Web-forensics use case

Acquire evidence from cloud storage and document portals

Eviquire can preserve evidence displayed through an authorized cloud storage or document portal: folder paths, document previews, ownership and sharing information, comments, visible versions and activity, native downloads, and acquisition records. It does not replace provider API collection, cloud-native export, synchronized endpoint acquisition, or backend audit evidence.

What this use case means

Eviquire can preserve evidence displayed through an authorized cloud storage or document portal: folder paths, document previews, ownership and sharing information, comments, visible versions and activity, native downloads, and acquisition records. It does not replace provider API collection, cloud-native export, synchronized endpoint acquisition, or backend audit evidence.

A document preview may not be the native file, folder paths can be virtual, links can resolve to external tenants, and version, sharing, comment, and activity panels load independently. A sound acquisition connects the displayed item to its portal location, owner, permissions, version, associated activity, and downloaded original where available.

Common situations

When this workflow is useful

  • Litigation, disclosure, due diligence, fraud, IP, or internal review of authorized cloud documents
  • Preserving version, ownership, sharing, comment, or activity information presented by a portal
  • Documenting a file before permissions, links, versions, retention, or content change

Recommended process

A documented acquisition workflow

  1. Define the source set

    Identify tenant, account, folders, documents, versions, date range, permissions, and exclusions.

  2. Preserve navigation and identity

    Record the portal URL, account role, folder path, document identifier, owner, sharing state, and how the item was located.

  3. Capture portal context

    Acquire previews, metadata panels, versions, comments, activity, link settings, and warnings after ensuring relevant dynamic panels are loaded.

  4. Download and verify

    Preserve authorized native files and generated exports, hash originals, label converted copies, record unavailable items, and close the case for controlled review.

Technical guidance

Conditions that affect cloud-document acquisition

Confirm these points during a short pre-acquisition validation on the authorized workstation.

Preview versus native file

Browser previews may render, convert, paginate, or omit content and are not necessarily identical to the stored file.

  • Preserve both portal presentation and native download where possible.
  • Record preview limitations and conversion warnings.
  • Hash the untouched native download before analysis.

Versions and permissions

Version histories, ownership, link access, inherited permissions, and activity depend on account role and portal policy.

  • Record the authorized role and effective sharing state.
  • Identify the selected version explicitly.
  • Do not claim inaccessible history is absent.

Linked and collaborative content

Comments, embedded files, linked documents, online-native formats, and external-tenant links may be separate sources or require generated exports.

  • Document export format and options.
  • Acquire external items only under separate authority.
  • Preserve relationships among files, comments, and links.

Reviewable output

What the evidence package should explain

Portal location

Tenant, folder path, document identity, owner, permissions, and navigation.

Document context

Preview, metadata, comments, versions, activity, and sharing presentation.

Native files

Authorized originals and generated exports with format details and cryptographic hashes.

Custody package

Session activity, timestamps, reports, limitations, and transfer records.

The exact artifacts depend on the source, plan, configuration, authority, and investigation. A report should identify what was and was not collected.

Professional considerations

Authority, proportionality, and limitations

  • Cloud repositories often contain broad confidential and personal datasets; use narrow scope and access controls.
  • Portal acquisition does not prove that a preview equals the backend object or replace provider audit and API evidence.
  • Preserve original files unchanged and perform conversion, redaction, and annotation on controlled derivatives.

Important: Eviquire supports a documented technical process. It does not establish identity, truth, culpability, infringement, or admissibility, and it does not replace legal advice or a validated organizational procedure.

Standards and primary guidance

Online evidence procedures should be validated for the organization and matter. Useful starting points include SWGDE guidance for acquiring online content, ISO/IEC 27037:2012, and NIST digital-evidence resources.

Frequently asked questions

Is a browser preview the original document?

Not necessarily. Preserve the native download or authorized export separately when available.

Can version history be captured?

Yes when the authorized portal exposes it, but completeness depends on permissions and retention.

Does Eviquire acquire an entire cloud account?

No. It acquires selected content presented through the authorized web interface.

How should online-native documents be preserved?

Record the portal context and export them in authorized available formats, documenting the format and options.

Are sharing links proof of access?

They document the displayed sharing configuration; actual historical access may require provider audit records.

Privacy preferences

Essential storage remembers this preference and is always active. Optional third-party services are disabled unless you allow them.