Skip to content

Human-rights records

Witness may be useful for committing to the existence of a carefully preserved record while sending only a hash to the gateway. This is a technical evidence workflow, not a guarantee of safety, anonymity, authenticity, or admissibility.

Minimize exposure

  1. Preserve the source material in a controlled evidence system with access and integrity procedures appropriate to the people involved.
  2. Hash the exact file locally; do not upload the content to Witness.
  3. Submit the digest with the supported CLI workflow:
witness attest --file record.bin --save record-job.json
witness status <hash>
  1. After confirmation, retain the signed attestation and the verification configuration with the protected record.

Caveats and safety boundaries

Do not assume that hash-only submission protects a person: a public, known, or small candidate file can be guessed, and the gateway can observe IP address, timing, user-agent, and proxy metadata. Do not put names, locations, case IDs, or other identifying material into filenames or surrounding requests unless the risk has been reviewed.

Freebird can make admission eligibility less linkable to issuance, but it does not hide transport metadata or make a deployment safe against a compromised operator. Follow the threat model and local safeguarding requirements before using a public service.