Five macOS apps and a CLI tool for media integrity and project preparation — create, copy, verify, and prove it.
Stable: CopyTrust and Drop Verify 2.5.3, mhl-tool 2.7.7. Beta: CopyTrust 2.8.2 Build 23 — CopyTrust can be made larger. Over 60% of the app's labels were drawn at 10 points, the smallest size Apple documents for macOS, and there was no way to ask for more. CopyTrust can now be shown at 1x, 1.25x, 1.5x or 2x from a control in the window header, from View ▸ Interface Size, or with ⌘+ and ⌘−. Text, controls, spacing and the window itself all grow together, so the same content stays on screen and simply becomes easier to read. The choice is remembered per Mac and is never carried in a preset. Nothing in the copy, verification, naming, receipt or P5 paths changed. CopyTrust only — Drop Verify and Folder Copy Compare stay at 2.8.1 build 21. Test notes: TEST_NOTES_v2.8.2.md.
Also in beta: CopyTrust, Drop Verify and Folder Copy Compare 2.8.1 Build 21 — knowing
whether a volume is really there, and never refusing to copy because one is not. macOS leaves the
mount-point folder under /Volumes behind after an unclean unmount, and every availability check
read that folder as the drive; nothing is created there now. A volume is found by the folder it
mounts at as well as the name it reports, at any depth below /Volumes, so a filespace mounted
two levels down resolves instead of being called missing. And one absent destination no longer
stops a run: it is dropped and named, every other destination still receives the footage, and
Start stays available.
Earlier in the line: a facility can lock a preset in, pinned by name so the convention itself can still be redeployed as often as testing needs (CopyTrust_ManagedPresetDeployment.md); a delivery gets one receipts folder holding everything; nothing is written at the root of a destination drive; and a preset can say which destination archives to P5, which makes proxies, and which P5 server to use. See RELEASE_2.7.8.md and TEST_NOTES_v2.7.8.md.
2.8 is a beta. Test it on media you can afford to lose, and keep a separate, verified backup made by something else — Archiware P5 or equivalent. This is free software from GitHub and it comes with no guarantees.
Development preview: Project Folder Creator 0.4.2 Build 21 — not released, and not to be used on work that matters. See its section below.
CopyTrust, Drop Verify and Folder Copy Compare share a version and build from one project. MHL Verify 2.6.0.
What each app does is below. What changed in each version is in RELEASE_NOTES.md.
Multi-source, multi-destination copy tool designed for camera card ingest but capable of copying any folders and files. Queue multiple cards, walk away, come back to verified results.
Copying
- One Copy switch, one Start button — with two or more destinations choose
Simultaneously(every destination at once) orIn series(an orderedA -> B -> Crelay chain), then pressStart - Several cards in one run — cards copy one at a time with auto-advance and per-card subfolder naming; every card in the run is listed with its own progress and status
- Queued sessions for walk-away staging across different card and destination setups
- Relay chains show
Stop 1,Stop 2in order; a queued leg can be pulled back into the workspace withEditto reorder it - Resumable ingest for cancelled or partial runs, when the saved manifest still matches the same source, destinations, and rendered subfolder
- Pre-copy review of the whole job — direct, fan-out, relay, or active-plus-queued — with one card per destination showing its verification, sorting, proxy and P5 choices
- Per-destination preflight (free space, write permissions, reachability), and a safe-to-eject flow after transfer
Verification and evidence
- Verification levels: Quick existence and size, Full post-copy xxHash64, or Inline hashing during the copy
- MHL v1.1 hash lists for Full and Inline — compatible with OffShoot, Silverstack, ShotPut Pro, YoYotta
- MHL import verification — drop any
.mhlto re-verify destination files; reads classic MHL v1.x and ASC MHL v2.0 - Session receipts (JSON + TXT), per-ingest logs, optional export to a separate folder, and relay-chain summaries at session close
- Relay chains write an immutable, password-free workflow plan with ordered step and dependency IDs, exported beside every leg's receipts
- The operator is recorded in every session manifest, defaulting to the macOS account
- Verify panel: Deep Compare Files, Compare Browser, Copy Missing, Retry MHL Export
Setup
- Volume browser and Volume Pool for fast source and destination setup
- Destination sets for one-click restore of saved destination groups
- Presets — save every Card and Folder setting under one name and load it back in one action; read-only shared presets deploy to a whole facility via
/Users/Shared/CopyTrust/Presets - Built-in Help with
Quick Start,Advanced Start, andSeveral Cards at Once
After the copy
- Contact sheet PDF (row or grid) and EXIF metadata CSV, generated as independent background artifacts — ExifTool for richer metadata, ffmpeg for MXF and MPEG-2 family thumbnails, REDline for R3D. Quick mode never invents hashes or an MHL
- HTML directory tree —
Project summary index,One HTML per top-level folder, orEntire project, all generated natively - Proxy media — optional H.264 High or HEVC Main 10 MOV at 12.5%, 25%, or 50%, with an optional
Final Cut Proxy Media/YYYY-MM-DDlayout and exact-basename relinking. Display rotation and the source's own colour characteristics carry into the encode, and each run writes JSON/TXT/LOG evidence. Real encode tests cover MOV and MXF; broader formats depend on the packaged ffmpeg decoder - Archiware P5 archive (testing) — after Full or Inline verification, submit a verified destination to a P5 server with searchable xxHash64, frame size and other bounded media metadata.
