Legislation

What is a timestamp, and why does it matter for log records?

"Logs without a timestamp are invalid" is a statement you hear often, but it's not how the legislation is actually written. This guide explains the official definition of a timestamp, its real place within 5651, and izgate's integrity chain, in the correct framing.

A timestamp is a record that independently proves, through an authorized electronic certificate service provider, that a piece of electronic data existed at a particular moment and was not altered after that moment. Law No. 5651 and its related Regulation do not make this term mandatory for general public use providers; for commercial-purpose providers, they instead require that a value confirming the accuracy, integrity and confidentiality of the records be recorded daily. A timestamp is an independent tool that strengthens that value and increases its evidentiary weight.

Short answer

The legislation does not say, for any public use provider, that "obtaining a timestamp is mandatory." What is required of commercial-purpose providers is that a value confirming the integrity of the records be recorded daily; a timestamp is a reliable, independent way of doing this, but it is not the only tool named in the legislation. For a non-commercial hotel, cafe or office, this provision does not apply directly; but voluntarily adopting the same technical approach makes it easier to demonstrate the reliability of a record when a request arrives.

Official definition (Law 5070, Art. 3/h)

Law No. 5070, the Electronic Signature Law, defines a timestamp as follows:

"Zaman damgası: Bir elektronik verinin, üretildiği, değiştirildiği, gönderildiği, alındığı ve / veya kaydedildiği zamanın tespit edilmesi amacıyla, elektronik sertifika hizmet sağlayıcısı tarafından elektronik imzayla doğrulanan kaydı,"

"Timestamp: A record verified with an electronic signature by an electronic certificate service provider, for the purpose of determining the time at which an electronic data item was produced, altered, sent, received and/or recorded,"

Electronic Signature Law No. 5070, Art. 3/h — unofficial translation — mevzuat.gov.tr

The key phrase in this definition is "by an electronic certificate service provider": a timestamp comes not from your own server's clock, but from an independent, authorized third party (for example, Kamu SM). This independence is the source of a timestamp's evidentiary value — you yourself could alter a date field kept on your own system, but you cannot retroactively change a stamp issued by an independent institution. Even if your server's system clock is set incorrectly, the timestamp provider's own clock and signature provide an independent reference point, which serves as a neutral referee in a dispute between two parties.

Relationship with 5651: the integrity value

The Regulation requires the following from commercial-purpose internet public use providers:

"(d) bendi gereğince kaydedilen bilgileri ve bu bilgilerin doğruluğunu, bütünlüğünü ve gizliliğini teyit eden değeri kendi sistemlerine günlük olarak kaydetmek ve bu verileri iki yıl süre ile saklamak,"

"To record daily, in their own systems, the information recorded pursuant to clause (d) and the value confirming the accuracy, integrity and confidentiality of that information, and to retain that data for a period of two years,"

Regulation on Internet Public Use Providers, Art. 5/1-e — unofficial translation — mevzuat.gov.tr

The provision does not use the word "timestamp"; it says a "value confirming the accuracy, integrity and confidentiality" of the records. Technically, this value can be built from a hash (digest), that hash protected with a digital signature, and optionally supported by an independent timestamp. This provision binds only the commercial-purpose category (internet cafes and similar venues); but a hotel, cafe or office that is not in the commercial-purpose category can also voluntarily apply the same integrity approach, strengthening the evidentiary value of its own records.

How a timestamp strengthens evidentiary value

A plain-text log file can easily be corrupted — lines added, removed or altered — by anyone with disk access, and proving that such a change was made afterward is difficult. Three elements together reduce this risk:

  • Integrity (hash chain)Each record's digest also carries the previous record's digest; if even a single line is deleted or altered in between, the chain breaks, and this is detected immediately.
  • Authentication (digital signature)The record is signed with a key unique to your installation; a forged file produced without that signature will not pass verification.
  • Proof of time (timestamp)An independent timestamp service confirms, independently of your organization, the moment the record existed — showing the signature was not applied after the fact.

The correct framing is this: a timestamp obtained from an authorized electronic certificate service provider strengthens the evidentiary value of a record; statements such as "logs without a timestamp are invalid" or "it's a legal requirement for everyone" are not consistent with the legislation. When any one of these three elements is missing, the integrity claim weakens: without a signature, a hash chain alone cannot say "this is the chain I produced"; without a timestamp, a signature cannot independently answer the question "when was this signature applied."

izgate's integrity pipeline

In izgate, archive records are protected hourly with a SHA-256 hash chain and an Ed25519 digital signature. In addition, a qualified timestamp is obtained once a day from Kamu SM, and an automatic integrity check runs every night; if any corruption is detected in the chain, a critical alert is generated.

In this pipeline, each segment is chained to the one before it; altering a segment retroactively would require re-signing the entire chain — which, combined with independent timestamps, is practically impossible. The live database used for search and this signed archive are kept at the same time but on separate disks; your search speed does not come at the expense of integrity guarantees.

Verification and export

From the panel, the integrity of any segment, or of the whole chain, can be verified with a single click: the hash chain, the signature and the timestamp are checked together, and the result is reported either as "chain intact" or showing exactly where the problem is. When a request arrives, the relevant period can be exported as a signed package containing a README, catalog, segment files, manifest and timestamp token. This package is prepared so that the other party can independently verify it with their own tools as well — it doesn't just say "we verified it," it carries the verification itself.

Archive verification and signed export screen in the izgate panel
Archive page: verify, download, export signed, and restore back to live.

Common misstatements

  • "Logs without a timestamp are invalid." The legislation contains no such provision; a timestamp strengthens evidentiary value, it is not a condition of validity.
  • "A timestamp is a legal requirement for all public use providers." The legislation does not use this term for general public use providers; what is required of commercial-purpose providers is an "integrity value."
  • "Any date field counts as a timestamp." It does not; under Law No. 5070, a timestamp is issued by an independent electronic certificate service provider.

Frequently asked questions

Is obtaining a timestamp mandatory?

No, the legislation does not make this term mandatory for general public use providers. For commercial-purpose providers, a value confirming the integrity of the records must be recorded daily; a timestamp is a tool that strengthens that value.

Where does izgate get its timestamp from?

izgate obtains a qualified timestamp from Kamu SM once a day; in addition, records are protected hourly with a SHA-256 hash chain and an Ed25519 signature.

Are records I keep without a timestamp invalid?

No. Your records are valid; a timestamp is additional evidence that strengthens their evidentiary value — its presence or absence does not eliminate the legal existence of the record.

What happens if integrity is broken?

izgate runs an automatic integrity check every night; if any corruption is detected in the chain, a critical alert is generated and the affected segment is shown in the panel.

This page is for information only; for the current text of the legislation, refer to the official source (mevzuat.gov.tr).

Strengthen your records with a hash chain, a signature, and a timestamp.

The izgate archive is signed hourly, supported once a day by a qualified timestamp, and verified automatically every night.