Article
Why a Bare Hash Is Not Enough for Court
A hash written on a sticky note proves nothing on its own — anyone can type any 64 characters. To be useful in a proceeding, the hash needs to live inside the Section 63 / 65B certificate, which records the device, the manner of acquisition, and the person attesting to it. That certificate is far stronger when it is digitally signed, so the signer's identity is bound to the document and any later edit is detectable, and RFC-3161 timestamped, so the moment it was created is sealed against an independent authority. Wrapping the hash in all of that, and keeping a clean chain of custody showing who handled the file and when, is what turns a number into something a court can rely on. The hash is necessary; it is not sufficient.
P26 (Section 63) and the older Indian Evidence Act (Section 65B) require an accompanying certificate, and a documented chain of custody is also expected. The hash is the technical backbone of that certificate, but admissibility is decided by the court on the facts of the matter. This article is general information, not legal advice.
Which hash should I use for court evidence in India?
SHA-256 is the common modern choice because it is collision-resistant and widely recognised. e-Dex also
computes SHA-512 and BLAKE3 for additional strength, and MD5 and SHA-1 for compatibility with older
records. Recording several algorithms side by side makes the integrity proof harder to dispute and lets a
verifier match against whichever value was originally noted.
What does a hash calculator actually prove for court evidence?
A hash calculator proves integrity — that a file is bit-for-bit identical to a previously recorded state.
If a single byte changes, the hash changes completely, so a matching hash is strong evidence that nothing
was touched. It does not prove who collected the file, what device it came from, or that it is relevant;
those questions belong to the chain of custody and to the court.
How does hashing fit into a Section 63 BSA / Section 65B certificate?
The statutory certificate for electronic records captures device, acquisition and deponent details, and it
relies on a hash to fix the exact state of the record. The hash is the verifiable core: it lets anyone
later recompute the value and confirm the record matches what the certificate describes. e-Dex generates
the hash and wraps it in a signed, RFC-3161-timestamped certificate that can be re-verified.
Can a hash and its certificate be verified again later?
Yes. The certificate records the file hashes, so anyone can recompute the hash of the same file months
later and compare it. A certificate produced by e-Dex can also be checked on the online certificate
verifier, which confirms the digital signature and timestamp without needing the original software. This
makes the integrity claim independently testable.
Conclusion
A hash is the quiet workhorse of digital evidence: it turns "trust me, this file is unchanged" into a number anyone can re-check. For court evidence in India, that hash is the technical backbone of the Section 63 BSA 2023 / Section 65B IEA certificate — but it only does its job when it is signed, timestamped and kept inside a clean chain of custody, and admissibility remains for the court to decide. You can do the whole workflow offline, on a single Windows machine, with e-Dex — the free Digital Evidence Integrity Suite. Download it free and start anchoring your files to a value you can prove.
Streamline Your Business with Planex365 ERP
Consolidate your sales pipeline, CRM contacts, inventory, accounts receivable, and billing in a single, secure database designed for Indian SMEs.
Related on e-Dex
Digital Evidence Software · Free Hash Tool · Verify a Certificate · Download e-Dex (free)