Introduction
To prove a photo has not been edited, you need records that were made before anyone asked the question: the original capture file (the RAW), a cryptographic hash of each file logged at the first backup and dated by an independent timestamp authority, and a log of who held the files from the shoot to the courtroom. A court does not ask for a certificate of authenticity. Under Federal Rule of Evidence 901 it asks the person offering the photograph to show that it is what they claim, and the hash, the RAW comparison and the log are what make that testimony checkable by the other side. The section how to prove a photo has not been edited sets out the three comparisons and the rules that admit them.
In a legal dispute, a single photograph can be decisive. A court relies on it through the person who vouches for it. The documented history around it, the chain of custody, protects that account when the other side asks when the file could last have been changed, a question testimony alone cannot settle. This guide is written around United States practice and the Federal Rules of Evidence. The records it describes are the same in any jurisdiction; the rules that weigh them are not, so readers elsewhere should take the procedure and leave the citations to local counsel.
A 2025 California case shows how a challenge actually plays out. In Mendones v. Cushman & Wakefield (Alameda County Superior Court, Case 23CV028772, order of September 9, 2025), self-represented plaintiffs submitted videos of a witness and photographs in support of their motion. The court found the videos AI-generated and at least one photograph materially altered, and it got there through the records. The metadata of one file named an iPhone 6 Plus running iOS 12.5.5, which could not have produced what the file was claimed to show, and the visual content contradicted itself. The court dismissed the case with prejudice as a terminating sanction. No new rule was needed for that outcome, only the originals, their metadata, and a judge who compared them.
This guide sets out a process for maintaining a chain of custody for photographic evidence, ensuring its integrity, and it explains how modern standards like C2PA make that process more secure and reliable.
What is Chain of Custody and Why It Is Critical
The chain of custody is the chronological documentation of an evidence asset's lifecycle. For a photograph, it is the log of who captured it, when it was created, how it was stored, who has accessed it, and how it is presented. Its importance is founded on three legal principles:
- Admissibility: Under Federal Rules of Evidence Rule 901, evidence must be authenticated before admission. The usual foundation for a photograph is Rule 901(b)(1), a witness with knowledge who says it fairly and accurately shows what it claims to show; that bar is low, and most photographs clear it on testimony alone. Rule 901(b)(9) addresses evidence produced by a "process or system," requiring a showing that the process produces an accurate result. A documented chain of custody supports both. Since 2017, hash-verified records can additionally qualify as self-authenticating under FRE 902(13) and 902(14), replacing live foundation testimony with a written certification.
- Integrity: The process proves that the photograph presented in court is identical to the one captured at the scene, free from any tampering.
- Credibility: A strong chain of custody is the best defense against claims that evidence was mishandled, altered, or contaminated.
Without this documentation, admission on the day is usually not the problem. The problem comes later, if a challenge is substantiated and the side offering the photograph has to produce the originals, metadata that agrees with the account, and a date that none of the parties controlled. None of that can be created afterwards.
The 6 Steps to a Defensible Chain of Custody
For forensic photography to be effective, it must adhere to a meticulous process. These six steps are the standard for creating a record that withstands legal scrutiny.
Step 1: Secure Image Capture
The chain of custody begins at the moment of creation. The record you can later anchor begins at the first backup, and nothing covers the card in between, so back up on the day you shoot.
- Shoot in RAW: Use the camera's RAW file format. It captures the maximum amount of original sensor data and is inherently more difficult to alter without detection.
- Verify Camera Time: Ensure the camera's internal clock is set to the correct date and time, synchronized to a reliable source. This embeds the initial, crucial metadata. Our camera setup checklist for evidence photography covers this and the other pre-shoot settings in detail.
- Capture for Context: Photograph the scene broadly, then take medium and close-up shots. When documenting specific items, include a reference scale (like a ruler) in the frame.
- Avoid Mobile Devices: Cellular phones and personal devices are not recommended for evidentiary photography unless operationally necessary. If used, document the necessity.
Step 2: Immediate On-Site Logging
The initial handling of the evidence must be documented instantly.
- Start a Log: Use a dedicated notebook or a secure digital application to create a chain of custody log.
- Record Essential Data: For each significant photo or memory card, log the following:
- Case or project identifier
- Precise date and time
- Geographic location (GPS coordinates are ideal)
- Name and signature of the photographer
- A concise description of the subject matter.
Step 3: Verifiable Transfer and Cryptographic Hashing
This is the most critical technical step in securing digital evidence.
- Use a Write Blocker: Transfer files from the memory card to a secure storage system using a hardware or software write blocker to prevent any alteration of the original media.
- Generate a Hash: Immediately after transfer, use a standard cryptographic algorithm (SHA-256 is the industry standard) to generate a unique hash value for each image file. This hash is an unforgeable digital fingerprint.
- Log the Hash Value: Record this alphanumeric string in the chain of custody log. The original memory card should then be sealed in an evidence bag and stored as a master copy.
