Verify a chain of custody record
Enter the verification code from an Authenticated Chain of Custody Form to confirm its tamper-evident seal is intact. Verification is free, requires no account, and never reveals the contents of the form.
Independent cryptographic verification operated by Lexeprint Inc. — chain-of-custody records designed with reference to FRE 901, ISO/IEC 27037, and NIST SP 800-86.
How verification works
When a form is created, CustodyTrack seals it with a hash value — a digital fingerprint of its contents. Every custody event that follows (creation, each transfer) is sealed with its own hash value that incorporates the previous one, forming a chain where altering any link breaks every seal after it.
When you verify, we recompute the entire chain and compare it to the sealed record. It works like a tamper-evident seal: if anything changes — a date, a name, a custody event — verification fails.
Only hash values and minimal metadata are checked. The evidence details on the form are never shared through this page.
A single code checks a single record. To check the whole ledger instead — every custody event on every form, re-computed end to end — run the public audit.
Common questions
- Do I need an account to verify a record?
- No. Verification is free, requires no account, and does not identify you to the party that created the record. Enter the code and the check runs immediately.
- Where do I find the verification code?
- It is printed on the Authenticated Chain of Custody Form itself, usually alongside a QR code that opens this page with the code already filled in. Whoever produced the form can also supply the code on its own.
- Does verifying reveal what the evidence is?
- No. The check compares hash values and minimal metadata. Item descriptions, case numbers, and the names of the parties are not disclosed by verifying — which is why a code can be handed to an opposing party without waiving anything.
- What does it mean if verification fails?
- That the record as stored no longer matches the seal computed when it was created, or that the code does not correspond to any record. A failure is a reason to ask questions about the record's handling; it is not, by itself, a finding about anyone's conduct.
- Who operates this verification service?
- CustodyTrack.io, operated by Lexeprint Inc. The check is arithmetic over stored hash values, and the whole ledger can be re-computed end to end by anyone through the public audit page — verification does not rest on trusting the operator.
What a result establishes — and what it does not
A passing check establishes three things
- A record with this code exists, and was created before the moment you are reading it — not assembled in response to a challenge.
- Its contents have not changed since it was created. Each entry is bound to the one before it, so altering an earlier entry breaks every entry after it and the check fails.
- The transfers it lists were acknowledged by both parties at the times shown, rather than written down afterwards by one of them.
It does not establish these
- That the evidence is admissible. Admissibility is decided by a court applying the rules of evidence in your forum. A custody record is one input to that question and never the answer to it.
- That the item described is what someone says it is. The record documents handling from the point it was created onward. What happened before that first entry is outside it entirely, and a well-kept record of a badly-collected item is still a badly -collected item.
- That the people named are who they claim to be. The record captures the identity asserted at each transfer. It is evidence of what was asserted and when, not an identity verification service.
- That nothing happened off the record. A custody record can only describe transfers someone entered into it. A gap in a chain is visible; an unrecorded handoff between two recorded ones is not.
If the check fails
A failure means the stored record no longer matches the seal computed when it was created, or that no record corresponds to the code. Both are worth asking about and neither is a finding about anyone's conduct — a mistyped code produces the same result as a modified record. Check the code against the printed form first, including characters that are easily confused. If it still fails, the person who produced the form is the one who can explain it.
Why you do not have to trust us
This check is run by the party with an interest in it passing, which is a fair objection. It is why the whole ledger can be re-computed end to end by anyone, without an account and without seeing the contents of any record. The arithmetic is the same arithmetic; running it yourself removes us from the answer.
What this page is doing, explained
Reference guides on how a cryptographic digest demonstrates that a file has not changed, and on the authentication rules that make the question matter.
Need to create a record of your own? See what an Authenticated Chain of Custody Form records.