Evidence Custody

Every artifact is content-addressed. Ingestion verifies tenant-owned uploaded bytes against an issued upload receipt, declared size, and SHA-256 address before the artifact can enter the verified state.

Public hosted capture uses a separate worker-authenticated ingestion boundary. Its signed envelope is accepted as independent only after worker identity, scope, receipt, bytes, and custody verify. Browser-recorder, CLI, CI, manual, and customer-imported evidence remains customer-attested or imported as appropriate; callers cannot self-label it independent.

The recorder applies field allowlists, DOM and accessibility-tree scrubbing, screenshot masking, and a user-visible redaction preview before upload. Interrupted uploads are resumable and idempotent. Hosted workers never receive authenticated customer sessions.

Retention, legal hold, audit export, token scope, revocation, project archive, privacy export, and deletion are separate controls. A sealed record cannot silently replace missing or tampered bytes.