Archive to P5andCreate proxiesare chosen per destination, and P5 preflight evaluates a whole relay chain - Deferred P5 handoff — a password-free request JSON preserves paths, hashes, metadata, target hints and job state when P5 is offline or automatic archive is off
Docs: Why and How (PDF) — the short case for it, a page per topic, First Run (PDF) — one page, fan-out to every destination, Operator Field Guide (short — features + 2-minute field test), User Guide (full), Workflow Guide (relay strategy), Illustrated Workflow Guide (PDF), P5 Restore & Verify, Workflow QA Matrix, and Quick Start.
The illustrated guide images are stored in
assets/copytrust_workflows/, so they render
directly on GitHub as well as in a local checkout.
- MHL output hashes every included regular file, including camera XML sidecars, databases, support files and thumbnail folders; contact-sheet, metadata CSV and proxy processing remains media-focused
- Active Camera Card exclusions trigger a mandatory pre-run confirmation naming patterns that can omit files or complete folders from the MHL
Single-folder drag-and-drop verification. Drop a folder and generate trust artifacts — no copy, no session, no setup.
- Media-focused recursive scan with configurable exclusion patterns when media artifacts are selected
- Generates selected outputs only: MHL, contact sheet PDF (row or grid), EXIF metadata CSV, and optional native HTML directory tree/index
- MHL output is what triggers hashing and session manifest creation; CSV/contact-sheet-only modes can run without hashes, and HTML-tree-only mode skips media analysis entirely
- Proxy media — edit-friendly HEVC/H.264 copies with per-clip progress and their own evidence, using the same codecs, sizes and Final Cut layout as CopyTrust. Only verified files get a proxy, and proxies stay beside the media rather than going to the export folder
- Writes artifacts into the folder and/or mirrors them to an export folder
- For package roots such as
.fcpbundle, writes itsReceiptsfolder beside the package; ordinary folders retain their existing internal receipt layout. Since 2.7.7 that folder is shared with CopyTrust rather than a separateDrop Verify_Receipts - Built-in Help > Drop Verify Help with setup guides for external codecs, HTML tree, and output options
Standalone MHL reader and verifier. Load any .mhl file, review it, and verify whether the media files still match.
- Side-by-side compare —
Side AandSide Bare picked separately, so the two MHL files can live on different volumes; each side shows its volume, file count and total size before you compare - A verdict on every comparison — match, timing-differs-only, different-layout, or differs. A Destination Sorted copy is paired with its pre-sort source by name, size and hash and reported as
Moved - Verify — re-hashes every file listed in the MHL and reports matched / mismatched / missing with digests
- Reads classic MHL v1.x and ASC MHL v2.0 (Silverstack 9+ default, incl.
ascmhl/folder layouts) - Re-check copies, archive restores, and handoff deliveries
- Works with MHLs from Drop Verify, CopyTrust, OffShoot, Silverstack, YoYotta, ShotPut Pro, or any MHL-capable tool
- Requires macOS 14+ as of 2.5.1 (2.4.1 remains for macOS 13, but cannot read ASC MHL v2.0)
See MHL_VERIFY_README.md, MHL_VERIFY_USER_GUIDE.md, and MHL_VERIFY_CHANGELOG.md.
The original tool that started the suite — a simple "did the copy work?" sanity check. Drop two folders and get an honest answer.
