Glossary

    Evidence glossary

    Online-harm evidence work has its own vocabulary, and the words matter. A "hash value" is not the same claim as "tamper-evident," and "lawyer-ready" is not the same claim as a formal court-admissibility standard. This glossary defines the terms Finium Legal uses across its evidence workflows, in plain language, so that reviewers, law firms, journalists, and the people affected by online harm can read a Finium evidence file, an article, or a workflow page and know exactly what each term promises and what it does not.

    Every definition here is written to stand on its own: read the bolded sentence and you have the core meaning, without needing the rest of the page. The elaboration below each definition explains why the concept matters for online-harm evidence specifically, and how Finium's own workflow treats it. These are vendor-neutral definitions first; where Finium's practice differs from general use, that is stated separately.

    01

    What is chain of custody?

    Chain of custody is the continuous record of who captured a piece of online evidence, when, how it was stored, who accessed it, and what happened to it afterward. It lets a reviewer verify that a file has not been altered since capture, without relying on memory or assumption.

    Read the full entry
    02

    What is a hash value?

    A hash value is a fixed-length string generated from a file's contents using an algorithm such as SHA-256. If even one bit of the file changes, the hash changes completely, which makes it a reliable way to show a stored capture is bit-for-bit identical to the version recorded at capture time.

    Read the full entry
    03

    What is timestamping?

    Timestamping is the practice of recording exactly when an online item was captured, along with the time source used, separate from any publication time shown on the platform itself. A defensible timestamp answers when something was preserved, not when it was originally posted or how authentic it is.

    Read the full entry
    04

    What does tamper-evident mean?

    Tamper-evident means a record is built so that any change made after capture, however small, would be detectable rather than hidden. It combines a hash recorded at capture, a documented timestamp, and a custody log, so a reviewer can tell whether a file matches what was originally preserved.

    Read the full entry
    05

    What is doxing?

    Doxing is the publication of someone's private information, such as a home address, phone number, workplace, or family details, without their consent and usually to enable harassment or intimidation. Evidence of doxing needs the original post plus the wider spread across mirrors, reposts, and screenshots before it disappears.

    Read the full entry
    06

    What is NCII?

    NCII, non-consensual intimate imagery, refers to sexual or intimate images or video shared without the depicted person's consent, including images that are digitally altered or synthetically generated. Evidence handling for NCII requires strict access controls so the affected person is not forced to keep re-encountering the material.

    Read the full entry
    07

    What is synthetic media?

    Synthetic media is audio, image, or video content that has been generated or manipulated using AI or other automated tools, ranging from lightly edited clips to fully fabricated footage. Evidence work treats synthetic media indicators as signals to record and preserve, not as a verdict on whether content is genuine.

    Read the full entry
    08

    What does "lawyer-ready" mean?

    Lawyer-ready describes an evidence file built to a standard a law firm can review efficiently: source-anchored captures, a labeled chronology, a custody record, and stated uncertainty, with legal characterization left entirely to counsel. It is the highest point on Finium's public evidence-language ladder, short of formal court use.

    Read the full entry