Web-forensics use case
Acquire web conferencing and meeting-platform evidence
Eviquire can preserve authorized information presented by a browser-accessible meeting platform: meeting identity and schedule, participant presentation, recordings, transcripts, chat, reactions, polls, shared files, attendance information and available exports. It records what the account could access; provider logs, host devices, native recording files and identity records may be required for a complete examination.
What this use case means
Eviquire can preserve authorized information presented by a browser-accessible meeting platform: meeting identity and schedule, participant presentation, recordings, transcripts, chat, reactions, polls, shared files, attendance information and available exports. It records what the account could access; provider logs, host devices, native recording files and identity records may be required for a complete examination.
Meeting evidence is often fragmented across event pages, recordings, transcript and chat panels, calendars, file services and administrator reports. Retention can be short, speakers may be labelled incorrectly, and playing or downloading content can create access events. The acquisition must preserve the meeting and account context without implying that display names prove attendance or identity.
Common situations
When this workflow is useful
- Workplace, compliance, litigation, training, harassment or disclosure matters involving an online meeting
- Preserving recordings, chats or attendance before retention expires
- Documenting what a host, participant or administrator account could retrieve
Recommended process
A documented acquisition workflow
- Define meeting and authority
Identify meeting or webinar, account role, dates, participants, recording, chat, transcript, files and privacy limits.
- Record portal state
Preserve service, tenant, meeting ID, host, scheduled time, timezone, role and navigation.
- Acquire meeting context
Document overview, participant and attendance views, playback, transcript, chat, polls, reactions and file relationships.
- Download available originals
Preserve authorized recordings, transcripts, chat, attendance reports and files in supplied formats.
- Verify and qualify
Hash artifacts, record automated transcript limitations, explain unavailable content, and correlate disputed identity or attendance with provider records.
Technical guidance
Conditions that affect meeting-platform acquisition
Confirm these points during a short pre-acquisition validation on the authorized workstation.
Playback and transcript state
Recordings may be trimmed, replaced, password-protected or streamed; automated transcripts can contain errors.
- Record playback settings and duration.
- Keep transcript and recording distinct.
- Preserve native downloads where available.
Participants and identity
Display names, dial-in labels and attendance reports do not conclusively establish who was present or attentive.
- Capture stable identifiers where lawful.
- Record join and leave semantics.
- Correlate important identity claims.
Privacy and investigator effects
Opening, sharing or downloading can generate access events and meeting material may contain non-parties.
- Use least privilege.
- Minimize unrelated content.
- Document created access events.
Reviewable output
What the evidence package should explain
Meeting context
Service, tenant, meeting ID, host, schedule, timezone, role and navigation.
Observed meeting record
Playback, transcript, chat, polls, participants and acquisition-session video.
Native exports
Recordings, transcripts, attendance reports, chat and files preserved with hashes.
Review package
Limitations, timestamps, activity records and chain of custody.
The exact artifacts depend on the source, plan, configuration, authority, and investigation. A report should identify what was and was not collected.
Professional considerations
Authority, proportionality, and limitations
- Confirm recording, employment, communications and privacy authority before collection.
- Automated transcripts and display names require cautious interpretation.
- Keep platform exports, Eviquire session video and participant-device evidence conceptually separate.
Important: Eviquire supports a documented technical process. It does not establish identity, truth, culpability, infringement, or admissibility, and it does not replace legal advice or a validated organizational procedure.
Standards and primary guidance
Online evidence procedures should be validated for the organization and matter. Useful starting points include SWGDE guidance for acquiring online content, ISO/IEC 27037:2012, and NIST digital-evidence resources.
Frequently asked questions
Can Eviquire download a meeting recording?
When the authorized portal provides a compatible download, preserve it separately with a hash.
Does an attendance report prove identity?
No. It records the platform’s account or connection presentation and may need corroboration.
Can chat and transcripts be captured?
Yes when available to the authorized account.
Is session video the original meeting recording?
No. It documents the acquisition and observed playback.
Can expired recordings be recovered?
Not through the portal if they are no longer exposed; provider or other sources may be required.
Who uses this workflow?
Relevant professional roles
This acquisition workflow is commonly relevant to these teams. The appropriate authority, scope, procedure, and review requirements still depend on the matter.
Forensic experts
Acquire online evidence with technical context, integrity verification, custody records, and reporting.
See role-specific guidance →Law enforcement
Preserve volatile online evidence for authorized criminal and intelligence investigations.
See role-specific guidance →Law firms
Preserve websites and online content for litigation, disclosure, legal holds, and expert review.
See role-specific guidance →In-house legal teams
Preserve early evidence for disputes, compliance, legal holds, and outside-counsel review.
See role-specific guidance →