Apps · Fieldstamp

The inspection where nobody travels.

Send a link. The other person opens it on the phone in their hand — no app, no account — points the camera at the damage, and you talk them round it. You tap to capture; the photo is taken at the sensor's own resolution, hashed on their device, and lands in a log that can be added to and never quietly edited. Then you export the report.

Nothing for them to install Video never touches a server Append-only evidence log

0 apps to install the person you need a photo from is the one least likely to install anything
0 frames stored on a server the live video is peer-to-peer; the stills stay in the inspector's browser
2 hashes per capture one of the image, one of the chain it sits in

The session

You open it

Name the session after the claim or the job. That name is the storage key the evidence log is written under, so a second inspector opening the same session sees the same log.

They join from a link

A browser, a camera permission, and nothing else. The picture comes straight from their phone to yours — the channel only carries who is here.

You ask, they point

Pick a template — motor claim, property condition, equipment handover — and each prompt appears on their screen in type you can read outdoors. Ask for anything else by typing it.

You capture

The still is grabbed on their device at the camera's full resolution, not pulled out of the compressed video. It arrives in chunks, gets re-hashed on your side, and is rejected outright if the two hashes disagree.

What a stamp holds

Every capture carries the facts that make it worth something later, and nothing that would make it a liability.

  • Time — the instant, in ISO and in the phone's own timezone.
  • Who and what — the name they joined under, the device, the screen.
  • The image — pixel dimensions, byte count, and the SHA-256 of the bytes.
  • Location, only if offered — off by default. When it is switched on, the coordinates are rounded to about eleven metres before they are stamped, let alone sent: enough to say which building, not which window.

Notes are stored beside the photo, never drawn into it. An annotation that alters the pixels alters the evidence, and then the hash no longer describes what the camera saw. So your notes travel with the entry and the image is left exactly as it was taken.

The chain

Each entry's chain hash is taken over the entry before it. That is the whole trick, and it is the reason a Fieldstamp log can be added to but not rewritten.

chain · how each link is made
chain₀ = SHA-256( "fieldstamp:<session>" | imageHash₀ | canonicalStamp₀ )
chain₁ = SHA-256(        chain₀           | imageHash₁ | canonicalStamp₁ )
chain₂ = SHA-256(        chain₁           | imageHash₂ | canonicalStamp₂ )

Remove the second photo, reorder two of them, or change a single character of a stamp, and every hash from that point on stops matching. Verify the chain in the console re-derives the whole thing and names the first entry that does not hold. The stamp is serialised with its keys sorted, so the same entry hashes to the same value in any browser, on any machine, next year.

Underneath, the log is written with the platform's storageAdd, which appends a version rather than replacing the last — so the history is kept by the storage layer as well as by the hashes.

The report

One self-contained HTML file: every photo at full resolution, its stamp, its two hashes, and the instructions for re-deriving the chain from the top. Open it and print to PDF and it is the same document.

The full-resolution photos are in that file and in your browser. They are not in our storage and never were — what went to storage is the stamp, the hashes and a thumbnail.

Export report saves fieldstamp-<session>.html
Verify the chain re-derives every hash and names the first break
Reopen the session restores the log from storage, thumbnails only

What Fieldstamp does not do, and you should know before you sell it. Both people have to be online at the same time — there is no record-now-send-later mode yet, and that is the single biggest reason a claimant drops out. The chain proves the log has not been altered since it was made; it says nothing about whether the person pointed the camera at the right car. And a rural mobile connection will give you a poor live picture even though the captured stills come off the sensor at full resolution — the preview is not the evidence.

Pricing

What it costs

Commercial — metered per completed inspection

Commercial, metered per completed inspection rather than per seat — an adjuster who does two inspections this month should not pay like one who does two hundred.

The split is the point of the price: the live video is peer-to-peer and never recorded, full-resolution photos stay in the inspector's browser and in the exported report, and only the stamp, the hashes and a thumbnail are stored. Footage of a stranger's home never becomes anybody's liability.

Talk to us before your first real claim — the first inspection is on us.

How it's built

The part that matters, in the open

Every entry's chain hash covers the one before it, so the log appends and never quietly rewrites.

js/fieldstamp-core.js
async function chainNext(prev, imageHash, stamp) {
    return sha256Text(prev + '|' + imageHash + '|' + canonical(stamp));
}

Taken from this app's source, not written for the page. Built on the Messaging Platform SDK.