Web-forensics use case
Acquire evidence from e-commerce and merchant portals
Eviquire can document authorized records presented through an e-commerce, marketplace seller, payment-service, or merchant administration portal, including products, orders, customers, payment status, refunds, disputes, shipping, messages, reports, and exports. It does not replace processor, marketplace, database, API, or financial-institution records.
What this use case means
Eviquire can document authorized records presented through an e-commerce, marketplace seller, payment-service, or merchant administration portal, including products, orders, customers, payment status, refunds, disputes, shipping, messages, reports, and exports. It does not replace processor, marketplace, database, API, or financial-institution records.
A transaction is distributed across order, payment, fulfillment, refund, dispute, customer, product, and communication views. Status can change automatically, money and time may be localized, and portal roles hide sensitive fields. The acquisition must preserve identifiers, linked histories, filters, and authorized exports without exposing unnecessary payment or customer data.
Common situations
When this workflow is useful
- Fraud, counterfeit, consumer, chargeback, contract, delivery, tax, or internal investigations
- Preserving seller actions, order history, refund or dispute status, and customer communications
- Documenting a transaction before status, retention, access, or marketplace presentation changes
Recommended process
A documented acquisition workflow
- Define transaction scope
Identify store, account, orders, products, dates, currencies, customers, disputes, communications, and exclusions.
- Document portal role
Record tenant, seller or merchant identity, account permissions, locale, timezone, currency, filters, and network conditions.
- Trace the transaction
Navigate from order to payment, fulfillment, refund, dispute, messages, product, and history while preserving identifiers and state.
- Export securely
Preserve authorized reports and files, minimize payment and personal data, hash originals, and verify the closed case.
Technical guidance
Conditions that affect e-commerce portal acquisition
Confirm these points during a short pre-acquisition validation on the authorized workstation.
Changing transaction state
Payments, fulfillment, refunds, disputes, and fraud checks can update while collection is underway.
- Record acquisition sequence.
- Capture status and time at each relevant view.
- Avoid operational actions.
Sensitive payment and customer data
Portals may display personal data, tokens, partial account numbers, addresses, and risk information.
- Collect only necessary fields.
- Never capture credentials or full payment secrets.
- Use restricted handling and redaction copies.
Exports and corroboration
Merchant reports can be filtered, aggregated, delayed, or generated in different timezones and currencies.
- Record parameters and format.
- Preserve the original export.
- Correlate disputed transactions with processor, marketplace, carrier, or bank records.
Reviewable output
What the evidence package should explain
Portal context
Store, account role, order and product identifiers, filters, locale, and currency.
Transaction history
Payment, fulfillment, refund, dispute, message, and status presentation.
Reports and exports
Authorized transaction files and documents with hashes.
Custody record
Session history, timestamps, limitations, reports, and transfer controls.
The exact artifacts depend on the source, plan, configuration, authority, and investigation. A report should identify what was and was not collected.
Professional considerations
Authority, proportionality, and limitations
- Apply payment-card, financial, consumer, privacy, and contractual requirements.
- Portal acquisition does not prove the identity of a buyer or seller or replace processor and institution records.
- Do not issue refunds, capture payments, contact customers, or alter orders unless expressly authorized.
Important: Eviquire supports a documented technical process. It does not establish identity, truth, culpability, infringement, or admissibility, and it does not replace legal advice or a validated organizational procedure.
Standards and primary guidance
Online evidence procedures should be validated for the organization and matter. Useful starting points include SWGDE guidance for acquiring online content, ISO/IEC 27037:2012, and NIST digital-evidence resources.
Frequently asked questions
Can order and refund history be preserved?
Yes when visible to the authorized portal account.
Can Eviquire acquire payment-card details?
It should collect only authorized and necessary displayed information, never credentials or prohibited payment secrets.
Does a merchant report prove settlement?
Not by itself; corroborate with processor or bank records when required.
Should status changes be documented?
Yes, including the acquisition sequence and displayed times.
Can the marketplace backend be acquired?
No. Eviquire preserves the authorized web presentation and exports.
Who uses this workflow?
Relevant professional roles
This acquisition workflow is commonly relevant to these teams. The appropriate authority, scope, procedure, and review requirements still depend on the matter.
Copyright and trademark professionals
Preserve listings, branding, seller context, media, and related pathways before takedown.
See role-specific guidance →Forensic experts
Acquire online evidence with technical context, integrity verification, custody records, and reporting.
See role-specific guidance →Law firms
Preserve websites and online content for litigation, disclosure, legal holds, and expert review.
See role-specific guidance →In-house legal teams
Preserve early evidence for disputes, compliance, legal holds, and outside-counsel review.
See role-specific guidance →