FAQ

Domande dettagliate

Le risposte qui sotto riprendono gli aspetti più tecnici, giuridici e pratici della FAQ storica.

When you click on 'Take a photo', the app performs multiple integrity checks on your phone and communicates them to the CertiPhoto information system. All data collected before, during and after the shot are encrypted several times per second, compiled at the time of sending, and finally verified upon receipt by the certification servers.

When all these steps are validated, the photo is formatted in a PDF document which will then be signed and timestamped, and finally sent to the user.
Yes. CertiPhoto produces documents with high probative value, at least in the French and European Courts. They are time stamped, electronically signed and strictly impossible to tamper with.

According to the Directive 1999/93/EC of the European Parliament, the electronic signature [must be] uniquely linked to the signatory, be capable of identifying the signatory, be created using means that signatories can maintain under their sole control, be linked to the electronic document to be authenticated. This is to ensure that any subsequent change in that document is detectable.
You just have to send a paper print of the certificates along with the original files on a USB key, so that the judge will be able to check the cryptographic information contained in the PDF documents.
Certificates are LTV-compliant (Long Term Validation) and include all cryptographic data necessary for their verification with no limit in time.

Their lifetime on CertiPhoto cloud, and therefore the possibility of viewing them online, is at least 2 years after the shot was taken.
Every evidence can be challenged about its probative value, whether it's a digital certificate or a bailiff's report. In such a case, CertiPhoto's source code and activity logs are designed to be audited as part of a forensic examination, under terms of a non-disclosure agreement.
Absolutely not. Pictures are timestamped by a secure trusted authority such as DigiCert or GlobalSign, which are among the most important certification services in the world. This is a verifiable and irrefutable mathematical link between your photo and the precise moment it was taken.
In individual mode, you manage your own credits and can acquire new ones directly from the Play Store or the App Store. This is the default mode.

In professional mode, your account is linked to a company that shares its credits with you. This allows a manager, designated as administrator, to manage the credits at the company level in a single operation.

An individual user can join a company at any time from the My account/Company mode menu by entering a unique 8-character code. Optionally, it is also possible to automatically link an account during its creation based on the e-mail address.

The professional mode also gives access to a board which allows you to manage the whole company's photos.
The CertiPhoto IT infrastructure is 100% GDPR compliant and is hosted in French data centers. Databases are replicated over three different sites and collected data are protected with multi-factor authentication.

These information are sealed by daily checksums to ensure their integrity according to a process inspired by the NF Z42-013 French norm. They will never be disclosed to any third parties, except with prior agreement from the user or upon a judicial authority's request.

You have a right to view and control your personal data and may at any time require their consultation or destruction.
No. CertiPhoto constantly communicates with its backend to check how your device is operating when you take a picture. The same goes for geolocation, which combines data from multiple sources for maximum accuracy and reliability.
No. The certification must apply an electronic signature and a secure timestamp when the picture is shot. Otherwise, there will be no way to prove that the picture has not been tempered with in the meantime or that it was taken on a specific date.
This forgery technique consists in distorting the reality in front of the camera lens. It is known in forensics science as "rebroadcasting" and exists since the invention of photography.

CertiPhoto can not detect in real time if you are misleading it. And no computer system is able to do so with an acceptable error rate at the current state of technology.

What we can do though, is to collect enough information at shot time to correlate them manually if a certificate is disputed. It will then be possible to demonstrate with a high probability whether the photo was falsified, but this can only occurs ex-post.

If there is still a doubt, a further analysis will be carried out using forensic investigation tools like Amped Authenticate. If it appears that the picture has been forged, the corresponding certificate will be immediately revocated.

Note that any user can dispute a photo from the share link or the thumbnail embedded in the certificate.

Important: if you fool the application to submit in court a certificate stating inaccurate facts, you are committing an offense which is liable to imprisonment for one year and a 15,000 euros fine (art. 441-7 of the French Criminal Code).
API stands for Application Programming Interface. It's a tool intended to interact with CertiPhoto's databases outside the app. This allows for instance to recover, in a single command line or via a web browser, photos taken by a particular phone, or at a specific location, or between defined dates.

The sorting possibilities are very wide and can be adapted to your needs. These advanced features are particularly useful in the professional area, because they allow a company to overcome the computer management of certified photos.
The app is designed for bilingual French/English use. Other languages may be added in the future depending on demand.