Take the photos, work through the checklist, close the file. That is all the person taking the photos has to do: the app puts the date, time and place into the image, works without a signal, and has an independent service timestamp the file. Below is everything the app and the dashboard do, part by part.

On site, with wet hands: the app says what is still missing and draws the details into the image.

Signed on the device, sealed by an independent service, and anyone can check it themselves.

What you send on, how you share it, and where your photos stay.


Orders set out, evidence gathered from outside, and everything in your own system.

Date, time to the second, address and your company name, drawn into the image rather than stored beside it. It survives a printout, a screenshot and a photocopy, and it stays readable in black and white, because a report often arrives on paper. Nothing to set up: the first photo already carries it.
Where it stops: the bar shows the device clock, and that is a stated value. The file carries the timestamped time next to it, and that is the one that is fixed.

A step asks for a minimum number of photos and for the things a photo cannot show: a number plate, a meter reading, a serial number, a date, a choice from a list. The app can read the plate or the meter in the viewfinder and propose it; you confirm, and your confirmation is what goes in. Every value travels inside the capture, under the device signature and the seal, so it sits under the same signature as the photo.
Where it stops: a checklist does not make the series complete. Whoever takes the photos still chooses what to photograph, and the report names the steps left open instead of hiding them.


The signing key is created inside the secure hardware of the phone and cannot be exported, on either platform: the Secure Enclave on iPhone, the hardware keystore on Android. Apple attests it through App Attest, Google through hardware key attestation. The counter that fixes the order of your captures comes from the same place.
To the person receiving the file it makes no difference at all: the same file, the same report, the same verification page, the same checks. A team where half the crew is on Android does not end up with two classes of evidence.
Where it stops: attestation establishes that the app was unmodified on a genuine device. It says nothing about what the camera was pointed at.
A dispute is rarely about thirty photos. It is about the one showing the pipe, or the two showing the damage. So the app makes an extract: those captures at full resolution, plus the handful of hashes that show they fall under the file’s seal, plus the same timestamp as the whole file.
It carries exactly the same weight as the full file, because it hangs from the same seal. It fits in an email, where a full archive of thirty photos does not. And it keeps the other twenty-eight photos out of the hands of the other party, which in a home or a business is usually more than the argument is about.
Where it stops: an extract says on its own face that it is capture 3 of 12, and which ones are missing. That is deliberate. Anyone can then ask for the whole file.


A company with five people on the road has a different question from a single user: who is going where, with which checklist, and is it done. The dashboard answers that. You set up orders with an address, a template and a person; they appear on that person’s phone under “Prepared for you”; and you watch the status move from prepared to picked up to registered. Members, roles and your own templates live there too, and you can search across everything your field staff recorded, including number plates and meter readings.
The same thing is available as an API with webhooks, so files land in your own system instead of in an inbox. That is the route for an insurer or a lender who wants the evidence to arrive where the claim already is.
What the dashboard shows: the registry: fingerprints, sequence numbers, seals and registry receipts. It can open photos in two places, and only because an organisation asked for it: the delivery answering a request, and files kept at EverStamp once an owner or administrator switches that on. Every opening through the dashboard or the API is written to that organisation’s audit log with who and when. Technically EverStamp can open them too, because we manage the key; we do that only at the organisation’s written request, or when a court or authority orders or demands it under the law.

An insurer needs photos from the policyholder. An energy supplier needs a meter reading when someone moves house. A valuer needs photos of the property before a desktop valuation. None of those people want an account or a subscription.
So you send a link. They see who is asking and what for, they work through the checklist, and what comes back is a file with the same device signature, the same seal and the same registry entry as one made by your own field worker. They take the photos in the EverStamp app, which they install first if they do not have it yet.
Where it stops: a guest is a name on a file, not an account. And the strength of what comes back is the same as everything else here: it establishes that these photos existed in this form by the time of the stamp, not what they show.