All resources
    Guide10 min read

    Chain of custody

    Custody event logs for online evidence

    A custody event log is the running record that connects every online-harm capture to who preserved it, when it was handled, where it was stored, what changed, and which export later used it. For law firms and evidence teams, the log turns screenshots, URLs, media files, and review notes into a traceable evidence file instead of a loose folder of material.

    Updated August 2026By Henryk Wexel

    Key takeaways

    • The custody event log is the spine of an online-harm evidence file: it records capture, preservation, review, redaction, transfer, and export events in order.
    • Each event needs a source, timestamp, actor, action, affected file or URL, integrity note, and reason for the action.
    • A log does not make legal conclusions. It lets counsel see what was observed, what changed, and where uncertainty remains.
    • For volatile platform material, account renames, deleted posts, and mirrored content, the event log is often what explains why a later evidence pack still makes sense.
    01

    What this is

    A custody event log is the evidence file's operating diary. It records what happened to each source item after discovery: capture, preservation, hashing, storage, review, redaction, export, and transfer. For online-harm matters, where posts can be edited, deleted, renamed, mirrored, or reported before counsel sees them, the log is what lets a later reviewer understand the path from public URL to structured evidence file.

    Answer summary

    Use a custody event log when online evidence may change. Record the source, capture time, actor, action, file identifier, hash or integrity note, storage location, review status, and export history for every material event. The log supports counsel review; it is not legal advice and does not promise any outcome.

    02

    The capture to export workflow

    1. Capture: preserve the source URL, visible account context, surrounding thread, media, and capture timestamp before the platform or account changes.
    2. Preserve: store the raw capture separately from analysis, annotations, and redacted working copies.
    3. Timestamp: record capture time, time zone, and time source, then add later handling events as they occur.
    4. Structure: assign evidence IDs, link related URLs, group items by incident or account, and separate observed facts from reported context and inferences.
    5. Export: generate a counsel-facing bundle with the custody log, exhibit index, source map, and any redaction notes, while retaining the raw file trail.

    The same workflow applies to public posts, search snippets, profile pages, messages where the firm is authorised to handle them, and platform notice records. The log is deliberately operational rather than legal: it records evidence handling so counsel can make faster and better-grounded decisions.

    03

    Evidence checklist for each custody event

    Minimum fields for a custody event log

    FieldWhy it matters
    Event IDGives every action a stable reference for review and export.
    Timestamp and time sourceShows when the handling event happened and avoids vague chronology.
    Actor or systemIdentifies who captured, reviewed, moved, redacted, or exported the material.
    Action takenSeparates capture, hash, storage, review, redaction, transfer, and export events.
    Source URL or evidence IDConnects the event back to the underlying item or file.
    Integrity noteRecords hash value, file size, storage path, or reason a hash was not available.
    Basis labelMarks whether a statement is observed, reported by the client, or inferred from a pattern.
    Reviewer noteKeeps open questions and legal-review flags separate from the raw evidence.
    04

    How event logs handle volatile platforms

    Online-harm evidence often changes for reasons outside the evidence team's control. A profile is renamed after first contact. A post disappears after a platform report. A mirrored page copies the material with a different timestamp. A search result still shows a cached preview after the destination changed. Each of those changes can weaken an evidence file if the record only contains the final screenshot. A custody event log keeps the sequence visible.

    • Account rename observed: record the prior handle, new handle, URL, capture time, and linked earlier evidence IDs.
    • Post deletion observed: record when the missing source was checked, who checked it, and which earlier capture preserves the prior state.
    • Mirror discovered: preserve the mirror as a new source, not as a replacement for the original.
    • Platform response received: log the notice, response time, response content, and affected source items without treating the response as a legal conclusion.
    05

    Common mistakes

    • Writing a narrative summary but leaving no event-by-event handling record.
    • Recording capture time but not later redaction, review, transfer, or export events.
    • Overwriting raw captures with annotated copies instead of preserving both and linking them.
    • Treating a hash as proof of truth rather than proof that a specific file has not changed since hashing.
    • Mixing client reports and observed platform facts without basis labels.
    • Omitting failed or inconclusive checks. Gaps are safer when they are labelled than when they are hidden.
    06

    How this fits Finium evidence packs

    Finium evidence packs use the custody event log as the link between capture tooling, monitoring notes, reviewer tasks, and counsel-facing exports. The law firm remains the legal actor. Finium structures the evidence file so the firm can inspect sources, uncertainty, and handling history without asking a client or analyst to reconstruct the matter from memory.

    Related operating guides include the chain-of-custody reference, the timestamping workflow, and the SHA-256 hash guide. Commercial and security context lives on the for-law-firms, evidence-standard, security, and contact pages linked below.

    07

    Use and limits

    This guide is an evidence-handling reference, not legal advice. It does not decide admissibility, unlawfulness, platform policy outcomes, or court acceptance. It does not provide emergency response and it does not promise that any platform, court, or reviewer will act in a particular way. The instructed law firm or qualified reviewer remains responsible for legal judgment.

    Frequently asked questions

    What is a custody event log for online evidence?

    It is a chronological record of the handling events around captured online material: who captured it, when, from which source, where it was stored, what hash or integrity check was recorded, when it was reviewed, and which export later used it. The log explains the path of the evidence file without deciding the legal issue.

    Is a custody event log the same as chain of custody?

    No. Chain of custody is the broader discipline of preserving and explaining evidence handling. The custody event log is the practical record that documents the steps inside that discipline for a specific matter or evidence pack.

    What events belong in the log?

    Capture, hash creation, storage movement, redaction, reviewer access, client-supplied context, platform response, account-name change, deletion notice, export generation, and delivery to counsel all belong in the log when they affect the evidence file.

    Does the log need to prove that a post is unlawful?

    No. The log records source and handling facts. It can label whether a fact was observed, reported, or inferred, but legal classification remains for the instructed firm or qualified reviewer.

    How does Finium use custody event logs?

    Finium uses custody logs to structure online-harm material into lawyer-ready evidence files: captures are tied to URLs, timestamps, hashes, reviewer notes, and export history so counsel can inspect the record without reconstructing it from scattered screenshots.

    References

    1. 01Finium evidence standard
    2. 02Chain of custody for online evidence

    FINIUM LEGAL

    Want this structured for a real matter?

    Send one public URL or representative matter and review the kind of source-aware evidence file Finium is built to prepare.