Services & fees · Access record
Access record
Everything else here records what a domain served. This records the opposite direction: which machines arrived to fetch it. You point a host of your own at this archive by DNS, and every request that reaches it is written down and sealed by us, not by you.
If this is the first product page you have opened: this archive has recorded, every day since 22 July 2026, what around 128,000 EU domains serve to machines, sealing each day so nobody can alter it afterwards. That covers what a site said. It does not cover who came, and your own server logs, which do, belong to you, which is exactly why they settle nothing.
Starting date. This one needs a machine that receives traffic rather than one that only reaches out, on hardware kept apart from both witnesses. The date on which recording starts for your host is confirmed to you in writing before anything is charged.
Where this is used
Case 1The half of the story your own records cannot tell
A publisher has done everything correctly: the reservation stands in the files machines read, and a standing observation shows it stood there on every day in question. The remaining question is what arrived at the door, and the only evidence for that lives in the publisher’s own server logs, written by the party they would benefit, held by it, editable by it.
Here the requests are received and written down by a third party. The daily entries go into the same seal as every other observation, so a request recorded on a Tuesday cannot be adjusted on Wednesday. What any of it means is for the lawyer; this archive records arrivals and draws no conclusion from them.
Copyright · text and data mining · publishers and agencies
Case 2Simply knowing which machines come at all
Before any dispute, there is a plainer question that most operators cannot answer: which automated visitors reach this site, how often, and how do they identify themselves. Server logs hold the answer somewhere, mixed into everything else, and they are rarely kept long enough to show a year.
A single host, declared openly and recorded daily, gives a clean series over time. Next to it sits this archive’s own daily record of what the crawler operators themselves published, their documentation and their declared addresses, on that same day. The two can be held side by side, and neither of them is our opinion.
Site operators · preventive recording · technical and legal together
Case 3An operator showing that it was not them
The direction reverses as easily here as anywhere else: an operator of automated software is told its systems fetched something they should not have, and its position is that the traffic was not theirs at all, a name in a request is a claim, not proof, and anyone can put any name in one.
A record kept by a third party, alongside that party’s dated record of which addresses each operator publicly declared as its own, serves that argument exactly as well as the opposite one. That symmetry is not a concession; it is the reason the record is worth producing.
Crawler operators · defence · in-house counsel
What you can use it for
For the host, and for every day from the admission onwards:
- Which requests reached it on that day, at what time, and for which paths?
- How did each request identify itself, and from which address did it arrive?
- What did the host’s own files say to machines on that same day?
- Which addresses had the crawler operators themselves published as theirs on that day?
- Can the day be checked against a public seal without us?
- You point a host at usA name on your domain, by DNS. Nothing is installed anywhere.
- The host says openly what it isDeclared as a witness host, in its own files and in the public record here.
- Every request is written down and the day is sealedReduced to one fingerprint, like every other observation.
- The root is anchored outside this archiveHanded out of the house the same day, so it cannot be corrected later.
The host is not hidden and not disguised. It says in its own files what it is and that requests to it are recorded, and it is listed here as a host this archive operates. Anything that only works by concealment would make this a different kind of business, and not one worth being in.
Typical use: alongside a standing observation of the same domain, because the two answer the two halves of the same question, what was published, and what arrived. Filed as an extract.
What is recorded, field by field
For each request reaching the host: the moment it arrived in UTC, the path requested, the method, how the request identified itself, and the address it came from, handled as described below. The day’s entries are reduced to a fingerprint that joins the same daily seal as every other observation in this archive.
Addresses are personal data, and are treated as such. Where a request comes from an address that the operator of an automated service had itself published as one of its own on that same day, the entry is kept in full: that is a company’s own declaration about its own machines. Every other request is kept only as a salted fingerprint of the address together with its network range, which is enough to show that requests recurred without recording who anybody was. This split is a deliberate limit on what the record can be used for, and it is not negotiable per customer.
The host’s own files are recorded too, on the same daily footing as any observed domain, so the record shows what the host was telling machines on the day they came.
Full field-by-field schema, with a worked example: what we store.
What is not recorded, and what this is not
Not your live site. This is a separate host, not your production server, and no traffic of yours is routed through this archive. What is recorded is what reaches that one name, and nothing else.
Nothing concealed, nothing baited. The host declares what it is. It is a visitors’ book at a door that is marked as such, not a device for provoking behaviour that would not otherwise have happened. We would not build the other thing, and a record produced by concealment would be worth less in any case.
No conclusion about any request. Whether an arrival was permitted, whether it contradicted anything, whether it was the operator it claimed to be: none of that appears. The entry says a request arrived and how it presented itself. Next to it stands the dated record of what the operators published about themselves. Putting the two together is legal work, and legal work is not ours.
And no notification. You will not hear from us when something arrives, because a witness that alerts one side is no longer a witness to both.
What sealed means here
This block is the same on every page of this site, and it is repeated on purpose: it is the part you need in order to judge everything else.
- One fingerprint for the whole day. Every observation made that day, yours among hundreds of thousands, is reduced to a single hash through a Merkle tree. One changed byte anywhere in that day, and the fingerprint no longer matches. There is no version that could be quietly corrected.
