Skip to main content

Evidence Integrity and Chain of Custody

Show that evidence is authentic enough for its purpose and record every collection, transfer, access, transformation, analysis, and disposition.

Trustworthy enough for the decision

Evidence integrity is confidence that a record is complete and unaltered enough for its stated use. Chain of custody records who collected, possessed, accessed, transferred, transformed, analyzed, stored, and disposed of an item, when, where, why, and how.

The required rigor depends on whether evidence supports rapid containment, internal review, insurance, employment action, or formal proceedings.

Collection record

Assign an evidence identifier. Record source, system owner, collector, authorization, date and time, clock source, location, state, method, tool and version, commands, errors, size, and cryptographic digest where meaningful. Capture surrounding context and configuration needed to interpret the item.

Write-protect or snapshot when possible. Preserve the original and analyze a verified working copy. Protect encryption keys and access logs separately.

Custody and transformation

Record every handoff and access. Use authenticated storage, least privilege, retention, backup, and tamper-evident logging. Document decompression, conversion, parsing, filtering, time normalization, redaction, and derived outputs so another analyst can reproduce the result.

Hashing shows that two byte sequences match. It does not prove the source was truthful or collection complete.

Failure and residual risk

Cloud exports can be regenerated rather than frozen. Live response changes system state. Automated pipelines can transform records before collection. Clocks can be wrong. Administrators and attackers can alter source logs. Encryption can protect confidentiality while key loss destroys evidence availability.

Perfect custody cannot repair a missing source or unsupported interpretation.

Pomerium boundary

Pomerium can emit logs, but operators own collection transport, storage, access, retention, integrity, time, export, and custody. Preserve relevant Pomerium configuration, policy version, deployment state, and upstream evidence with the log records needed to interpret a decision.

Evaluation checklist

  • What decision will the evidence support, and what integrity and custody rigor does it require?
  • Are source, authorization, collector, time, tool, method, errors, digest, context, and original state recorded?
  • Can every access, transfer, transformation, redaction, analysis, and disposal be reproduced?
  • Does the integrity mechanism protect authenticity and completeness, not only byte equality after collection?
  • Which missing source, mutable provider export, clock error, or source compromise limits the conclusion?

Sources and further reading

Keep learning

Cryptography and Data Protection

Digital Signature

Bind a defined message to a private signing key and verify it through an authenticated public key, purpose, and context.

Learn this term

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo