The KeyProof record

One hire, one record.
It says what it does not have.

Every hire on KeyProof ends in a single dated record. It opens by listing each check as on record, not on record, or not yet due, with the gaps counted at the top. A thin record cannot pass as a full one, which is what makes a full one worth handing to an insurer.

Record · KP-2026-0417BMW M4 CompetitionDEMO1233-day hire · issued 12:04
Verified by KeyProof
None missing. One not yet due.5 / 6 on record
Identity checkPhoto ID matched to a selfie, by StripeOn record
Driving licenceShare code supplied, checked by you on gov.ukOn record
Signed agreementYour agreement, e-signed, sealed with a hashOn record
Condition at handoverNine timestamped photos when the car went outOn record
Condition at returnDue when the car is back, still out on a 3-day hireNot yet due
Deposit£1,500 held on the hirer’s card, logged to the bookingOn record
No section missing, ready for your insurer

Illustrative record. Not a real hirer.

A form is submitted and closed. This is not.

The same link the hirer opens days before collection is the pass the firm reads at the car, the thread the hire runs on while the car is out, and the record both of them keep afterwards. It has one more state after that, and nobody has to remember it.

Every pack opens by stating its own gaps.

The reader of a hire record is usually a claims handler, a solicitor or an accountant, on paper, months later, with no context. Absence is the hardest thing for that reader to see: a record with no licence check looks, at a glance, exactly like one with a licence check, because a missing section is simply not there. So the record refuses to let that happen. It opens with a register that names every check and stamps each one.

On record

The thing exists and the document shows it, in the detail further down the page.

Not on record

The thing should exist by this point in the hire and does not. A stated gap, named in plain words, not an empty space a reader might skim past.

Not yet due

The thing could not exist yet because the hire has not reached it. Return photos of a car still out on hire are not a gap, and the register does not pretend they are.

One line above the register counts them: how many items are not on record, so a reader who reads nothing else knows how much of the hire has evidence behind it. Every stamp is derived from the booking’s own data, not from a box an operator can tick, so no route through the product produces a record that reads better than the hire actually went.

What one record carries

Six checks, each with its own stamp on the register.

These are the items the register names. Each one lands on the same record, in the same place every time, so a reader learns the layout once and knows it on every hire.

Hirer check-in

Whether the hirer completed the check-in link before the keys moved, and when. Everything else the hirer supplied hangs off this one fact, so it leads the register and is the first thing a reader can check.

Identity check

Photo ID matched to a selfie. Stripe runs the check and holds the document and the selfie as the regulated provider; KeyProof records the pass-or-fail result, not the images. A check carried forward from an earlier hire says so, and never reads as a fresh one.

Driving licence

The hirer supplies a DVLA share code and the last eight of their licence number, and you run the free check on gov.uk. KeyProof never contacts the DVLA about a driver: it records that the check was done and when.

Signed agreement, and what is sealed

Your own hire agreement, e-signed and bound to the booking. Three things are then fingerprinted with SHA-256: the agreement wording at the moment of signing, the hire itself over its own particulars, and every condition photograph individually. Any later change to any of them is detectable, which makes them tamper-evident. It does not make the whole record tamper-proof, and this page does not claim it does.

Checkable without us

Whoever you hand the pack to can verify those fingerprints in their own browser. No account, no login, and no need to contact KeyProof at all: an insurer, a solicitor or a council officer checks the maths themselves. Evidence nobody has to take your word for is worth more than evidence they do.

Condition at handover and return

Timestamped photographs of the car when it went out and again when it came back, each set numbered so a reader can cite one. A notice arriving five weeks later meets one dated record, not a camera roll.

The deposit, and the timeline

The deposit you took, held on your own account, logged against the booking. Alongside it, a server-timestamped timeline of what happened and when, so the sequence is not your word against theirs.

Built to be read by a stranger, months later.

A record is only evidence if someone who was not there can trust it. So the KeyProof record is built for the reader who has no context and cannot ask you a question.

It states its own gaps

A record that hid what it was missing would make every complete record worth less, because none of them could be trusted to be saying everything. So it says so, in the same fixed place, every time.

It is derived, not asserted

Every stamp on the register comes from the booking’s own columns. There is no field an operator can fill in to make a hire read as more complete than it was.

The timestamps are server-recorded

The times on the record are set by the system when each thing happened, not typed in afterwards.

It reads in black and white

The stamps are words, not colours, because a pack is read photocopied at least as often as it is read on a screen.

It can leave the building without a login

One tap mints a read-only link to a single hire: no account for whoever you send it to, and it expires after 30 days. The DVLA share code never appears on it and the hirer’s contact details are withheld, because your insurer’s counterparty is you, not your hirer. Creating the link is stamped on the booking’s own timeline, so sharing is itself part of the chain of custody, and one action revokes every live link on that hire.

It has a stated life, and it does not quietly outlive it

A record is kept for 24 months after the hire ends and then deleted in full. The clock stops on its own while a dispute is flagged or a claim or a fine is still open, so a pack cannot expire out from under a live case. Nothing is held here because deleting it was never got round to.

What the seal says, and what it does not.

When every item on a hire is on record, the pack carries a “Verified by KeyProof” seal. That seal is printed off the register and off nothing an operator can set, so a hire cannot be made to earn it. It says the evidence behind the hire is complete. It does not say who is right about the hire: you decide what counts as new damage and whether to pursue a charge, every time, and KeyProof records what happened without ever scoring it.

And you do not have to take the seal on our word. Every pack prints the fingerprints it was sealed with, and anyone holding a pack can check them against the document, the photos and the hire itself. The maths runs in their own browser, there is no account to create, and the answer comes back as a match or not a match. An insurer, a solicitor or a council officer can verify a KeyProof record without ever contacting KeyProof, which is the only version of this claim worth making.

KeyProof is not an insurer, an authority or a court, and the record makes no claim that any of them has pre-approved it. What it is designed to be is a straight, dated, complete account of one hire that holds up when it is read. How the underlying data is handled sits on our security page.

One record per hire.
It never overstates itself.

Walk a check-in in the demo and watch the register fill in, or see how the record is made across a whole hire.

A founding cohort of five firms
£49/ month

Locked for as long as you stay, any fleet size.

30 days free on every plan. No setup fee, no minimum term, cancel any time.

Get set up by a founderWhatsApp us