ProofShot · In proof

ProofShot — the aperture mark and wordmark from the production brand pack.

Capture what matters online.
Keep proof you can verify anywhere.

Local-first Windows proof workstation: capture what matters online, keep a proof bundle with SHA-256 receipts and a Proof Passport, and verify it later without trusting the tool or the internet. Rebrand in progress — the engine currently ships as HyperSnatch v1.6.18 under its legacy name.

No public build yet
Status In proof Version Platform Windows Tests 99/99 E2E Proof verification pending Verified
The ProofShot Workbench on a fresh proof workspace: the four-step flow, the intake panel, and the status and proof-card stack.
The Workbench on a fresh proof workspace — real capture from the v1.6.18 build, using the synthetic demo case the product ships with.
Local-first, no account
Receipts + SHA-256 manifests
Tamper-evident by design
Offline verifier in every bundle

One workbench takes it in. Nothing runs by itself.

The job is one sentence: something online matters, and you want it captured with proof. Paste a URL or a page into the Workbench and SmartDecode reads what the target actually contains — offline.

SmartDecode (v2.5.0, built into this release) works on the page's own text. It reads the structure the page declares for itself — scripts, stylesheets, images, links, embedded declarations — and separates what is real from what is not.

  • Everything is resolved locally: no account, no upload, no cloud hop.
  • Refusals are kept apart from candidates, so the operator sees what was dismissed and why.
  • A full capture keeps the page's own artifacts and structure, not just a summary.

Capture is structural, not photographic. This build reads and records the page's own resources and receipts; there is no pixel-screenshot engine in it. What you see below is a real SmartDecode run — two candidates identified, best target selected.

The Workbench intake panel after a real SmartDecode run: status reads Decode complete, two candidates identified, best target selected.
A real SmartDecode run on a pasted page: “Decode complete: 2 candidate(s) identified and best target selected.” The input is a synthetic demo page.

What it reads

Scripts, stylesheets, images, links, and encoded declarations — the page's own references.

Refusals separated

Incomplete or non-extractable references are refused, listed separately, never mixed into results.

Offline by default

The extraction pipeline runs locally, with no account and no network dependency.

A plan you can read — and run yourself.

Decode produces candidates, ranks them, and says which one is the best target and why. Then it hands you a plan — it never acts on your behalf.

Every candidate gets a confidence score and a place in a deterministic ranking. The best target is selected the same way every time, and the extraction table shows the source and the score. A retrieval plan is generated from the result — a command the operator can run, change, or ignore.

  • Candidate rows show what was found, where it came from, and how confident the engine is.
  • The plan is output, not action. Nothing is fetched, downloaded, or executed automatically.
  • Results are deterministic: the same input produces the same ranking on every run.
The candidates table with two scored candidates and the generated retrieval plan above it.
Two scored candidates from the real run above, with the generated plan. In the screenshot the plan is a request the operator can run — SmartDecode does not run it.

Confidence, with reasons

Scores come from the extraction pipeline itself and sort deterministically.

Best target selected

One candidate is chosen as the best — the one the plan is built around.

Operator runs the plan

The generated plan is a starting point for the operator, never an autonomous action.

One folder per engagement.

Everything captured for one matter stays together, locally, in a simple project container.

A case is a workspace folder with a name and an ID — created in one click from the Cases panel. Items added to it keep their timestamps, and the case list shows the count at a glance. It is deliberately simple: a container for evidence and its receipts, not a team collaboration system.

  • Create a case, name it, and it appears with its own ID and creation time.
  • Items hold their own hashes and receipts inside the case folder.
  • The whole workspace lives on the machine — no cloud project, no shared account.
The Cases panel with a real case row: case ID, case name, item count, and timestamp.
A real case created in the running build — ID, name, item count, and local timestamp.

One-click case

Create a named case from the Cases panel; it appears with its own ID.

Local timestamps

Every item and case carries the machine's own time when it was recorded.

Simple by design

No team workspaces, no shared projects — a container, on purpose, per the product freeze.

Export a bundle you can hand over.

One export writes the whole matter to a folder you choose: the captured page, its artifacts, and the proof files that let anyone check it later.

The proof bundle is the product. Its layout is fixed and documented, and every file in it is covered by a SHA-256 manifest. A Proof Passport states what the bundle is, when it was exported, and why — and the bundle carries its own offline verifier so someone with zero software can check it.

  • One export writes the full bundle: artifacts, captured page, receipts, manifests, and the verifier.
  • Proof Passport summarises the matter; SHA256SUMS.txt covers every file.
  • The proof-card stack (passport, tamper trial, diff, nutrition) shows everything that can be proven about the workspace at a glance.
The Workbench after a real export: the bundle has been written, Prove It Again and Tamper Trial are now enabled.
A real export from the running build — the bundle lands in the folder you chose, and Prove It Again and Tamper Trial unlock.
The proof-card stack on the Workbench: Proof Passport, Tamper Trial, Proof Bundle Diff, and nutrition cards.
The proof-card stack — passport, tamper trial, diff, and nutrition for the loaded workspace.
The exported bundle's fixed anatomy — this exact layout came out of the running build.

