Corporate legal, IT & eDiscovery
Every internal investigation eventually has to explain how it handled the data.
Collections from a mailbox, an endpoint, or a SaaS tenant are quick to run and slow to account for. CustodyTrack records who collected what, when, and who has held it since — as a chained trail kept deliberately outside the systems it describes.
In-house counsel, security and incident-response teams, and the eDiscovery function that inherits their collections.
The problem
Where the custody record comes apart.
The collection is logged inside what is being investigated
An administrative export from a productivity suite leaves its audit entry inside the very tenant under review. That is a poor home for the record of an investigation into that tenant, and a poorer one for the record of who took the export afterwards.
The data crosses organisational lines immediately
Security hands to legal, legal hands to outside counsel, outside counsel hands to a review vendor. Each hop is an attachment and an assumption that nothing changed in transit.
Preservation and documentation get conflated
A hold notice stops deletion. It does not record who took custody of the collected set, and it does not show that the set produced eight months later is the same one — which is the second half of what a spoliation motion asks about.
Defensibility is asserted rather than evidenced
A process is defensible when it can be described, repeated, and shown to a third party. Screenshots of an export wizard and a memory of who ran it are none of those things.
Where it fits
Three points in work you already do.
Collect
Record the collection at the moment it runs: the tenant or host, the custodian accounts in scope, the date range, the method used, and the digest of the exported set.
Route
Each transfer — security to legal, legal to counsel, counsel to a review vendor — is acknowledged by the receiving party and chained to the entry before it.
Account
When the process is questioned, the whole trail re-computes from the first entry to the last, and any third party can confirm it independently of your team and your tooling.
The terms this record uses
- Internal investigation
- Incident response
- Custodian collection
- Legal hold
- Defensible process
- Audit trail
- Vendor handoff
- Spoliation
What you can stand behind
Claims that survive being tested.
An audit trail outside the system under review
The custody record does not live in the tenant, the endpoint agent, or the ticketing queue it describes. Independence from the systems in scope is the entire point of keeping it elsewhere.
Tamper-evident by construction, not by policy
Each entry carries the digest of the entry before it, so altering one breaks verification for every entry after it. That makes alteration detectable; it does not make a database row unchangeable, and the difference is one an opposing expert will press on.
Verification without handing over the collection
Auditors, regulators, and opposing parties can confirm a record is intact from a verification code. Custodian names, date ranges, and matter details are not disclosed by the act of verifying.
Field definitions informed by published guidance
Collection and handling fields are informed by NIST SP 800-86 and ISO/IEC 27037 rather than invented in-house, so the record reads the way an examiner or a reviewing expert expects it to.
Start from the right form
The templates this work needs.
The four collection types a corporate matter actually produces: a SaaS tenant export, a mailbox, a server acquisition, and an endpoint image.
Cloud & online
Cloud software service
A whole SaaS tenant — M365, Workspace, Slack, Salesforce — collected across custodians.
Cloud & online
Email / mailbox
A single mailbox and its contents, as a PST, MBOX, or EML set — one custodian, not a tenant.
Devices
Server
A physical, virtual, or cloud server taken live or powered down — RAID, role, and image.
Devices
Computer
A desktop or laptop imaged for analysis — storage, write-blocker, and image hash.
All twelve templates are available on every plan — see the full set.
Common questions
- How is this different from our eDiscovery platform's audit log?
- A review platform logs what happened inside that platform. CustodyTrack records custody across the boundaries between systems and organisations — collection, handoff to counsel, handoff to a vendor — and lets a third party check the record without access to any of them.
- Does IT have to deploy anything?
- No. There is no agent and no integration. A collection is recorded through the web app, and the only thing that leaves your environment is a hash value and the metadata you type.
- Can outside counsel or a review vendor take custody without a licence?
- Yes. The receiving party signs through a secure link at no cost. Only the party creating forms consumes credits.
What it costs
$4.99 per Authenticated Chain of Custody Form, or a monthly plan for regular volume. Transfers and verifications are unlimited and free on every plan, and the party receiving a transfer never pays anything.
Other work looks different? See the other three.
Give the next collection a record that outlives the matter.
Two forms free at signup. Unlimited transfers and verifications on every plan, for every party you hand off to.