Web-forensics use case
Preserve website evidence for litigation
Website evidence preservation is the documented acquisition of relevant online content and its technical context before the material changes or disappears. For litigation, the objective is to create a reviewable record that can be authenticated and explained—not merely a screenshot of what was visible.
What this use case means
Website evidence preservation is the documented acquisition of relevant online content and its technical context before the material changes or disappears. For litigation, the objective is to create a reviewable record that can be authenticated and explained—not merely a screenshot of what was visible.
Web pages are volatile. Text, product listings, terms, disclosures, comments, and entire sites can be edited without notice. A browser printout may show the visible content but omit the source URL, acquisition environment, underlying material, integrity records, and examiner activity needed to assess provenance later.
Common situations
When this workflow is useful
- Documenting representations, notices, offers, or contractual terms published online
- Preserving defamatory, fraudulent, or infringing content before removal
- Supporting discovery, disclosure, expert review, or an internal legal hold
Recommended process
A documented acquisition workflow
- Define scope and authority
Record the legal or organizational purpose, target URLs, relevant date range, authorized accounts, and collection boundaries before acquisition.
- Prepare the environment
Document the software version, device or virtual environment, time source, network route, and settings that could influence the capture.
- Acquire content and context
Preserve the relevant pages, screenshots, source material, downloads, media, session activity, and technical context appropriate to the issue.
- Verify integrity
Generate cryptographic hashes and reliable time records, then confirm that the evidence package can be checked after collection.
- Review and report
Keep the original package unchanged, work from copies when appropriate, maintain custody records, and describe the method and limitations in the report.
Reviewable output
What the evidence package should explain
Visible record
Screenshots, long-page captures, and session recording can document what an examiner observed.
Source context
URLs, page source or web archives, downloads, and relevant metadata help connect the record to its online source.
Integrity record
Hashes, timestamps, and audit logs help reveal later alteration and document the acquisition sequence.
Review material
A structured case file and forensic report help counsel, experts, and decision-makers understand the collection.
The exact artifacts depend on the source, plan, configuration, authority, and investigation. A report should identify what was and was not collected.
Professional considerations
Authority, proportionality, and limitations
- No software can determine admissibility; evidence is assessed under the facts and rules of the relevant jurisdiction.
- Collect only what is relevant and authorized, especially when pages contain personal, privileged, or confidential information.
- Document inaccessible, missing, dynamic, or failed content rather than implying that a capture is complete when it is not.
Important: Eviquire supports a documented technical process. It does not establish identity, truth, culpability, infringement, or admissibility, and it does not replace legal advice or a validated organizational procedure.
Standards and primary guidance
Online evidence procedures should be validated for the organization and matter. Useful starting points include SWGDE guidance for acquiring online content, ISO/IEC 27037:2012, and NIST digital-evidence resources.
Frequently asked questions
Is a screenshot sufficient evidence for court?
A screenshot may be useful, but it usually does not preserve enough source context or process documentation on its own. Its weight depends on authentication, relevance, applicable rules, and the surrounding evidence.
Does a timestamp prove that website content is true?
A timestamp supports when a particular digital record existed or was processed; it does not prove that the statements on the page were accurate or identify who authored them.
Should the original evidence package be edited?
The original should be preserved according to organizational procedure. Review, redaction, and production should normally use controlled copies while keeping integrity and custody records.
Can Eviquire guarantee court admissibility?
No. Eviquire supports documented acquisition and integrity verification, but admissibility is determined by the relevant court or decision-maker.