Guide24 August 20264 min read808 words

What Is a Timestamp? Its Role in Law 5651 Log Signing

A timestamp proves data existed at a moment and stayed unchanged via an authorized provider; SignLogger signs logs daily with Kamu SM.

#what is a timestamp#e-signature#law 5651 log signing#kamu sm#credits

A timestamp is an electronic record that, through the endorsement of an authorized certification service provider, proves a piece of electronic data existed at a specific moment and has not been altered since. Under Turkey's Law No. 5651, access and transaction logs must carry evidentiary weight, which requires the time of their creation to be reliably documented and their integrity to be demonstrably intact. A timestamp answers exactly this need: it binds a precise date and time to the digest derived from a log.

This content is general information, not legal advice. Rely on current legislation and expert counsel for the scope of your obligations.

How a Timestamp Works

A timestamp is not applied to the entire log but to a digest (hash) mathematically derived from it. The process runs briefly as follows:

  • A one-way digest (hash) is calculated from the log record's content.
  • This digest is sent to an authorized timestamp server.
  • The server appends its own trusted time to the digest and signs the whole with its electronic certificate.
  • The returned timestamp token is stored alongside the log and later serves as proof that the record existed at that moment.

Because the content cannot be reconstructed from the digest, only the digest is stamped — the data itself is never sent to a third party. If even a single character of the content changes, the digest changes entirely and the stamp becomes invalid, making any subsequent tampering visible.

Timestamp vs. Electronic Signature

The two concepts are often confused, yet they answer different questions. An electronic signature answers "who approved this?", while a timestamp answers "when did this exist, and has it changed since?". In Law 5651 log signing, the two are used together for strong evidentiary value.

FeatureTimestampElectronic Signature
What it provesMoment of existence and integrity of the dataIdentity and intent of the signer
Core questionWhen? Has it changed?Who? Did they approve?
Time informationTrusted external clock sourceNo binding time on its own
ProviderAuthorized timestamp serverSigner holding a qualified certificate

The Authorized Provider and the Credit Model

For a timestamp to carry legal validity, it must be obtained from an authorized certification service provider. In Turkey, one such authorized authority is TÜBİTAK Kamu SM. Kamu SM's timestamp service operates on a credit (kontör) basis: each stamping operation consumes one credit. Consequently, a log-signing system needs a sufficient credit balance to keep running continuously.

  • Credits are purchased in advance and consumed with each signing operation.
  • If the balance runs out, no new stamping can occur — so monitoring the balance is critical.
  • Credit consumption varies with signing frequency and the structure of the record batches being stamped.

SignLogger Signs Logs Every Day

SignLogger signs the access and transaction logs it retains every day with a timestamp and e-signature through an authorized certification service provider (TÜBİTAK Kamu SM). Each day's records are therefore stored with a reliable date and with their integrity proven. Because the stamp would be invalid had the records been altered afterward, signed logs carry strong evidentiary value in audits and legal requests.

SignLogger is brand-independent; it works with any RADIUS-capable firewall and is positioned to run on the organization's own infrastructure (VMware/Hyper-V), so your data stays on-premises and never leaves your organization. You can find the details of daily-signing obligations on our Law 5651 log signing solution page.

Frequently Asked Questions

Is a timestamp sufficient on its own?

A timestamp proves when data existed and that it has not changed, but it does not establish the signer's identity. For strong evidentiary value it is usually combined with an electronic signature; SignLogger applies both together.

How often should logs be signed?

Records are expected to have their integrity documented regularly. SignLogger signs logs every day, protecting each day's records with a reliable date. For exact duration obligations, consult current legislation.

What happens when Kamu SM credits run out?

When the credit balance is depleted, no new timestamp can be obtained. Monitoring and renewing the balance in time is therefore important; otherwise the daily signing process may be interrupted.

Does timestamping send the log content to a third party?

No. Stamping is performed on a digest (hash) derived from the log. Since the content cannot be recovered from the digest, the data itself is not shared; with SignLogger the logs remain on the organization's own infrastructure.

What happens if a signed log is altered later?

Even the smallest change in the content completely alters the digest and invalidates the existing timestamp. This makes any subsequent tampering apparent during verification.

Which provider should issue the timestamp?

For legal validity, the stamp must be obtained from an authorized certification service provider. SignLogger signs through an authorized authority such as TÜBİTAK Kamu SM.

Last updated: 25 August 2026

See SignLogger Law 5651 compliance for yourself

Request a free demo