RoseLab
Back to BlogDocument integrity October 1, 2026 7 min read

Digital evidence and chain of custody — how to use a hash to preserve screenshots, PDFs and files

A screenshot alone proves little. Learn what chain of custody means for digital evidence, how the SHA-256 hash fits into it, what it proves (and what it does not), and a step-by-step method to preserve screenshots, PDFs, audio and documents as evidence.

Equipe RoseLab Verificado

Chat screenshots, PDFs, voice messages, photos and spreadsheets show up in almost every dispute today. And almost every lawyer has heard the other side's objection: "that screenshot could have been edited". The technical answer to that objection has a name — chain of custody — and its most basic tool is the hash.

This guide explains, without legalese or tech jargon, how a hash helps preserve digital evidence, what it can prove, what it cannot, and how to keep a simple, consistent record of your files.

This article is for information only and is not legal advice for a specific case.

The problem: a digital file has no "original"

A paper contract has a physical original, with signatures, visible erasures and marks of age. A digital file does not: every copy is identical to the previous one, and a careful edit leaves no visible trace. That is why a screenshot on its own is weak — just by looking, nobody can tell whether it shows what was on the screen or what someone wanted to show.

The question the judge, the expert and the other side always ask is the same: how do we know this file is the same one that was collected back then?

What chain of custody means

Chain of custody is the chronological record of everything that happened to a piece of evidence from the moment it was found: who collected it, when, how, where it was kept, who had access and what was done with it. Courts in most countries expect it, especially in criminal cases, and the international reference standard for handling digital evidence is ISO/IEC 27037 (identification, collection, acquisition and preservation of digital evidence).

The logic applies to any digital evidence, in any area of law: the more complete and verifiable the record, the less room there is for claims of tampering. In the United States, for example, the Federal Rules of Evidence (Rule 902(14)) expressly allow data copied from a device or file to be authenticated by a certified "process of digital identification" — in practice, a hash.

Where the hash fits in

The SHA-256 hash is a file's "fingerprint": any change, however small, produces a completely different hash. In the chain of custody, it works as a digital seal:

  1. At the moment of collection, the file's hash is calculated and recorded;
  2. At any later point — during the expert review, at the hearing, years later — the hash is calculated again;
  3. If the values match, the file is bit for bit the same as the one collected.

That is exactly what forensic examiners do when they copy a seized phone or drive: they hash the original and the copy and record both in their report. For the concept in detail, see what a SHA-256 hash is.

What a hash proves — and what it does NOT

This is the point that causes the most confusion, and it is worth being honest about it.

A hash proves: that the file has not changed since the moment the hash was calculated and recorded.

A hash does not prove:

  • that the screenshot was not edited before the hash was calculated. If someone faked the image and then hashed it, the hash will "guarantee" the fake;
  • who created the file;
  • when the file was created — the operating system's date can be changed;
  • that the content is true — only that it is the same.

In other words: a hash is only as strong as the moment and the way it was recorded. A hash calculated at the time of collection, by a third party, with a reliable date, is worth far more than one calculated by the interested party months later.

"How can I check whether a screenshot was edited?"

This is one of the most searched questions, and the honest answer is: by looking at the image alone, no online tool can guarantee it. Clues such as misaligned edges, mismatched fonts or inconsistent shadows may raise suspicion, but they prove nothing — and a careful edit leaves none of those traces.

The safe approach is the reverse: instead of trying to prove afterwards that the screenshot was not edited, preserve the evidence in a way that makes editing implausible:

  • capture the conversation or page at the source (the device itself, the original link), not just the cropped image;
  • prefer the original file to a screenshot (the chat export, the PDF downloaded from the system, the original audio file);
  • calculate and record the hash at the time of collection;
  • when the evidence is decisive, use a neutral third party with a documented method: a notary or bailiff where that service exists, a forensic examiner, or a web-capture service that records metadata, hash and a trusted timestamp.

Step by step: preserving digital evidence with a hash

For everyday files in a law firm or business — contracts received, receipts, PDFs from systems, audio — a simple procedure already makes the evidence much stronger:

  1. Keep the original file, as received. Do not open and save over it, do not convert it, do not "enhance" the image;
  2. Calculate the SHA-256 hash — for example by dropping the file into the integrity checker, which calculates it in your browser without sending the file anywhere;
  3. Record it in a separate document: file name, hash, date and time, who collected it, where it came from (email from X, system Y, device Z);
  4. Fix the date by an independent means — emailing the record to yourself and to the client already creates an external trace; for sensitive matters, a trusted timestamp from a qualified timestamping authority gives the date legal weight;
  5. Store the original in a controlled place, ideally with a second copy — and every copy must have the same hash;
  6. When filing, state the hash in the brief or in an annex, so anyone can recalculate and check it.

Sample record (simple template)

Field Example
File chat_export_2026-09-14.pdf
SHA-256 0dcc72df…33dec714 (all 64 characters)
Collected on 14 Sep 2026, 10:32
Collected by Name of the person responsible
Source Export made on the client's phone, in the presence of …
Storage Case folder + copy on external media (same hash)

This record, signed and dated, is the seed of a certificate of integrity — a document stating the hash of each file delivered.

How to cite a hash in a brief or report

A clear format that is easy to check:

The file "signed_contract.pdf", filed as Exhibit 3, has the SHA-256 hash 0dcc72df86128c750bd88c5347d66a064f1c9137ff3a2ac0221c4feb33dec714, calculated on 14 September 2026, which can be verified with any SHA-256 calculation tool.

Always state the algorithm (SHA-256), the full value (64 characters) and the date of the calculation.

Watch out: what breaks the chain of custody without you noticing

  • Opening and saving the file (the program rewrites metadata and the hash changes);
  • Sending a photo as a photo on WhatsApp (the app recompresses it; send it as a document);
  • Converting the format (Word to PDF, HEIC to JPG) and discarding the original;
  • Merging, compressing or splitting a PDF that has already been digitally signed — the new file does not carry a valid signature. Always keep the original intact and work on copies.

Frequently asked questions

Is a screenshot with a hash valid evidence? The hash strengthens the evidence by showing that the file has not changed since it was recorded, but it does not prove the screenshot was not edited before. The weight of the evidence depends on the whole picture: source, collection method, timing of the hash, witnesses, a notary's record or an expert report.

What is the point of recording the SHA-256 of evidence in a report? To let anyone, at any time, confirm that the evidence analysed is exactly the same as the evidence collected. Without the recorded hash, that check is impossible.

Does moving the file to another folder harm the evidence? No, as long as the content does not change — the hash stays the same. See more questions like this in file hashes: 12 common questions.

Are a hash and a timestamp the same thing? No. The hash proves the file did not change; the timestamp proves when that hash already existed. Together, they prove that this exact file existed on that date. The difference is explained in our guide to document encryption.

Is it safe to calculate the hash of confidential evidence online? It depends on the tool. In RoseLab's checker, the calculation happens in your browser and the file is never sent to a server — so the evidence does not travel through third parties.

Featured

Ready to put it into practice?

Free, no sign-up — and your files never leave your computer.

Generate the SHA-256 hash of a piece of evidence — free