For CFOs, legal teams, and technical evaluators
The condition ledger your legal team will actually accept.
A photo album proves someone took photos. A VeriProp sealed report proves when they were taken, by whom, where, and that not a single byte has changed since. That difference is what decides deposit disputes.
Why a sealed report is legally different from a photo record
Every photo is hashed at the moment of capture, on the tenant's device. Those hashes are combined into an evidence root, bound to tenant identity, GPS coordinates, and a server timestamp, and sealed. When the manager countersigns, a final acknowledgement hash closes the chain.
Tamper-evident by construction
Changing, adding, removing, or editing any photo after sealing breaks the hash chain. This includes AI-generated edits, crops, filters, or any modification of the original bytes. Tampering is not merely forbidden - it is mathematically detectable.
Provable timeline
The tenant cannot claim photos were added after move-out, and the operator cannot be accused of backdating evidence. The seal timestamp is part of the hash itself.
Readable by a tribunal
The sealed report is a structured document with a verifiable integrity hash - the same principle used in qualified electronic signatures, applied to property condition.
Not just photos. Cryptographic proof.
A photo on a phone proves nothing. A VeriProp sealed report is mathematically tamper-proof and legally defensible.
File Hash
SHA-256 of photo bytes, computed client-side at capture
Evidence Root Hash
SHA-256 of all file hashes in display order
Report Integrity Hash
SHA-256(evidence root + tenant identity + GPS + timestamp)
Acknowledged Hash
SHA-256(integrity hash + manager IP + user agent + server timestamp)
The claim that matters in a dispute
The tenant cannot allege the operator added, swapped, or edited photos after move-out - including AI-based inpainting or any pixel-level modification. The operator cannot be accused of backdating evidence. Both directions of accusation fail against the same chain, because every hash is fixed at seal time and each level depends on the one below it. Symmetric non-repudiation is the product; the cryptography is the mechanism.
The condition delta: dispute prevention made visible
Every move-out report is compared, surface by surface, against the sealed move-in baseline of the same tenancy. The output is not a pile of photos - it is a structured comparison a property manager can review in minutes.

From raw data to portfolio health.
Turn individual condition reports into actionable, portfolio-wide intelligence.
Condition trends by building
Identify which buildings degrade fastest and which unit types require more frequent refurbishment. Allocate CAPEX with confidence.
Move-out workload forecasting
Know weeks in advance what work each building needs. Book contractors and order materials before the seasonal rush.
Damage pattern detection
Discover which unit types and building configurations produce disproportionate wear. Allocate maintenance budget where it compounds.
| Room type | Move-in condition | Move-out condition | Assessment |
|---|---|---|---|
| Bathroom | CLEAN | STAINED | Significant wear |
| Kitchen - appliances | NEW | STAINED | Significant wear |
| Kitchen - surfaces | NEW | MARKED | Minor wear |
| Bedroom - furniture | CLEAN | MARKED | Minor wear |
| Bedroom - floor | CLEAN | CLEAN | Unchanged |
| Bedroom - walls | CLEAN | MARKED | Minor wear |
Example output from a 56-unit pilot building. Generated automatically after each move-out wave.
Cost intelligence, not just condition intelligence.
Every remediation job gets logged against the condition report that triggered it. Over time this builds a real cost baseline, not an estimate. Which buildings cost the most to turn over. Which unit layouts wear fastest. Which cities run hotter on refurbishment spend. The data an operator needs to negotiate maintenance contracts and forecast CAPEX, generated automatically from the same records that already protect deposits.
By building
Identify the buildings with the highest cost per turnover.
By unit type
See which layouts and fit-out grades degrade fastest.
By city
Compare refurbishment spend across markets as the portfolio grows.
Every tenancy builds your baseline.
From your first sealed report, VeriProp starts learning what your properties look like. The more tenancies complete, the more precisely it knows what normal is - and what to flag.
From day one
Org room profile
Starts from day one. Built from your units and room types. Understands your buildings.
Compounds over time
Unit spatial profile
Deepens with every tenancy. After three cycles the system knows exactly what normal looks like for each room.
Deviations flagged. Nothing else reaches your queue.
Data security and compliance
GDPR-native data model
Tenant personal data is erasable on request: names and phone numbers are nulled and claims severed, while the anonymised hash chain and condition record are preserved under Art. 17(3)(b).
WORM evidence storage
Evidence is write-once, read-many. Photos cannot be updated or deleted after submission - enforced at the storage layer, not as a policy promise.
Four-level hash chain integrity
File hash, evidence root hash, report integrity hash, acknowledged integrity hash. Each level is verifiable independently; any alteration anywhere breaks the chain.
Retention built for disputes
Sealed records are retained for the tenancy duration plus a minimum of three years, matching limitation periods for deposit claims. No automated deletion; purging requires legal sign-off.
Independent verification for third parties
Coming soonAn opt-in verification page per organisation. Anyone the operator chooses to share a report with - a tribunal, a lawyer, a tenant - pastes the report ID and independently confirms that the hash chain is intact and the record has not been altered since sealing.
The verifier recomputes the hash chain from the stored evidence and compares it against the sealed values.
No account needed and no VeriProp involvement in the check. The mathematics is the authority, not us.
Opt-in per organisation: operators who prioritise data privacy keep it off; operators who want maximum legal defensibility turn it on.
See the ledger on your own portfolio.
We onboard one building, run a full move-out wave, and hand you the condition reports. Then you decide.