A cryptographic hash can help show that a digital file has not changed. It cannot tell you why the item was collected, who had it, which device it came from, whether an output was the original acquisition or a later conversion, or why a copy was transferred.
Those questions live in the handoffs.
Treat custody as events
A useful custody record is chronological. Each event identifies:
- the case and item;
- the person or controlled system responsible;
- the date and time;
- the action and purpose;
- the from/to location or recipient;
- relevant condition, seal or verification details;
- acknowledgement or approval where required.
“Stored securely” is a policy statement. It is not an event record.
Link physical and digital identities
The physical phone, source storage, native export, acquisition package, working copy and report are different items. They should not collapse into one vague label such as “phone dump.”
Use stable identifiers and associate each derived item with its source. Record tool and version, filenames, size and hashes where applicable. If a package is unpacked, converted or filtered, preserve the source package and document the transformation.
Access is part of custody
Modern evidence work may involve a laboratory, outside examiner, counsel, reviewer, hosting provider or OEM support team. Possession is only one dimension. The case record should also show who could access the material, why, and through which environment.
This matters especially when sensitive personal, privileged or cross-border data is present.
Close the record
Custody does not stop at the report. The engagement should define return, retention, legal hold and deletion. If copies remain with multiple parties, responsibility and end dates should be known.
The strongest chain of custody is not the longest form. It is the shortest complete record that lets a reviewer reconstruct every material handoff.
See the evidence-handling notes and Zeno’s intended examination sequence.