Sooner or later, most disputes touch the web: what a shop promised, what an article claimed, what the terms said, what a competitor advertised. And in every one of those disputes, the same practical question decides more than any legal argument — can you prove what the page actually said, at the moment that matters?
This guide is the complete answer. It explains why web content behaves unlike any other evidence, compares the four ways people try to preserve it, walks through how forensic capture works under EU law, and gives you the practical checklist — including the cases where a single capture is not enough.
Why website evidence is different
Paper doesn't rewrite itself overnight. A web page does — silently, without version history you can access, and often precisely because a dispute has started. Content is edited, posts are deleted, whole domains vanish, and the party who controlled the content controls what remains of it. Web evidence has an expiry date, and you never know when it is.
The second problem is the opposite one: web content is trivially fabricated. Anyone can open a browser's developer tools, rewrite a page's text in two minutes, and screenshot the result — pixel-perfect, indistinguishable from real. Courts know this. Which is why every serious assessment of web evidence comes down to three questions:
The three questions every court asks
- 1.Authenticity — is this really what was published at that address?
- 2.Integrity — has it been altered since it was captured?
- 3.Provenance — who captured it, how, and exactly when?
Four ways to preserve a web page — compared
In practice, four methods appear in disputes again and again. They are not equal.
1. The plain screenshot
Free and instant — and evidentially the weakest option. No cryptographic hash, no trusted timestamp, no source data; nothing distinguishes it from a fabrication made in two minutes. Screenshots still get admitted where nothing better exists, but they are increasingly challenged, and the challenge is increasingly successful.
2. Public web archives
The Wayback Machine and national archives are invaluable when you need the past and preserved nothing yourself. But crawls are irregular (your date may be missing), coverage is patchy, snapshots can be excluded retroactively, and none carry a qualified timestamp. An archive is a library, not an evidence system.
3. Notarial records
The traditional route: a notary observes the page and records what they saw. Legally recognized — but slow, expensive, limited to what appeared on screen at that moment, and preserving no source data. Scheduling a notary rarely matches the speed at which web content disappears.
4. Forensic capture with a qualified timestamp
The method built for the problem: the page is captured with documented methodology, every asset is hashed, and the whole structure is sealed with a qualified electronic timestamp under eIDAS — creating evidence with a legal presumption of integrity, available in seconds, verifiable by anyone.
Deeper dives: Wayback Machine as court evidence · why screenshots are not enough
How forensic web capture works
A forensic capture collects more than a picture: the full-page screenshot, the complete HTML, the network traffic (HAR), and metadata about how and when the capture ran — following a documented, repeatable methodology aligned with ISO/IEC 27037, the international standard for digital evidence acquisition. The answer to "how was this obtained?" is a process description, not an improvisation.
Every collected asset receives a SHA-256 hash recorded in a manifest and linked into an append-only chain; from that point, changing a single byte anywhere is mathematically detectable. The hash structure is then sealed by a qualified electronic timestamp from an EU-accredited trust service provider — which activates a legal presumption of the date's accuracy and the data's integrity, recognized in all 27 member states. Verification requires no trust in the provider: the open-source gpa-verify tool validates everything offline.
The full legal framework — Articles 41 and 42 of eIDAS, what "qualified" means, and why the presumption shifts the burden of proof — is covered in our guide to web evidence under eIDAS.
What to capture: the practical checklist
When the moment comes, capture more than feels necessary — storage is cheap and hindsight is expensive.
- ✓The page itself, full length — not a cropped screenshot. Context above and below the key passage matters when authenticity is questioned.
- ✓The exact URL and visible timestamps — dates on the page, "last updated" notices, post timestamps.
- ✓The identity context: the site's imprint or about page, the seller information, the author's profile. Identities change or vanish once trouble starts.
- ✓Source data, not just pixels: HTML and network traffic carry information a screenshot cannot — and make fabrication claims much harder to sustain.
- ✓Related pages in the same session: terms and conditions, pricing, contact page. Disputes have a habit of expanding beyond the page you started with.
Public pages vs. content behind a login
Publicly accessible pages can be captured server-side: a neutral capture infrastructure requests the page exactly as any visitor would, which keeps the operator's device out of the chain of custody entirely. This is the strongest setup for public content — fast, repeatable, and free of "what else was on your computer" questions.
Content visible only when logged in — private groups, restricted posts, member areas — is invisible to any server. It must be captured from within your own authenticated browser session, with the forensic pipeline applied to what your session actually sees. That is exactly what the browser extension capture is built for.
One capture proves a moment. A series proves a story.
A single capture answers what a page said at one instant. But many disputes are about change over time: when did the claim appear, what did the terms say before, when was the article quietly edited? For those questions, a single snapshot — however well sealed — is structurally insufficient.
The answer is a scheduled series: the page captured automatically every day or week, each run a complete sealed proof, building the before-and-after record that turns "we believe it changed" into a dated, verifiable timeline. See how scheduled website monitoring works.
Capture your first evidence in under a minute
Enter a URL, get a complete Evidence ZIP with an eIDAS qualified timestamp — verifiable by anyone, independently of us. Or send us the URL and we do it for you.
Frequently asked questions
Is a website capture admissible as evidence in court?
Admissibility is decided by the court, but the starting position matters enormously: a capture sealed with an eIDAS qualified timestamp carries a legal presumption of date accuracy and data integrity under Article 41(2) of Regulation (EU) 910/2014, recognized in all member states. The burden shifts to whoever disputes it — the opposite of where a plain screenshot leaves you.
How do I prove a web page said something in the past?
Retroactively, public archives are the only option and an imperfect one. Reliably, only evidence created at the time works: a capture sealed with a qualified timestamp proves both the content and the moment. The practical rule is simple — capture while the page still says what matters.
What's the difference between a screenshot and a forensic capture?
A screenshot is an image with no verifiable properties. A forensic capture is a package: full-page image plus HTML, network traffic and metadata, all hashed with SHA-256, sealed with a qualified timestamp, and independently verifiable offline. One asks the court to trust you; the other hands over proof anyone can check.
Can I capture a page that requires login?
Yes — through a browser extension running in your own authenticated session, since no server can see content behind your login. The forensic pipeline (hashing, qualified timestamp, verifiable package) is applied to exactly what your session displays.
How do I document that a website changed?
Proving change needs two verifiable states — before and after, each sealed at its own point in time. Scheduled monitoring produces exactly that: automatic captures on a fixed schedule, each a complete proof, with email notification when the captured content differs from the previous run.
Who can verify the evidence, and does it depend on GetProofAnchor existing?
Anyone, and no. The Evidence ZIP is verified with the open-source gpa-verify tool — offline, using open standards only, without an account or any contact with us. A Bitcoin anchor additionally proves existence-in-time independently of any company, including ours.
Go deeper
This guide is general information, not legal advice. The assessment of evidence in a specific proceeding always rests with the competent court.