Investigations

Documenting without exposing the content

Investigative material must hold up in court and stay confidential at the same time. How to get both, and what no tool can do in your place.

Investigative material has two requirements that seem to pull in opposite directions. It must be verifiable by third parties, or it will not hold up. And it must stay confidential, because it concerns people who consented to nothing. Most tools resolve this by sacrificing the second.

The problem with platform deposit

The common way to make content «certified» is to upload it to a service that stores it and attests its date. It works, but it carries a consequence that weighs heavily in investigative work: the content ends up on third-party infrastructure.

Which means: a vendor holding material about identifiable individuals, one more processor in the chain, an additional risk surface in the event of a breach, and the awkward fact that somebody besides you and your client can physically see what you documented.

If making evidence defensible requires handing it to a third party, you have solved one problem by creating another — and the new one concerns people who never authorised you.

Separating what proves from the content

stays on the device the photo, the video, the audio the camera original the voice notes no third party sees it. Us included. only this reaches the server the cryptographic fingerprints the histogram (photo) or waveform (audio) the signed manifest and the timestamp enough to prove, not enough to see A histogram describes the distribution of light: it does not allow the image to be reconstructed.
The guarantees travel; the content does not. Video is not transmitted at all: for photos and audio, only a statistical representation and the fingerprints go up.

There is a way to get both, and it lies in separating what is needed to prove from what needs protecting. To show that a file is intact and predates a given date you do not need to hold the file: its cryptographic fingerprint, the signed manifest and the timestamp are enough.

In the LOCUS model the media stays on the device, inside the sealed package. For photographs, what goes to the server is the histogram — a graph of tonal distribution, from which the image cannot be reconstructed. For audio, the waveform. Video does not go up at all.

The practical consequence is clear: no vendor, us included, is in a position to know what you documented. It is not a confidentiality promise to be honoured — it is a technical impossibility.

What you hand to counsel

The package is self-contained: it holds the media, the metadata, the signed manifest, the timestamps and the tools to verify them. Counsel, or the opposing party's expert, can check it on their own computer, offline, without an account and without going through us.

That is not a convenience detail. It means the verifiability of your work depends neither on our commercial survival nor on our willingness to cooperate, and that nobody logs who verified what and when. The walkthrough is in how the opposing party verifies your evidence.

The regulatory frame, and what the tool does not do

Maximum clarity is needed here, because this is where a tool can be misunderstood most damagingly.

Processing personal data remains subject to Regulation (EU) 2016/679 (GDPR), with its obligations on lawful basis, data minimisation, purpose limitation and storage limitation. Investigative activity is additionally regulated at national level, and the applicable framework differs across Member States.

None of those conditions is satisfied by a cryptographic seal. Evidence that is technically unassailable but gathered unlawfully remains evidence gathered unlawfully: file integrity and lawfulness of collection are distinct questions, and the second is not solved by mathematics.

What the tool does do, and which has genuine value from a data protection standpoint, is reduce the exposure surface: fewer parties involved in the processing, no transfer of content to a vendor, no copy on someone else's infrastructure. That aligns with the minimisation principle, but it is not a lawful basis and does not replace the assessments that fall to you and to the controller.

On audio and filming: caution

Recording conversations and filming people and private premises are subject to strict limits, which vary by context, purpose, whether the recorder is party to the conversation, and the forum where the material will be used. These are legal assessments to be made case by case, with counsel — not questions an application can settle or authorise.

That a tool technically permits an acquisition says nothing about its lawfulness. Worth repeating, because confusing the two is exactly what turns useful documentation into a problem.

Organising the material

An operational point that weighs more than it seems: acquisitions accumulate, and the moment you need them is the moment when working out which belongs to which engagement has become expensive. Filling in the case reference on every acquisition and grouping packages by file as you go — not retrospectively — is the difference between extracting what you need in minutes and reconstructing from memory months later.

Finally, remember that you are the custodian: if the package is lost it cannot be rebuilt, because the content was never anywhere else. Confidentiality has that price, and it is paid with a backup copy.

Continue with the chain of custody and the date of a photo.