Verify later — without trusting ProofShot or the internet.

The whole point of the bundle is that it outlives the tool that made it.

Proof is checked against the files, not against this product. Prove It Again re-verifies an exported bundle directly from disk, and the offline verifier shipped inside the bundle does the same job on any machine with a browser. The Tamper Trial proves the system sees changes: it runs four temp copies of the bundle — a modified artifact, a missing hashed file, an altered passport, and a deleted verifier — and each tamper is caught.

  • Prove It Again recomputes and compares hashes against the bundle's own manifests.
  • The verifier HTML ships inside every bundle — verification needs no software install.
  • The Tamper Trial is a real self-test: four tampered copies, all detected.
Prove It Again re-verifying the exported bundle from disk.
Prove It Again, run from disk against the exported bundle — a real re-verification.
The Tamper Trial results: modified file, missing file, altered passport, and deleted verifier, each marked as caught.
The Tamper Trial against four temp copies of the export — modified, missing, altered, and deleted files, each caught.

What this product is not

Words matter, and the cheapest way to trust a proof tool is to be exact about its limits:

  • Not court-certified — nothing here certifies anything for court.
  • Not a chain-of-custody — we record hashes and receipts, not custody.
  • Tamper-evident, not tamper-proof — changes are detected and reported; nothing is unhackable.
  • Not a legal evidence platform — verification is the operator's to interpret.
  • Not a media ripping utility — capture is one input type into a proof bundle, not the product's purpose.
  • Not ProofForge — that is a separate project; the names are not interchangeable.

The ProofShot rebrand, stated plainly.

The public identity has moved; the packaging has not. This section says exactly where each name stands.

The production brand pack shipped the aperture mark, wordmark, and hero artwork you see on this page. But a rename is not a name change until it reaches the files people run — so the v1.6.18 application still presents itself as HyperSnatch inside its own UI, and the bundle it exports still says so. That is deliberate: UI strings are batch-renamed in a controlled rebrand release, not patched one by one.

Public name
ProofShot — the product identity this page and the brand pack use.
Current build
HyperSnatch v1.6.18 — the same engine, still shipped under the legacy name.
Reserved name
Proof Forge — the underlying proof-bundle engine name, reserved and not claimed here.
Parent
The Proof Foundry — the studio that produces ProofShot.
The ProofShot production brand hero artwork: the aperture mark over a dark steel-and-cyan landscape.
The ProofShot brand hero from the production asset pack (designer artwork).

One honesty note about branding collateral: the example hashes and timestamps inside the brand pack's asset manifest are illustrative placeholders from the designer handoff — they are artwork metadata, not verification evidence for this product. The hashes that matter are the ones inside a proof bundle.

Release status & evidence

Current status of the internal build. The public release under the ProofShot name is not out yet — this is the present state, not a promise.

Runtime UX pass
Complete (story screens captured from the live build)
Smoke suite
99/99 E2E
Build
Electron desktop application: SmartDecode v2.5.0 extraction pipeline, proof-bundle export (SHA-256 manifests, Proof Passport, offline HTML verifier), 99/99 E2E green. Rebrand in progress — the engine ships as HyperSnatch v1.6.18 under the original brand while ProofShot identity work continues.
Released artifact (ProofShot)
None — no artifact served under this name yet
Underlying engine
HyperSnatch v1.6.18, public under the legacy name
ProofStrip status
verification pending

The underlying engine (HyperSnatch v1.6.18) is public under its legacy name, with a 99/99 E2E test suite, SHA-256 checksums, and release receipts. The ProofShot rebrand has not yet propagated through packaging and code, so no release or download is claimed under the ProofShot name. ProofForge is a separate project and is not this product.

Known limitations

Honest about what is not ready.

No public download under the ProofShot name

The engine ships as HyperSnatch v1.6.18 under the original brand while identity migration continues. No artifact is served under the ProofShot name until the rebrand completes across packaging and code.

UI still carries the legacy name

The v1.6.18 app title, shell, and strings still read HyperSnatch. Batch rename is held for a controlled rebrand release — this page is the public-facing side of that migration, done first on purpose.

Capture is structural, not photographic

SmartDecode reads and records the page's own resources and structure. There is no pixel-screenshot capture engine in this build, and no engine will be added while the product freeze is active.

Scoped by the product freeze

No new extraction engines, intelligence features, or automation lanes while the freeze stands. Cases stay simple project containers, and proof means hashes, receipts, and tamper-evidence — nothing more.

Other Proof Foundry products