Article
What the Certificate Documents
A good cloud evidence collection certificate captures the particulars of the collection so the export can be traced back to its source. In practice that means:
Provider and service — for example Microsoft 365 (Exchange Online, SharePoint or
OneDrive), Google Workspace, or a specific AWS account and region.
Account or tenant — the mailbox, custodian, tenant ID or bucket the data came from.
Collection method and tool — Microsoft Purview eDiscovery export, Google Vault, an admin
console download, or a documented API / native export.
Collection window — the date range or query used, and when the export was run.
Custodian / operator — who performed the collection.
Exported objects and hashes — an itemised list of the downloaded files with their
cryptographic fingerprints.
Does e-Dex connect to Microsoft 365, Google Workspace or AWS to collect the data?
No. e-Dex never touches the cloud service. You run the export yourself using the provider's own tools —
Microsoft Purview eDiscovery, Google Vault, an admin console or an API — and then point e-Dex at the
downloaded files. e-Dex hashes those files and records the collection particulars in the certificate after
the fact. It runs fully offline on your own Windows machine and does not need internet to do its job.
What should a cloud evidence collection certificate contain?
It should identify the cloud provider and service (for example Microsoft 365 Exchange Online or
SharePoint, Google Workspace, or an AWS account), the account or tenant the data came from, the collection
method and tool used, the collection window or date range, the custodian or person who ran the export, and
an itemised list of the exported objects with their cryptographic hashes. The hashes let anyone recompute
and confirm the files have not changed since collection.
What is the difference between a cloud evidence collection certificate and an eDiscovery
collection certificate?
They overlap heavily. An eDiscovery collection certificate documents a structured collection across one or
more sources as part of a discovery process. A cloud evidence collection certificate is the same idea
narrowed to data that lives in a SaaS or cloud platform — it emphasises the provider, the tenant and the
native export method (Purview, Vault, an API). In practice many cloud collections are part of a wider
eDiscovery exercise, and the same hashing and certification approach applies to both.
Can e-Dex sign and timestamp a cloud evidence certificate?
Yes. e-Dex can apply a PAdES digital signature to the certificate using a Digital Signature Certificate
(DSC) on a USB token, binding the deponent's identity to the document so later edits are detectable. It can
also attach an RFC-3161 trusted timestamp from a Time-Stamping Authority, giving independent proof of when
the certificate was produced. Both happen on your own machine.
Conclusion
Cloud and SaaS platforms now hold most of the evidence that matters, and an export is only as credible as the record that accompanies it. A cloud evidence collection certificate — provider, account, method, window and the verified hash of every object — turns a downloaded package into something you can defend. Run the export with your provider's tools, then let e-Dex — the Digital Evidence Integrity Suite hash, certify, sign and timestamp it on your own Windows machine.