A screenshot is not evidence. It has no verifiable timestamp, no source link, no context and no proof that it was not edited. When a narrative becomes a matter for legal, a regulator or the board, the public conversation behind it must be preserved in a form that answers three questions: what was said, when was it captured, and has it been changed since. This guide explains how.
Why ordinary captures fail
Public posts are deleted, edited and taken down. Accounts vanish. Videos are re-uploaded with different titles. By the time counsel asks for the record, the original is often gone, and what remains is a folder of screenshots of uncertain origin. Even when the content survives, a screenshot cannot show that it was captured on the date claimed or that it has not been altered. Under scrutiny, that uncertainty is enough to set the evidence aside.
What an evidence pack contains
A proper evidence pack bundles everything the team relied on, preserved as captured. The public posts, with their text, author handle, source link and platform timestamp. Screenshots taken at capture, as a visual record. Transcripts of any public video, in the original language, with the passage that matters marked. The timeline that places each item in sequence. The written reads the team worked from, so that the reasoning is on record alongside the facts.
Hashes and chain of custody
Two mechanisms turn a bundle into evidence. A cryptographic hash of the bundle, recorded at the moment of capture, means that any later change to any item alters the hash and is therefore detectable. A chain-of-custody record lists who created the pack, when, who accessed or exported it and when, so that the bundle's history can be shown. Together they let you say, with confidence, that the record is what it was on the day.
Capture at the moment of reliance
The right time to preserve evidence is when you rely on it: when an alert fires, when a decision is taken, when a response is approved. Preserving at that moment produces a record that shows what was known when the decision was made, which is exactly the question a review will ask. Preserving later produces a reconstruction.
For legal teams
Counsel needs the pack in a form that can be disclosed, cited and, if necessary, produced. Export formats should include the raw items, the hash record, the custody log and a human-readable index. Provenance should be explicit: for each item, where it came from and when it was captured. Avoid any process that edits or annotates the captured items themselves; annotations belong in a separate layer.
For boards and regulators
A board wants the story and the assurance that the story is grounded. Pair the written read with the pack: the read explains what happened and what was decided; the pack shows the evidence behind every claim. A regulator will additionally want the custody log and the approval records for any public statements, so that both the facts and the organisation's conduct are on record.
Responsible limits
An evidence pack preserves the public conversation about a subject. It is not a dossier on a person. Keep packs subject-led, limit them to public sources, and do not aggregate material on private individuals. These limits protect the organisation as much as the public: evidence gathered improperly is evidence you cannot use.
A checklist for the next incident
- Preserve at the moment of reliance, not after the fact.
- Capture text, source link, timestamp, screenshot and, for video, transcript.
- Hash the bundle at capture and record the chain of custody.
- Keep annotations separate from captured items.
- Pair the pack with the written read and the approval records.
- Subject-led, public sources only, no material on private individuals.