URMA

URMA / THE OPEN PROTOCOL

Independent recovery.
Verifiable records.

URMA defines how private objects, atomic public records and generic public multipart objects are written, verified and recovered. Capture, Archive, Wire and Git build distinct workflows on the same protocol. Journalism is our first use case.

  1. Write
  2. Verify
  3. Recover

Private recovery needs your separately kept compartment root and accessible records. V0 is a normative draft with scoped implementation evidence; full conformance is not claimed.

One foundation.
Distinct applications.

Capture serves journalistic originals and context. Archive handles generic private files and collections. Wire publishes public text, identities and replies. Git has an approved public HEAD-only design and a separate implementation scope.

Reusable shared services and interoperable profiles support these applications. Optional Camera hardware runs Capture. Fund the protocol or an individual implementation without duplicating shared work.

Independent funding scopes ↗

01 / URMA CAPTURE — JOURNALISM

What they can take.
What stays yours.

The story doesn’t end with the camera.
Capture is our first journalism application of the URMA protocol.

THE PRESSURE / THE DIFFERENCE

01 / THE DEVICE

The capture device is gone.

A camera or phone is seized, destroyed or lost. Its local copy is no longer available.

WITHOUT AN INDEPENDENT COPY

Camera
Only copy
Lost

The file dies with the device.

When the only copy is on the camera, destroying it destroys the route back to the photograph.

WITH URMA CAPTURE

Published
Your key
Your file

The original stays in reach.

A reader retrieves the completed publication from accessible historical records and opens it with the separately kept key. The original device is not required.

02 / THE PERSON

The reporter is cut off.

The reporter is detained or loses contact. The newsroom or a trusted reader still needs the material.

WITHOUT AN INDEPENDENT COPY

Reporter
Device
Newsroom

The handoff is cut off.

If access depends on the reporter sending the file or unlocking the device, the handoff stops when contact is lost.

WITH URMA CAPTURE

Published
Trusted key
Newsroom

The evidence can still speak.

A trusted reader who already holds the secret can recover completed publications without the reporter’s device or participation.

03 / THE PROVIDER

The platform stops being a way in.

A provider, CDN or platform is compromised, censored, deleted or denies access.

WITHOUT AN INDEPENDENT COPY

File
Provider
Blocked

One provider controls the only route.

If the only accessible copy sits behind that service, deletion or denied access cuts off recovery. A compromised provider may also expose any material it can read.

WITH URMA CAPTURE

History
Your key
Reader

Use an independent source.

A compatible reader retrieves retained encrypted records from another accessible source and opens them with your key, without the original platform or URMA service. Possession of ciphertext alone does not grant access to the media.

TWO BOUNDARIES, MADE EXPLICIT

Preservation starts
before the loss.

PUBLICATION REQUIRED

The bytes have to get out.

If power or connectivity fails before publication finishes and the device is lost, neither route can recreate the missing bytes. Our reader reports an incomplete result instead of claiming a recovered file.

ACCESSIBLE RECORDS REQUIRED

A copy must be reachable.

If no source can supply the required records, recovery waits on access. Independent archives reduce reliance on one provider; they do not make connectivity or retained history unnecessary.

These are Capture private-object design scenarios. Authenticated bytes do not prove a scene was genuine. Conventional independent backups and end-to-end encryption can also protect material. Preservation does not prevent detention or coercion, and content encryption does not hide all publication metadata.

The evidence behind the design ↗

02 / THE REASON WE EXIST

Freedom of the press
needs a longer memory.

A seized camera. A wiped memory card. A newsroom forced offline. Too often, controlling the place a story lives means controlling whether it survives. Read the documented cases, starting with WikiLeaks ↗

Capture preserves journalistic originals and context through Capture Evidence. Archive handles generic files and collections through Private Files. They share one archive engine. Wire serves public text and identities. Git has an approved public HEAD-only design; its application remains to be implemented. Each application has its own contract and funding scope.

Explore the applications

03 / CHOOSE YOUR GROUND

The mission stays.
The network can change.

Preservation is the purpose. Chains are infrastructure.
Choose the redundancy the story calls for.

CAPTURE DIRECTION

Litecoin.

Capture’s initial publication direction. Current Android evidence is on Litecoin Testnet; this is not a protocol-wide default or a mainnet release claim.

PRIMARY PRESERVATION
EXTRA REDUNDANCY

Bitcoin.

An optional additional copy for Capture material, with an explicit publication budget. Wire keeps a separate feed on each configured chain/network.

REINFORCE THE RECORD
THE HORIZON

Beyond.

One protocol, extensible transports. New chains and storage systems can become destinations without becoming the identity of URMA.

OPEN TO WHAT COMES NEXT

Capture direction: Litecoin first, optional Bitcoin copies. This is application policy. Wire has separate feeds per chain; all public V0 records use Taproot. Future transports require their own specification and evidence.

Explore the architecture ↗

LET THE WORK SPEAK

Journalism needs witnesses.
History needs the files.