Use after copying with CopyTrust, Archiware P5 Sync, a Finder copy, rsync, Hedge, ShotPut Pro, or any other tool.
- Compare mode — Quick Scan (name, size, date) or Full Scan (xxHash64 / SHA-256 content hashing); per-file comparison: missing, extra, different, identical; Copy All Missing to sync differences, then Refresh to re-verify; MHL v1.1 generation and verification (reads MHL v1.x and ASC MHL v2.0 as of v2.5.1) from either compared folder
- Subfolder Check mode — fast structural sanity check: aligns immediate subfolders side-by-side with file counts, total sizes, and Archiware P5 stub file detection (
.p5a/.p5c); colour-coded match indicators (exact / close / different / one-side-only); click any matched row to drill down using the active Quick / Full Scan setting - Date Only quick-scan status plus per-file Hash Check for same-size, different-date pairs without forcing a full rescan
- Folder selections persist across a mode switch, and cancelling a scan is non-destructive
- Standalone app — no ingest session, no receipts, no artifacts
Creates one numbered project from a reusable main folder template, across Edit, Archive, Cloud or
custom storage — the step before the first card is copied. Each destination gets its own copy
rules from the same template: Edit may receive the whole thing while Archive receives only
1n {project} and its descendants.
Not a release. This is a development build, published so the workflow can be read and discussed. It has not been through acceptance on real facility storage. Do not use it on work that matters.
- One template, a different projection on each storage — a per-destination tree of what that storage receives, showing what every folder, file and package name becomes
- Project tokens —
{project},{project_name}and{project_full}render into the project folder and into any selected folder or.fcpbundlename; a template already using a facility's ownyear-xxxshorthand needs no renaming to be used - Per-destination layout —
Projects/2026directly, orProjectswith a year folder, set per destination or taken from the layouts CopyTrust already enforces - The projects already on that storage, with the next free number offered, and an existing number refused before anything is written
- A read-only plan — every final path, every folder the run will create, free-space warnings, and a refusal by name for anything it will not do
- Staged, verified, then committed — each destination is copied to a hidden staging folder beside its final path, every planned path is verified, the staged tree is checked for anything the plan did not ask for, and only then committed by a same-volume rename. Nothing is ever overwritten or merged
- Storage that is not really mounted is refused — the same mount-table rule as 2.8.1, and here a mistake is a whole project structure written to the boot disk
- Receipts, always — JSON and text, written to this Mac on every run with nothing to configure, and to a chosen folder as well when one is set
- Profiles — the whole set-up under a name, template included, exported as one folder and imported on another Mac that then needs nothing else. Destinations can be taken from a CopyTrust preset rather than typed a second time
- Retry Incomplete — replans only the destinations that failed and reverifies those already committed, and the new receipt still answers for the complete requested set
Not complete: CopyTrust handoff, per-destination live progress, cancellation during one large copy, and acceptance on real Edit, Archive and Cloud storage.
Start with the Quick Start (PDF) — one page from an empty window to a created project. The User Guide (PDF) is the full document.
Command-line tool for creating MHL v1.1 manifests and verifying both classic MHL v1.x and ASC MHL v2.0 manifests (v2.7.7). Same MHL engine as CopyTrust and Drop Verify, built for the terminal.
mhl-tool create <folder>— hash files and write an MHL manifest into that folder, beside the files it describes, where every reader resolves its paths from (--outputto put it elsewhere)mhl-tool verify <folder>— verify files against MHL(s); finds the manifest in the folder, and still in aReceipts,*_Receiptsorascmhlsubfolder, so manifests from earlier versions keep verifying- Media-only (default) or
--all-filesmode - JSON output for scripting, quiet mode for CI
- Reads MHLs from any tool (OffShoot, Silverstack, ShotPut Pro, YoYotta), including ASC MHL v2.0 hashlists — the Silverstack 9+ default
- Signed, notarized
.pkginstaller for distribution
⌘K— Compare Folders⌘R— Refresh Comparison⌘⇧N— Reset both folders
- Drop Verify: README, User Guide, Troubleshooting, and Drop Verify / MHL Verify Workflow
- Folder Copy Compare: README and User Guide
- Project Folder Creator: Quick Start (PDF) and User Guide (PDF)
- Testing and operations: CopyTrust 2.6 Beta Test Notes and CopyTrust Sentry Observability
- Background: What Is MHL and Why Use It?
- Release history: Media Trust Tools Release Notes and MHL Verify Changelog