Web-forensics use case
Acquire electronic voting, survey and consultation portal evidence
Eviquire can document an authorized electronic voting, survey or consultation web interface: event and form identity, version, questions, permitted pre-submission selections, confirmation or receipt presentation, published results and authorized administrative views. It does not validate tallying algorithms, ballot secrecy, voter eligibility, backend databases or election infrastructure.
What this use case means
Eviquire can document an authorized electronic voting, survey or consultation web interface: event and form identity, version, questions, permitted pre-submission selections, confirmation or receipt presentation, published results and authorized administrative views. It does not validate tallying algorithms, ballot secrecy, voter eligibility, backend databases or election infrastructure.
Opening or submitting a ballot or survey can consume credentials, reveal secret choices or irreversibly alter state. Questions may be randomized, conditional or updated, while results change as responses arrive. The acquisition must prioritize secrecy, authority and non-interference and clearly distinguish a participant journey from administrative and published-result evidence.
Common situations
When this workflow is useful
- Disputes about question wording, accessibility, availability, confirmation or published results
- Preserving a consultation or survey before it closes or changes
- Documenting authorized administrative configuration without exposing respondent identities
Recommended process
A documented acquisition workflow
- Define authority and non-interference
Identify event, role, form, permitted actions, secrecy constraints, test credentials and prohibited submissions.
- Record form context
Preserve organizer, title, version, eligibility or access presentation, period, locale and timezone.
- Acquire the permitted journey
Document instructions, questions, conditional paths and confirmation using an approved test or review mode rather than a live secret ballot where possible.
- Preserve authorized results
Download published or administrative reports only when permitted, protecting respondent data.
- State technical limits
Hash artifacts and refer tally, eligibility, logs and infrastructure questions to appropriate system and election evidence.
Technical guidance
Conditions that affect voting and survey evidence
Confirm these points during a short pre-acquisition validation on the authorized workstation.
Secrecy and irreversible state
A live submission can reveal a choice, consume a token or create a legally significant vote.
- Prefer test or preview mode.
- Never record secret choices without authority.
- Do not submit merely to demonstrate the interface.
Conditional and changing forms
Questions can depend on earlier answers, randomization, role, region or form version.
- Record the path and version.
- Document inaccessible branches.
- Preserve changes as separate acquisitions.
Results and respondent data
Live totals may be provisional and administrative exports may identify participants.
- Record result status and time.
- Minimize respondent data.
- Seek authoritative certified results separately.
Reviewable output
What the evidence package should explain
Event context
Organizer, form or ballot, version, role, access conditions, period and timezone.
Interface record
Instructions, questions, permitted path, confirmation and session video.
Results and reports
Authorized published or administrative exports preserved with hashes.
Review package
Non-interference record, limitations, timestamps and custody history.
The exact artifacts depend on the source, plan, configuration, authority, and investigation. A report should identify what was and was not collected.
Professional considerations
Authority, proportionality, and limitations
- Ballot secrecy, electoral law, respondent consent and research ethics take priority over completeness.
- Do not use real credentials or submit real choices simply to capture a workflow.
- Portal acquisition cannot validate the backend count or security architecture.
Important: Eviquire supports a documented technical process. It does not establish identity, truth, culpability, infringement, or admissibility, and it does not replace legal advice or a validated organizational procedure.
Standards and primary guidance
Online evidence procedures should be validated for the organization and matter. Useful starting points include SWGDE guidance for acquiring online content, ISO/IEC 27037:2012, and NIST digital-evidence resources.
Frequently asked questions
Can Eviquire prove an election result?
No. It can preserve interface and published records; authoritative tally evidence requires other methods.
Should a live ballot be recorded?
Generally use an authorized test or preview; secret choices require exceptional authority and safeguards.
Can question versions be documented?
Yes, with event, path and time context.
Can administrative reports be acquired?
Only with authorization and respondent-data controls.
Does a confirmation prove inclusion in the tally?
Not by itself; backend and official records may be required.
Who uses this workflow?
Relevant professional roles
This acquisition workflow is commonly relevant to these teams. The appropriate authority, scope, procedure, and review requirements still depend on the matter.
Forensic experts
Acquire online evidence with technical context, integrity verification, custody records, and reporting.
See role-specific guidance →Law enforcement
Preserve volatile online evidence for authorized criminal and intelligence investigations.
See role-specific guidance →Law firms
Preserve websites and online content for litigation, disclosure, legal holds, and expert review.
See role-specific guidance →In-house legal teams
Preserve early evidence for disputes, compliance, legal holds, and outside-counsel review.
See role-specific guidance →