machinewitness

Services & fees · Twelve-month record

Twelve-month record

Twelve months of one domain in a single document: for every observed address, the days on which it changed, what it said either side of each change, and the chain from each of those days to a seal that was published and anchored at the time.

If this is the first product page you have opened: this archive has recorded, every day since 22 July 2026, what around 128,000 EU domains serve to machines, sealing each day so nobody can alter it afterwards. An extract turns one of those days into a document. This one turns a whole year into a document: because the question that usually decides a matter is not what a page said on one day, but since when it said it, and what it said before.

Where this is used

Case 1The authority does not ask what it says, but since when

A supervisory authority looks at a notice that is plainly there today and asks the only question that matters for the period under review: was it there in March, and in what wording. An extract for a single day answers for that day. A screenshot answers for this morning. Neither answers for a year.

This document does: every day of the period is accounted for, the days on which the wording changed are named, and the versions either side of each change appear as the bytes that were actually served. Where a page was unreachable on some day, that is stated too, rather than quietly closed over.

Compliance · supervisory review · data protection officer

Case 2A pattern that only shows over time

Some matters do not turn on a single state but on a sequence: a reservation that appears, disappears and reappears; a claim that is quietly softened each time a letter arrives; conditions that move shortly before a deadline. Each individual day proves little, and assembling the sequence by hand invites the objection that whoever assembled it chose the days.

Here the days were not chosen. Every day of the period is in the document because every day was recorded, and the change dates fall out of the record rather than being asserted. What follows from a sequence is for a lawyer to argue; this archive supplies the sequence and draws no conclusion from it.

Unfair competition · copyright · litigation counsel

Case 3The same year, ordered by the side defending itself

An allegation often contains an implicit claim about time: that something was never there, or was added only after the fact. The defence needs the same twelve months the other side is relying on, and it needs them from a source that does not belong to either party.

Anyone may order this for any observed domain, at the same published fee, and the document does not change according to who paid for it. Where the record shows the notice was there all along, it shows that; where it shows the opposite, it shows that too.

Defence · regulatory proceedings · in-house counsel

Nothing is fetched for this document. It is drawn from days that were already sealed, which is the reason it can be made at all. ALREADY SEALED Days that exist already Up to twelve months of one domain, every observed address. ON REQUEST The changes are found The days on which something changed, and what it said either side. FOR EACH DAY The chain is written out From each file to that day’s published root and its outside anchors. YOU HOLD One document, checkable Method sheet included. An expert repeats every step without us.
Nothing is fetched for this document. It is drawn from days that were already sealed, which is the reason it can be made at all.

What you can use it for

Over the whole period, for every observed address of the domain:

  • Since when has it said what it says now?
  • On which days did it change, and what did it say before each change, byte for byte?
  • Was it reachable on every day of the period, and where not, on which days?
  • Was anything added or removed during the period, and on which day?
  • Can each of those days be checked against a public seal without us?
  1. You name the domain and the periodTwelve months, or less. We do not ask what the matter is.
  2. The days are read out of the archiveNothing is fetched now; the days were recorded when they happened.
  3. The change days fall out of the recordNot chosen by anyone: a change is a change of the stored fingerprint.
  4. Each day comes with its chainFrom the file to that day’s root, to the public log and the external anchors.

Nothing new is observed for this document. It is assembled entirely from days that were already recorded, sealed and anchored at the time, which is precisely why it cannot be shaped to suit whoever ordered it.

Requires that the domain was under observation during the period. This document cannot reach back to days nobody recorded. The free coverage check says whether a domain is observed and since when; where it is not, the record can start today with a standing observation, and a year from now this document will be available for that year.

What is in the document

A PDF and a ZIP. The PDF states the domain, the period, which addresses were observed and by which witness, then for each address a dated list of the days on which its content changed, with what it said before and after each change. Days on which the server refused or failed to answer appear as what they were. The ZIP carries the bytes themselves for every version named, the response headers, the certificate chains, and for each day the path from the file’s hash to that day’s root, the root as published, and the external anchors, with a plain-text description of how to recompute every step without us.

Both witnesses appear separately, so the two independent records can be held against each other rather than presented as one voice.

The method sheet is included, and the period may be shorter than twelve months at the same fee; a shorter period is not cheaper, because the work is in the assembly, not in the length.

Full field-by-field schema, with a worked example: what we store.

What this document does not do

It does not interpret the sequence. The change days are stated; what they mean, whether a change was significant, whether it suggests anything about anyone’s intentions, is not our business and appears nowhere in the document.

It cannot cover days before the observation began, and it does not estimate them. Where the record starts in the middle of the period you asked for, the document says so on its first page instead of quietly starting later.

Bytes, not pixels, here as everywhere: what the server sent, not how a browser would have drawn it.

And it carries no rating, no comparison and no conclusion: the same document goes to whoever asks for it, on the same terms.

Diagram: a captured file is hashed (SHA-256), the hash is placed on a Merkle path to that day's root, the root is checked against the public log, and outside anchors confirm the date, independently of MachineWitness.
The chain behind “sealed,” explained in the block below.

What sealed means here

This block is the same on every page of this site, and it is repeated on purpose: it is the part you need in order to judge everything else.

