Article
Offline, Signed and Time-Stamped
e-Dex generates the certificate fully offline on your own Windows machine, so your evidence files never leave your computer. Where you need extra assurance, you can apply a PAdES digital signature with a Digital Signature Certificate (DSC) on a USB token, binding the signer's identity to the document so any later edit is detectable, and attach an RFC-3161 trusted timestamp that seals the exact time the certificate was produced against an independent Time-Stamping Authority. Only the timestamp step needs the internet; everything else runs locally.
P26 (formerly Section 65B of the Indian Evidence Act). It is supporting documentation that demonstrates a file is unaltered through cryptographic hashes and a MATCH / MISMATCH verdict. It strengthens the integrity story behind the evidence, but how it is tendered and weighed is for the court to decide on the facts of the matter. e-Dex helps you produce the document; it does not guarantee admissibility.
What is the difference between an evidence integrity certificate and a Section 63 BSA certificate?
The evidence integrity certificate is the everyday attestation that a set of files is unaltered. It
records multi-algorithm hashes per file and an overall verification result. The Section 63 BSA / Section
65B IEA certificate is the formal, court-prescribed certificate for electronic records, set out in the
Schedule to the BSA in Part A and Part B form, and it captures device, acquisition and deponent details in
addition to integrity values. The integrity certificate is the simpler foundation; the Section 63
certificate is the full statutory form.
Does e-Dex need an internet connection to verify file integrity?
No. e-Dex runs fully offline on your own Windows machine. Hashing files, comparing them against recorded
values and generating the evidence integrity certificate all happen locally, so your evidence files never
leave your computer. An internet connection is only needed if you choose to apply an RFC-3161 trusted
timestamp from a Time-Stamping Authority.
Which hash algorithms does the evidence integrity certificate use?
e-Dex computes multiple algorithms per file, including MD5, SHA-1, SHA-256, SHA-512 and BLAKE3. Listing
several algorithms side by side makes the integrity proof stronger and lets a verifier match against
whichever value was originally recorded. SHA-256, SHA-512 and BLAKE3 are the modern, collision-resistant
choices, while MD5 and SHA-1 are included for compatibility with older records.
What does MATCH or MISMATCH mean on the certificate?
When you verify a file, e-Dex recomputes its hash and compares it against the expected or recorded value.
If every byte is identical the result is MATCH, meaning the file is unchanged since it was recorded. If
even a single byte differs the result is MISMATCH, meaning the file has been altered or corrupted. The
certificate also shows an overall verification result across all files so the outcome is visible at a
glance.
Conclusion
The evidence integrity certificate turns a vague assurance into a one-page, verifiable fact: these files are unaltered, proven by multiple hashes and a plain MATCH / MISMATCH verdict. It is the simplest and most reusable document in the digital-evidence toolkit, and the foundation the heavier certificates build on. You can produce one in minutes, offline, on a single Windows machine with e-Dex — the Digital Evidence Integrity Suite. Download it free and start proving your files are exactly what they should be.