Article

P26 (the successor to Section 65B of the Indian Evidence Act). A well-structured collection certificate strengthens the defensibility of that record by showing the court what was collected, from whom, by what method, and that it is unaltered. e-Dex helps you produce that documentation, but admissibility is decided by the court on the facts.

Does e-Dex need an internet connection to create a collection certificate?
No. e-Dex runs fully offline on your own Windows machine. Hashing the collected items and generating the certificate happen locally, so nothing leaves your computer. An internet connection is only used if you choose to attach an RFC-3161 trusted timestamp, which contacts a Time-Stamping Authority for an independent record of when the certificate was produced.

What is the difference between an e-discovery collection certificate and a chain-of-custody log?
A chain-of-custody log tracks who handled the evidence and when, from collection through to court. A collection certificate is a point-in-time statement about the collection event itself: the matter reference, the custodian, the scope and date range, the source system, the search terms or filters used, and the hashes of the items collected. The two are complementary, and the integrity hashes recorded in the certificate are what tie the documented collection to the items actually held.

What details should a defensible e-discovery collection certificate contain?
A defensible collection certificate should identify the matter or case reference, the custodian whose data was collected, the collection scope and date range, the source (mailbox, file share or endpoint), and the exact search terms or filters applied. It should then list the collected items with their cryptographic hash values, and ideally a signature and timestamp so the document itself is tamper-evident.

Can a collection certificate prove the collected data was not altered?
It can demonstrate integrity through cryptographic hashing. e-Dex computes a fixed-length hash (such as SHA-256) for every collected item. If the same item is hashed later and the values match, it is bit-for-bit identical to what was collected; if a single byte changed, the hash changes completely. Recording these hashes in the certificate gives you a verifiable basis to show the data has not been altered since collection.

Conclusion

A defensible e-discovery collection comes down to showing what you collected, from whom, by what method, and that it is unaltered. A collection certificate that captures the matter, custodian, scope, source and search terms — and pins each item to a verifiable hash — turns that into a reviewable record rather than a recollection. That is exactly what e-Dex — the Digital Evidence Integrity Suite is built to help you do, from item hash to signed, timestamped certificate, on a single Windows machine. Download e-Dex and put a defensible record behind your next litigation hold.

Try ERP Demo