What we do instead. We say “tamper-evident” and never a stronger word, and the certificate references the served artefacts rather than claiming they sit in a vault they do not sit in. The store is planned; when it ships, this paragraph changes.

6 · We do not detect screenshots.

A web page cannot reliably tell when an operating system takes a screenshot. Our research prototype logged focus changes and print-screen keypresses as a deterrence signal, and we measured that this catches almost nothing real. The product therefore does not do it at all: there is no such listener in SIDR and no such event in the record.

What we do instead. Nothing, and we would rather tell you that than show you a line in a log that means less than it looks like it means. The mark on the page is the mechanism here; a screenshot carries it.


Three more, briefly, because they get asked.

We are not a data room. SIDR sits beside one. It does not host your closing checklist or your Q&A workflow, and it is not trying to.

We do not take a position in your deal. No success fee, no custody of funds, no rating of your counterparties, no opinion about whether a deal is good. The product has no screen anywhere that mentions money moving.

A certificate is not a court outcome. It is a record designed to support your position. What it proves and what it does not are printed on its own face, and no version of it says otherwise.

The seventh thing — a commitment, not a mechanism

“Your record does not depend on us existing. Every evidence package verifies offline with open tools, you can export it at any time, and if SIDR ever ceases to operate every customer gets a 90-day export window before anything is deleted.”

Two of those three clauses are tested engineering facts — offline verification and on-demand export. The 90-day export window is a business and legal commitment the founder is making, not a piece of software with a test; we say so rather than call it “verified” the way the hash chain is.

Still the most useful page we have.

If any of the six is a dealbreaker for your process, it is better that you know now — and we would genuinely like to hear which one. If none of them is, the room takes a few minutes to set up.