CaseStamp : Evidence Log

Verify a Report

Last updated: July 27, 2026

If someone has handed you a CaseStamp report, you don't need the app, an account, or anything from CaseStamp to check whether a file in it is genuine. Every entry lists a SHA-256 hash — a 64-character fingerprint of that exact file — and you can recompute it yourself with a command already built into your computer.

1. Get the original file

You need the original photo or video file — the one attached to the email or shared alongside the report, not an image copied or extracted out of the PDF. A PDF re-encodes images when it embeds them, so a picture pulled out of the report won't match the hash even if nothing is wrong. If you only have the PDF, ask the sender for the original files.

2. Compute its hash

3. Compare

Compare the result character-for-character to the SHA-256 hash printed next to that entry in the report. Some tools print it in uppercase or with spaces between characters — ignore case and spacing, only the characters themselves matter.

If it matches exactly, the file is byte-identical to the one recorded at the time shown in the report. If even one character differs, the file has changed since then.

What a match proves — and what it doesn't

A match proves the file is the same one CaseStamp hashed at the moment listed in the report — not a re-save, re-compression, or edited copy. It doesn't prove what the photo or video depicts, and it doesn't independently confirm the device's clock was accurate at the moment of capture. A timestamp and hash record when a file was saved and whether it's changed since; they can't confirm the story behind it.

A mismatch doesn't automatically mean a file was altered. It can also mean you're hashing a copy that was re-saved, re-compressed, or extracted from the PDF rather than the original file.

See How It Works for the standards behind this, and the FAQ for common questions.

← Back to CaseStamp