Web-forensics use case

Acquire web conferencing and meeting-platform evidence

Eviquire can preserve authorized information presented by a browser-accessible meeting platform: meeting identity and schedule, participant presentation, recordings, transcripts, chat, reactions, polls, shared files, attendance information and available exports. It records what the account could access; provider logs, host devices, native recording files and identity records may be required for a complete examination.

What this use case means

Eviquire can preserve authorized information presented by a browser-accessible meeting platform: meeting identity and schedule, participant presentation, recordings, transcripts, chat, reactions, polls, shared files, attendance information and available exports. It records what the account could access; provider logs, host devices, native recording files and identity records may be required for a complete examination.

Meeting evidence is often fragmented across event pages, recordings, transcript and chat panels, calendars, file services and administrator reports. Retention can be short, speakers may be labelled incorrectly, and playing or downloading content can create access events. The acquisition must preserve the meeting and account context without implying that display names prove attendance or identity.

Common situations

When this workflow is useful

  • Workplace, compliance, litigation, training, harassment or disclosure matters involving an online meeting
  • Preserving recordings, chats or attendance before retention expires
  • Documenting what a host, participant or administrator account could retrieve

Recommended process

A documented acquisition workflow

  1. Define meeting and authority

    Identify meeting or webinar, account role, dates, participants, recording, chat, transcript, files and privacy limits.

  2. Record portal state

    Preserve service, tenant, meeting ID, host, scheduled time, timezone, role and navigation.

  3. Acquire meeting context

    Document overview, participant and attendance views, playback, transcript, chat, polls, reactions and file relationships.

  4. Download available originals

    Preserve authorized recordings, transcripts, chat, attendance reports and files in supplied formats.

  5. Verify and qualify

    Hash artifacts, record automated transcript limitations, explain unavailable content, and correlate disputed identity or attendance with provider records.

Technical guidance

Conditions that affect meeting-platform acquisition

Confirm these points during a short pre-acquisition validation on the authorized workstation.

Playback and transcript state

Recordings may be trimmed, replaced, password-protected or streamed; automated transcripts can contain errors.

  • Record playback settings and duration.
  • Keep transcript and recording distinct.
  • Preserve native downloads where available.

Participants and identity

Display names, dial-in labels and attendance reports do not conclusively establish who was present or attentive.

  • Capture stable identifiers where lawful.
  • Record join and leave semantics.
  • Correlate important identity claims.

Privacy and investigator effects

Opening, sharing or downloading can generate access events and meeting material may contain non-parties.

  • Use least privilege.
  • Minimize unrelated content.
  • Document created access events.

Reviewable output

What the evidence package should explain

Meeting context

Service, tenant, meeting ID, host, schedule, timezone, role and navigation.

Observed meeting record

Playback, transcript, chat, polls, participants and acquisition-session video.

Native exports

Recordings, transcripts, attendance reports, chat and files preserved with hashes.

Review package

Limitations, timestamps, activity records and chain of custody.

The exact artifacts depend on the source, plan, configuration, authority, and investigation. A report should identify what was and was not collected.

Professional considerations

Authority, proportionality, and limitations

  • Confirm recording, employment, communications and privacy authority before collection.
  • Automated transcripts and display names require cautious interpretation.
  • Keep platform exports, Eviquire session video and participant-device evidence conceptually separate.

Important: Eviquire supports a documented technical process. It does not establish identity, truth, culpability, infringement, or admissibility, and it does not replace legal advice or a validated organizational procedure.

Standards and primary guidance

Online evidence procedures should be validated for the organization and matter. Useful starting points include SWGDE guidance for acquiring online content, ISO/IEC 27037:2012, and NIST digital-evidence resources.

Frequently asked questions

Can Eviquire download a meeting recording?

When the authorized portal provides a compatible download, preserve it separately with a hash.

Does an attendance report prove identity?

No. It records the platform’s account or connection presentation and may need corroboration.

Can chat and transcripts be captured?

Yes when available to the authorized account.

Is session video the original meeting recording?

No. It documents the acquisition and observed playback.

Can expired recordings be recovered?

Not through the portal if they are no longer exposed; provider or other sources may be required.

Privacy preferences

Essential storage remembers this preference and is always active. Optional third-party services are disabled unless you allow them.