00000000:00 d0 50 33 6a 6a 7f 79 17 a0 53 6c cc bd cf 77..P3jj.y..Sl...w00000010:ff c7 6b b7 af 2c 94 da 92 aa d2 12 5d 60 77 b1..k..,......]`w.00000020:8b ba c5 8a f1 cb a4 73 9a 29 95 3b 10 78 5d 30.......s.).;.x]000000030:04 50 de ac bd 31 bd 13 3f c0 b2 28 75 de 60 18.P...1..?..(u.`.00000040:cc 85 b2 9c 47 a9 43 50 e9 d7 c7 c4 b1 76 5e db....G.CP.....v^.00000050:a4 bd 27 0b..'.
Every packet had a witness.
↑ You scanned this card
This card contains real encrypted data.
The hex dump on the front is a genuine AES-256-GCM ciphertext. Tap decrypt and it is recovered live, on your device.
GCM authentication tag verified
Decrypted Plaintext
Decrypted
✓ AES-256-GCM decryption successful
✓ GCM authentication tag valid (16 bytes)
✓ Decrypted in-browser · no server, no key sent
Inside the evidence bundle
How Trawler packages this payload into an independently verifiable evidence bundle. The capture context below is illustrative; the ciphertext, key and decryption above are real.
AES-256-GCM application data · 84 bytes# The exact bytes printed on the front of your card
00 d0 50 33 6a 6a 7f 79 17 a0 53 6c cc bd cf 77ff c7 6b b7 af 2c 94 da 92 aa d2 12 5d 60 77 b18b ba c5 8a f1 cb a4 73 9a 29 95 3b 10 78 5d 3004 50 de ac bd 31 bd 13 3f c0 b2 28 75 de 60 18cc 85 b2 9c 47 a9 43 50 e9 d7 c7 c4 b1 76 5e dba4 bd 27 0b
# 68 bytes ciphertext + 16 bytes GCM authentication tag
03Retained Session Key
key material# The TLS session key for this connection, retained at the moment of capture.# Not broken, not intercepted. Preserved. The Unwitting Witness™.