An order arrives from a Belgian prosecutor at 9pm on a Tuesday, cites an eight-hour deadline, and lands in a queue built for subpoenas measured in days. From 18 August, that stops being an edge case.
Most of this release is about that date. The rest is a run of work on Targets that decides how much a search is worth before an analyst spends an afternoon on it, plus a change to how agents find their agency when they sign up.
EU e-Evidence
Regulation 2023/1543 requires that service providers can receive, review and respond to European Production Orders and Preservation Orders through a standardised interface from 18 August. The clocks are the part that catches people. An order can carry an eight-hour deadline, and it runs from when the order was issued rather than from when someone on your side noticed it.
How orders reach you before member states connect
Not every member state will have its own system live on the 18th. Where one isn't, authorities can sign in to Kodex directly and submit orders by hand. What lands in your queue is an ordinary Kodex request, with the e-Evidence fields, priority, emergency flag and non-disclosure handling already populated from the order itself.
Deadlines come from the order's priority rather than from whoever happens to open it. An eight-hour emergency order shows an eight-hour clock, and nobody has to work out the date by hand. The timeline carries a system entry summarising the order as it came in, so an analyst picking the case up cold can see what was asked for without opening the PDF.
Saved searches, dashboard filters and exports all read e-Evidence fields now. You can route an emergency order to email, Slack or PagerDuty, and get a second alert two hours before it expires if it's still open. The manual submission guide walks through what an authority sees on their side. This goes live on 18 August, and it's enabled per organization, so if you haven't talked to your CSM about setup yet, this is the week to do it.

The ETSI API, ready for testing
The other path is machine to machine. Our ETSI-compliant API is built and waiting for member states to bring their own systems online. As each one does, orders will arrive over the standard interface and open in your queue with nothing rekeyed by anyone. If you expect volume across several member states, your CSM can get you testing against it now rather than in the week it matters.
Targets
Three changes to how targets get submitted and searched. Admins get two new ways to say what a usable submission looks like before it arrives, and analysts get a view of where a target has already turned up.
Seeing when a target already appears on another request
You open a request and scan its selectors. One of them now carries a count in the Related Requests column, where previously nothing told you that another analyst had already worked the same email address on a different case. Click the count and you get a search view scoped to those matches, using whatever columns you normally work in.
From there you pick. Tick the requests that are genuinely related, add them, and they appear in the sidebar with an entry on the timeline so the next person to open the case can see the connection and who made it. Nothing links itself, which matters when a shared selector is a coincidence rather than a lead. It's enabled for power users today, and your CSM can turn it on for your team.

Deciding what makes a search worth running
A name on its own returns thousands of records, which is not something an analyst can act on. You can now write that judgement into the product instead of catching it after the fact.
Required selector combinations let you say which selectors have to travel together. Wallet address with transaction hash for crypto work, name with date of birth for social. Minimum identity confidence sets the same idea at the organization level: either one unique identifier such as an email address or account ID, or two non-unique ones such as a name and a date of birth.
Neither rule blocks a submission. An agent who is missing something gets told while they are still in the form, and the gap is visible on the request before anyone starts work on it. Your CSM sets both up for your organization.

Choosing between an exact match and a broader one
Target search now separates "is" from "is like". Use "is" when you have the exact value and want only that. Use "is like" when you are working from a partial or slightly wrong selector and want close matches back as well. Previously you got one behaviour and had to infer which. This is on for everyone.

For law enforcement and government requesters
Everything above is for the providers who receive requests. This part is for the agencies sending them.
Finding your agency the first time
Creating a Kodex account used to start with an empty box and your agency's name. Enough people typed a slightly different version of the same department that a single police force could end up spread across a dozen records, none of which matched the one their colleagues were using.
You now pick from the agencies already verified against your email domain, and your address is checked as you enter it. Adding a new agency is still there for the case where yours genuinely isn't listed. It takes a deliberate step now, because that path sends your account for manual review.
The reason to care is how long you wait at the start. Landing in the right agency makes your account eligible for automatic approval, rather than sitting in a queue until someone moves you across and closes the duplicate behind you. There is nothing to switch on, and it applies to everyone signing up now.

In Case You Missed It
July's release brought live date filters and unread-comment filtering to advanced search, let analysts re-group target selectors after submission, added notifications for next action dates, and moved multi-factor authentication into the agent sign-up flow.
Get Your Free Drone Autonomy Guide Today!

Featured Blogs
EU e-Evidence is live today. Here's what actually changed.
.png)




