Security

Controlled access to case materials

Akta provides a dedicated folder for one matter, available only to people with assigned permissions. Materials are stored in their designated folder, and each addition, check, download and handoff is recorded in a linked activity history. Any break in that history’s continuity is detectable.

Register-continuity check

A change to part of a file identifies where register continuity is lost.

Each register entry carries the fingerprint of the preceding entry, and new events can only be appended. Changing any part causes the seal and the following links to become inconsistent. Fingerprints are computed in this browser; nothing leaves your device.

Linked-entry register

    Fingerprints are computed in this browser with SHA-256. The result reports consistency with recorded values or the point at which register continuity is lost. The check concerns technical integrity and does not determine evidentiary weight.

    The lifecycle of access

    Access is granted through a controlled process

    Access to materials requires completion of the permission-granting procedure. Each stage is recorded in the activity history.

    Place
    Account and folder

    A dedicated workspace is created for one specific matter. The service stores materials only in their assigned case folder.

    Permission
    Access assigned to a person

    The folder owner or law firm grants access to a specific person and defines the scope of that person’s permissions. Knowing a link or case number is not a basis for access.

    Adding
    Materials in the folder

    A person authorized to access the matter adds a material using “Upload an export or document” or “Capture a web page”. The file is stored in its assigned folder and receives a SHA-256 fingerprint.

    Handoff
    A package with a contents list

    The recipient receives a set with a file list, source descriptions and instructions for an independent check.

    Protection against unauthorized access

    Case identifiers do not grant access

    A link alone

    A folder address does not grant permission to view its contents. Access requires an individually assigned permission.

    A case number alone

    A case number identifies the matter but does not provide a basis for access to its materials.

    An upload without an account

    Materials can be added only after sign-in and within a closed case folder. The service provides no anonymous file-upload form.

    Package assigned to another user

    A package is visible only through a proper handoff to a named recipient.

    Information available to an authorized person

    Scope of information in the folder

    Permission scope

    A named list of people authorized to access the folder, together with the scope of their assigned roles.

    Material register

    Every material with its description, date of addition and recorded digital fingerprint.

    Activity history

    A chronology of additions, checks, downloads and handoffs.

    Handoff scope

    A package with a contents list and independent-check instructions.

    Technical control

    Mechanisms for checking material integrity

    Digital fingerprints, a linked activity history and a seal enable comparison of the current state with previously recorded values.

    FingerprintSHA-256 and SHA-512 fingerprints

    Two fingerprints are computed for every file. A later change causes an inconsistency with the values recorded when the file was added.

    HistoryLinked activity history

    Every event carries the fingerprint of the preceding event. Altering the history causes a detectable loss of continuity.

    SealSeal with time-status information

    The seal covers a fingerprint of the matter state. Its result says whether an independent timestamp or a technical system-time record was used.

    Additional mechanisms
    Source version kept read-onlyAfter upload, the source version is retained in read-only form. Its fingerprint provides the reference for later checks.
    Consistency check on demandThe service recomputes the fingerprint and compares it with the value recorded when the file was added.
    Source-version descriptionThe user describes the source, and technical information stored in the file is checked for edit traces.
    Public seal registryThe latest register fingerprint and the continuity of its links can be checked publicly without an account.
    A package for independent checkingThe ZIP package contains a file list, an activity history and verification instructions. The opposing party or a court can check it independently.
    Additional sign-in verificationSign-in can require a second factor, and access scope is defined separately for each case folder. The account and its materials can be permanently deleted under the service rules.
    Material provenance attestationA portable, signed provenance attestation can be created for a material. It links the fingerprint, source, timestamp and history, and the recipient can independently verify its validity.

    These mechanisms support comparison of the file and its linked history with values recorded earlier. They do not determine the authenticity of the content or its evidentiary weight. That assessment belongs to the court, where appropriate with expert evidence.

    Safeguards check result

    The seal status reflects the checks that were performed

    An account type does not confer an eIDAS level. The result reports technical safeguards, time attestation and confirmed qualified status separately.

    Technical safeguardsalways checked
    • SHA-256/512 fingerprint
    • Append-only seal chain
    • Explicit status of the recorded time

    These elements document file consistency and history continuity. They are not automatically an advanced eIDAS signature or seal.

    Qualified statusonly when confirmed
    • Qualified timestamp from a verified trust-service provider
    • Separate checks of the provider and service status
    • An explicit statement in the verification result

    Status is not inferred from the account type, a file fingerprint or an internal technical label.

    File-integrity check

    A technical reference point for the selected file version.

    Select a file. The browser computes its SHA-256 fingerprint, records the operation time and creates a seal. A later change will cause an inconsistency with the recorded values. The file is not transmitted from the device.

    Source fileSHA-256 · locally
    Drag a file to this area
    Documents, images, recordings and e-mail messages are supported
    Select a file from the device
    INTEGRITY CHECK RESULTawaiting

    Select a file to create a reference record and check the consistency of its current version.

    TECHNICAL RESULTAWAITING
    0%

    Select a file to create a record and check the consistency of its current version.

    SHA-256 FINGERPRINT
    TIMESTAMPRFC 3161
    ENTRY NUMBER#000 · initial entryAPPEND-ONLY REGISTER
    Material handling cycle

    Adding, sealing and handing off a material are documented in a linked activity history.

    1. AddingA fingerprint computed when the file is stored in the folder.
    2. SealA fingerprint of the matter state with an explicit statement of the time attestation used.
    3. HandoffA package with a contents list for independent checking.
    Access to folder functions

    Material operations are available after folder activation

    This page explains the access rules. Receiving files, permissions, activity history and package handoff work only inside an active account with an assigned folder.

    Activate an account and folder