Timestamping
What is timestamped, what is hashed, and why it is not an electronic signature.
A sealed evidence package also needs to be verifiably placed in time. RestorSignal distinguishes four possible timestamping profiles, labeled T0 through T3, which do not offer the same level of guarantee.
T0 — Application timestamp
This is simply the date the application recorded at the moment of the event — an ordinary timestamp, with no cryptographic mechanism attached. It places the event in time but guarantees nothing beyond what the system that produced it asserts.
T1 — RestorSignal secure timestamping
RestorSignal can provide a secure timestamping service that operates only on the evidence package's fingerprint (its hash) — never on its content. The service receives that fingerprint and returns a signed record specifying, among other things, the hash algorithm used, the document's hash, the date and time, the timestamping policy applied, the service version, and its own signature.
T2 — Independent third-party timestamping
In this profile, only the package's fingerprint is submitted to a third-party timestamping service, independent of RestorSignal. The principle is the same as in T1 — only the fingerprint travels, never the content — but the guarantee rests on a separate third party.
T3 — Qualified external timestamping
This profile refers to external timestamping backed by a legal and technical qualification that is genuinely established. It can only be used when that qualification is actually in place for the relevant context — it is not a profile available by default or in every situation.
What is timestamped, and what never is
One point deserves to be stated explicitly: regardless of the profile, only the evidence package's cryptographic fingerprint is sent to the timestamping service — never its content. The timestamping service therefore never sees the restored data or the detail of the results; it receives a fingerprint, and returns a certified date for that fingerprint.
This is not an electronic signature
The vocabulary needs to be precise: this mechanism is timestamping combined with cryptographic hashing, not an electronic signature in the legal sense of the term. The two notions serve different needs, and RestorSignal must never use the term "electronic signature" to describe what is technically a timestamping and integrity mechanism.
In the same way, T1 must never be presented as equivalent to T2 or T3: each profile rests on a different chain of trust, and conflating them would overstate the guarantee actually provided by RestorSignal's internal timestamping service.
The T1 service's time source
The T1 timestamping service itself relies on a time source whose reliability is actively monitored: regular synchronization against a UTC reference, monitoring for drift in that source, logging of any time-related incident observed, and explicit refusal or degradation of the service whenever the time source can no longer be considered reliable. A T1 timestamp is therefore never produced "blindly" against a clock whose reliability has not been verified.
Retention
Every evidence package is associated with a retention policy, whose duration can depend on the subscribed plan, the tenant, or a specific contractual requirement. One important point: temporary data produced during a restore (particularly in a disposable environment) does not automatically follow this long retention policy that applies to evidence package metadata — these are two distinct retention regimes, and they should not be confused with one another.