Rashnova
The evidence layer for your Windows PC: a sealed record of what happened on it.
Rashnova is the evidence layer for Windows. Switch on continuous recording and it runs as a quiet system service, recording every USB connection, file open, sign in, program start with its full command line, PowerShell execution, change to critical registry keys and browser window title. Every entry is sealed to the one before it, so a change anywhere shows. Every week it hands you a plain summary of what your machine actually did. When the device has to leave your hands, Repair Mode seals the whole visit into a report you can give to anyone.
SESSION
A3F2-9C1A-4F0B
EVENTS
1,284
INTEGRITY
100%
SECOND COPY
ENCRYPTED
RECORDER
RUNNING
Three things worth a look this week.
RECORDING UNINTERRUPTED · 43 DAYS
COVERS FILE READS, USB, PROCESSES, BOOTS. DOES NOT SEE SCREEN CONTENT, KEYSTROKES OR NETWORK PAYLOADS.
USB DEVICES OBSERVED
2 unique drives
BYTES MOVED
5.0 GB
HASH CHAIN . SEALED
6 of 1,284 blocks
WATCHDOG . ACTIVE
Self-healing monitor
UPTIME 31d 04h 12m
RESTARTS 0
UPTIME 31d 04h 12m
RESTARTS 0
UPTIME 12h 45m
RESTARTS 1
UPTIME 31d 04h 11m
RESTARTS 0
[14:31:08] WATCHDOG_RESTART_LOGGED
USB Watcher process_id=4892 stopped unexpectedly
elapsed_until_restart_ms=4720
action=process_relaunched verify=ok
chain_entry_written hash=8a02f1 prev=c54bd7
integrity_unbroken
FORENSIC REPORT . SIGNED PDF
Session A3F2-9C1A-4F0B
EVENTS
1,284
DURATION
47 min
INTEGRITY
100%
# report.pdf, manifest excerpt
session_id A3F2-9C1A-4F0B
chain_root 0xb24a91...e8d2
events 1284 (CRIT 1, HIGH 2, INFO 1281)
integrity sha256_chain unbroken
watchdog 1 restart logged inline
shadow_copy aes-256-gcm verified
signature pkcs7_signed_data ok
verify offline: rashnova-verify report.pdf
Under the hood.
Standard, proven parts. Nothing invented.
Rashnova is built on well established, standard cryptography, not anything of our own invention. Standard parts, assembled into a whole where any change shows.
- +Runs quietly in the background, through reboots
- +Every entry sealed to the one before it
- +An encrypted second copy of the record
- +Your PIN never stored in a form that could be turned back into it
Tampering is mathematically forced to leave a mark.
Editing one entry breaks the seal on every entry after it. Deleting the main log leaves the encrypted second copy behind. Stopping the recorder leaves a gap the record itself points to. Every kind of interference produces evidence.
- +The chain breaks visibly if any row is altered
- +The second copy survives the main log being deleted
- +A stopped recorder leaves a gap on the record
Two ordinary weeks, and one that was not.
Most weeks the Readout is unremarkable: a few hundred file reads by your browser under Documents, two USB devices seen, nothing copied to removable media. That is the point: you looked, and now you know. Then the laptop goes in for a screen replacement. You arm Repair Mode, collect it two days later, and the sealed report shows one technician login, four file opens all inside the diagnostic folder, no USB devices, no new processes. Proof that nothing else happened. Had it instead shown a USB stick arriving and the user-photos folder being read, you would have evidence the law cares about.
Rashnova.
Trust is good. Proof is better.
Free for individuals, forever. Everything stays on your PC, and it produces evidence you can check on day one.
