Chain of Custody
From the Camera Card to Your Case File
Documented, hash-verified, and timestamped
Video evidence is increasingly challenged on authenticity. When opposing counsel asks where a recording has been, who handled it, and whether it has changed, you should have a documented answer. Our process creates that record for every deposition we capture, starting the day it is recorded.
Our Process, Step by Step
- Capture. The deposition is recorded to camera memory cards with isolated, multi-channel audio.
- Same-day forensic imaging. The same day, each master card is imaged to the E01 forensic format under forensic write-protection, so the card is read without being altered. Each image records both MD5 and SHA-256 hash values, and the imaging logs are locked against modification.
- Protected storage. The E01 image is stored in an append-only vault on a mirrored storage array, with an encrypted offsite copy. Every transfer is verified against the original hash values.
- Hashed deliverables. The MP4 files you receive are produced from the preserved master, and each one is SHA-256 hashed.
- Signed, timestamped report. All hash values are compiled into the hash report, which is digitally signed and then anchored with OpenTimestamps. The signature identifies who issued the report; the timestamp provides independent proof of when it existed.
- Encrypted delivery. No physical media changes hands on site. Files are delivered by encrypted cloud transfer.
What You Receive
- A signed hash report with every job. A digitally signed PDF listing the MD5 and SHA-256 values of each E01 image and every file it contains and the SHA-256 value of each delivered MP4, delivered with its OpenTimestamps proof file.
- E01 copy, on request. A complete forensic image of the master recording is available as an add-on.
- Certification, on request. A written certification describing the imaging and verification process, prepared by the person who performed it.
Supporting Authentication
Under Federal Rule of Evidence 902(14), data copied from an electronic device or storage medium can be self-authenticating when it is verified by a process of digital identification, such as hash values, and supported by a certification from a qualified person. Our process is designed to support self-authentication procedures like this one; counsel remains responsible for the rule's notice requirements. In any court, the hash report gives you a documented, independently verifiable record of the recording's integrity. Admissibility is always decided by the court.
Retention and Verification
E01 masters are retained for seven years. To request a copy of a master, a certification, or verification of a delivered file, email calendar@akamailegalvideo.com with the case name and deposition date.
In Plain English
- E01 image: A widely used forensic file format that stores an exact copy of a memory card together with its hash values and acquisition notes.
- Hash value: A digital fingerprint calculated from a file's contents. Change a single bit and the fingerprint changes completely, so matching hash values show a file is identical to the original.
- MD5 and SHA-256: Two different hash algorithms. Recording both lets the image be checked with either one.
- Digital signature: Identifies who issued the report and shows whether it has changed since it was signed. PDF readers such as Adobe Acrobat can check it.
- Timestamp: OpenTimestamps records the report's fingerprint in the Bitcoin blockchain, a public ledger no single party controls. It shows the report existed at that time without relying on our word.
- Checking a file yourself: Tools built into Windows and macOS can calculate a file's SHA-256 value. If it matches the hash report, the file is unchanged.