  1. One fingerprint for the whole day. Every observation made that day, yours among hundreds of thousands, is reduced to a single hash through a Merkle tree. One changed byte anywhere in that day, and the fingerprint no longer matches. There is no version that could be quietly corrected.
  2. Published where anyone can see it. The fingerprint goes into the public log the same night, under a fixed, citable URL, together with the instructions for recomputing it.
  3. Handed out of the house three times on the same day. An RFC 3161 time-stamp service, a decentralised OpenTimestamps anchor in the Bitcoin blockchain, and a qualified eIDAS time-stamp from GLOBALTRUST (e-commerce monitoring GmbH, Austria), a qualified trust service provider listed on the EU Trusted List. The third of these is paid for and supervised, and it is worth saying so plainly: only the qualified time-stamp carries the presumption laid down in Article 41(2) eIDAS. A free anchor establishes that the data existed and has not changed, but it carries no presumption laid down by law.
  4. Twice over, by two witnesses that cannot write to each other. Two machines at two providers in two countries, with separate keys. Each seals its own day and takes its own anchors.

In plain words, two sentences. We cannot change a byte afterwards, because the day's fingerprint would no longer match. And we cannot backdate one, because that fingerprint has been in other people's hands since the night it was made. No one has to believe us: every step can be repeated with standard tools.

Further: how it works · what we store · glossary.

Does this stand up in court?

We cannot promise that, and nobody can promise it honestly: what a court accepts is for the court to decide. What we can tell you is what the document is made of, and each of the four facts below can be checked before you buy anything.

  1. It comes from a third party, not from you. Not your screenshot, not your server log. The bytes were fetched and stored by a third party that did not know your matter existed, on a day chosen by the calendar and not by the case. That is the difference between a record and an account of events.
  2. A presumption laid down by law. Every sealed day since 31 July 2026 carries a qualified electronic time-stamp from a qualified trust service provider on the EU Trusted List. Under Article 41(2) of Regulation (EU) No 910/2014 (eIDAS), such a time-stamp enjoys a presumption of the accuracy of the date and time it indicates and of the integrity of the data it is linked to. Article 41(1) says something much narrower, namely that a time-stamp may not be denied legal effect merely because it is electronic. The two paragraphs are routinely confused; the one that matters here is the second.
  3. Two independent witnesses. Two machines, two providers, two countries, separate keys. Each one seals its own day and anchors it externally on its own. Neither can write to the other, so neither can be corrected to match the other after the fact.
  4. Verifiable without us. An appointed expert repeats every step with standard tools: recompute the hash of the file, rebuild the path from that hash to the day's root, check the root against the public log and against the external anchors. We do not have to be believed, and that is the point of the whole construction.

What follows from this in your particular matter is for your lawyer to say. We do not advise, do not rate and do not take a side, and the other side can order the same document on the same published terms. That is not a weakness of the document. It is the reason it is worth anything.

How to order

  1. By e-mail to contact@machinewitness.eu, or through the form on this site. Name the domain and the period, and your billing address with a VAT number if you have one. We do not ask what the matter is.
  2. We confirm in writing what we received and name the fee for your request. Nothing is charged before you have that in writing.
  3. You receive a payment link.
  4. Delivery normally within five working days of a complete request; if a court deadline is running, say so when you order and we handle it within 48–72 hours instead, ahead of the normal queue.
  5. The document is delivered as PDF and ZIP; the fact that an extract was issued is not published, and the other side is not told.

We answer in German, English or Spanish.

Fee

450 € for one domain and up to twelve months, as set out in the fee table. The same fee covers every address of that domain that was under observation during the period, and it covers the domain’s registration and DNS history too where a domain record was running. A second domain in the same request is a second document at the same fee.

Form of the result

PDF and ZIP, delivered by e-mail or by a download link that does not expire without notice. Paper on request, at cost, where a court requires it.

The method sheet is included. Every extract comes with the general method sheet at no extra charge, including the one covering a single day. It describes how this archive observes, seals and anchors, and it carries a version and a date. It is not written for your matter, and it does not have to be: it is the same for everyone, which is precisely what makes it checkable.

The technical procedure statement is a different document, written for this particular observation, signed and addressed to a court or an appointed expert. You do not need it in order to file the extract. It becomes relevant when the other side disputes the method rather than the content. See the fee table.

What becomes public, and what does not

Visible to anyone

  • that the domain or URL is observed, and from which date
  • the dated entry in the public record of admissions
  • the daily roots and anchors, as for every other observation

Never published

  • who applied, in no document
  • why: we do not ask what the matter is
  • what the files said: content is issued only as an extract, at the published fee, to anyone

The other side can see that the URL is observed, and since when. That is the price of a witness that belongs to no party, and it belongs here, before the purchase, not in the small print. Where a look-alike domain is observed as a precaution, an opponent may infer that someone is preparing. Whoever does not want that buys a capture of a single day instead of a standing observation.

Neutrality. This archive records; it does not rate, rank or advise. Three conditions hold for everything on this page: it is visible to everyone in the same way; the fee is published and depends neither on who asks nor on how a matter ends; and whoever pays receives nothing a third party would not also receive, which means no notification, no mention as the applicant, no priority, and no content without an extract that anyone else could order too.

Further reading: how it works · evidence extract · terms, section 5.