- Published where anyone can see it. The fingerprint goes into the public log the same night, under a fixed, citable URL, together with the instructions for recomputing it.
- Handed out of the house three times on the same day. An RFC 3161 time-stamp service, a decentralised OpenTimestamps anchor in the Bitcoin blockchain, and a qualified eIDAS time-stamp from GLOBALTRUST (e-commerce monitoring GmbH, Austria), a qualified trust service provider listed on the EU Trusted List. The third of these is paid for and supervised, and it is worth saying so plainly: only the qualified time-stamp carries the presumption laid down in Article 41(2) eIDAS. A free anchor establishes that the data existed and has not changed, but it carries no presumption laid down by law.
- Twice over, by two witnesses that cannot write to each other. Two machines at two providers in two countries, with separate keys. Each seals its own day and takes its own anchors.
In plain words, two sentences. We cannot change a byte afterwards, because the day's fingerprint would no longer match. And we cannot backdate one, because that fingerprint has been in other people's hands since the night it was made. No one has to believe us: every step can be repeated with standard tools.
Further: how it works · what we store · glossary.
Does this stand up in court?
We cannot promise that, and nobody can promise it honestly: what a court accepts is for the court to decide. What we can tell you is what the document is made of, and each of the four facts below can be checked before you buy anything.
- It comes from a third party, not from you. Not your screenshot, not your server log. The bytes were fetched and stored by a third party that did not know your matter existed, on a day chosen by the calendar and not by the case. That is the difference between a record and an account of events.
- A presumption laid down by law. Every sealed day since 31 July 2026 carries a qualified electronic time-stamp from a qualified trust service provider on the EU Trusted List. Under Article 41(2) of Regulation (EU) No 910/2014 (eIDAS), such a time-stamp enjoys a presumption of the accuracy of the date and time it indicates and of the integrity of the data it is linked to. Article 41(1) says something much narrower, namely that a time-stamp may not be denied legal effect merely because it is electronic. The two paragraphs are routinely confused; the one that matters here is the second.
- Two independent witnesses. Two machines, two providers, two countries, separate keys. Each one seals its own day and anchors it externally on its own. Neither can write to the other, so neither can be corrected to match the other after the fact.
- Verifiable without us. An appointed expert repeats every step with standard tools: recompute the hash of the file, rebuild the path from that hash to the day's root, check the root against the public log and against the external anchors. We do not have to be believed, and that is the point of the whole construction.
What follows from this in your particular matter is for your lawyer to say. We do not advise, do not rate and do not take a side, and the other side can order the same document on the same published terms. That is not a weakness of the document. It is the reason it is worth anything.
How to order
- By e-mail to contact@machinewitness.eu, or through the form on this site. Name the host you intend to use, and your billing address with a VAT number if you have one. We do not ask what the matter is.
- We confirm in writing what we received and name the fee for your request. Nothing is charged before you have that in writing.
- You receive a payment link.
- Nothing is delivered at this stage, because what you are buying is the record itself. Extracts drawn from it later arrive within five working days; where a court deadline is running, say so when you order and we handle it within 48–72 hours instead, ahead of the normal queue.
- We tell you in writing whether and from when this can start. Only then is anything charged, and the host is entered in the public record with its date.
We answer in German, English or Spanish.
Fee
450 € per year per host, charged yearly in advance, as set out in the fee table. Extracts at the same published fees as for anything else here. Nothing is charged until we have told you in writing that it can start: and if the answer is that it cannot yet, that is what you will be told.
Form of the result
A dated entry naming the host in the public record. There is no document at this stage; the document is the extract drawn later for the days in question.
The method sheet is included. Every extract comes with the general method sheet at no extra charge, including the one covering a single day. It describes how this archive observes, seals and anchors, and it carries a version and a date. It is not written for your matter, and it does not have to be: it is the same for everyone, which is precisely what makes it checkable.
The technical procedure statement is a different document, written for this particular observation, signed and addressed to a court or an appointed expert. You do not need it in order to file the extract. It becomes relevant when the other side disputes the method rather than the content. See the fee table.
What becomes public, and what does not
Visible to anyone
- that the domain or URL is observed, and from which date
- the dated entry in the public record of admissions
- the daily roots and anchors, as for every other observation
Never published
- who applied, in no document
- why: we do not ask what the matter is
- what the files said: content is issued only as an extract, at the published fee, to anyone
The other side can see that the URL is observed, and since when. That is the price of a witness that belongs to no party, and it belongs here, before the purchase, not in the small print. Where a look-alike domain is observed as a precaution, an opponent may infer that someone is preparing. Whoever does not want that buys a capture of a single day instead of a standing observation.
Neutrality. This archive records; it does not rate, rank or advise. Three conditions hold for everything on this page: it is visible to everyone in the same way; the fee is published and depends neither on who asks nor on how a matter ends; and whoever pays receives nothing a third party would not also receive, which means no notification, no mention as the applicant, no priority, and no content without an extract that anyone else could order too.
Further reading: how it works · evidence extract · terms, section 5.