Professional card offload tools handle most of this step for you. OffShoot, Silverstack, ShotPut Pro and YoYotta write a manifest during every transfer, a hash list of each file on the card. Lumethic Offloads anchors that manifest with an independent timestamp authority the moment the backup happens. The hash log then carries a third-party date instead of resting on your own records, and backdating it becomes technically infeasible. How to prove a photo existed on a date explains what such a timestamp establishes. One setting in the transfer tool decides how much the anchored manifest can prove. A hash log binds file contents only when it uses a cryptographic hash; the xxHash default in every major offload tool catches copy errors and nothing more, and a receipt built on it is graded offload-event-only, which proves that the copy took place, not what the files contained. Switch the tool to C4 before the shoot and the receipt is graded content-bound. The checksum settings guide shows the setting in each tool.
Step 4: Controlled Storage in a Secure System
Once transferred, the evidence requires protection from any unauthorized access.
- Use a DEMS: Store images in a Digital Evidence Management System (DEMS) or a Digital Asset Management (DAM) system with strict, role-based access controls.
- Audit All Actions: The system must automatically log every instance of a file being accessed, viewed, exported, or modified. This audit trail is a core part of the chain of custody.
- Work on Copies Only: All analysis, enhancement, or distribution must be performed on verified copies of the original file. The original remains untouched.
Step 5: Transparent and Documented Analysis
Any modification to an image must be fully documented and repeatable. The same rules that govern news photojournalism apply to evidentiary photography.
- Use a Verified Copy: Never perform adjustments on the original evidence file.
- Permitted Enhancements: An image may be lightened, darkened, cropped, or have its color and white balance adjusted. These adjustments reveal existing information.
- Prohibited Modifications: Adding or removing any content from the image is unacceptable and will compromise admissibility.
- Document All Steps: Every tool, software version, and specific adjustment must be meticulously recorded. For example: "Adobe Photoshop 2025, Levels adjustment: input 15, 1.00, 245."
- Preserve All Versions: The original file, the working copy, and the final enhanced version (each with its own hash value) must all be preserved.
Step 6: Methodical Courtroom Presentation
The final step is the presentation of the evidence and its complete history.
- Submit the Documentation: The complete chain of custody log must be submitted along with the photograph.
- Be Ready to Verify: Be prepared to demonstrate in court that the hash of the presented photograph matches the hash logged at the time of ingestion, which proves the presented file is the one that was hashed then.
How to Prove a Photo Has Not Been Edited
The question a court actually asks is narrower than "is this photo genuine". It is whether the file in front of the judge is the file the witness says was captured, unchanged since. Three comparisons answer it, and each one needs something you kept on the day of the shoot.
Hash comparison. Compute the SHA-256 hash of the exhibit today and compare it with the hash logged at first backup (Step 3). A match means not one byte has changed since that log entry. The log entry proves its own date only if someone independent dated it, which is what an RFC 3161 timestamp on the manifest provides. Without it, the other side will point out that the log lives on your disk and could have been written yesterday.
RAW-to-JPEG comparison. When the camera recorded RAW and JPEG together, the RAW holds the sensor data and the JPEG is the camera's rendering of it. Rendering the RAW again and comparing it with the delivered JPEG shows whether the image content matches within the tolerances of the camera's own processing. Cloned patches, removed objects and composited elements show up as regions where the two disagree. This is the comparison Lumethic runs, and it also answers the AI question, because a generated image has no RAW behind it.
Metadata consistency. Capture time, camera model, serial number, lens and software tags in the JPEG must agree with the RAW and with the on-site log. A Software field naming an editing application, or a modification time earlier than the capture time, does not prove tampering, but it is what the opposing expert will ask about first.
The Federal Rules of Evidence give these comparisons a place. Rule 901(b)(9) allows authentication by evidence describing a process or system and showing that it produces an accurate result, which is how a hash comparison or a forensic RAW comparison enters the record. Rule 902(13) and 902(14) let a qualified person certify in writing records generated by an electronic process and data copied from a device, storage medium or file, so the hash verification does not need live testimony; the committee note to 902(14) names hash values as the way to establish that a copy is identical to the original. Our FRE 902 guide covers the certification itself.
For the examination itself, the reference examiners work from is the Scientific Working Group on Digital Evidence's Best Practices for Image Authentication (document 18-I-001, version 2.0 of March 2025). It defines image authentication as determining whether a questioned image is an accurate representation of the original data, and it directs the examiner to both the scene content and the file structure. The comparisons above give an examiner exactly that material. Without the RAW and the dated hash, the examination is limited to what the JPEG alone reveals, and its conclusions get correspondingly weaker.
How to Photograph Evidence: The Minimum Documentation Standard
The six-step process governs what happens to evidence photographs after capture. Just as often, the question is what the photographs themselves must contain. At a minimum, evidence should be photographed in a three-tier sequence, with every frame accounted for:
- Overall (establishing) shots place the scene in context: wide frames from each approach or corner, showing entrances, exits, and the spatial relationship between items. These come first, before anything is moved or marked.
- Mid-range (relationship) shots connect an individual item to its surroundings. They are close enough to identify the item and wide enough that its position within the overall scene remains visible.
- Close-up (examination) shots record the item itself: first as found, then with a reference scale and evidence marker in frame, shot perpendicular to the subject to avoid perspective distortion. For toolmarks, injuries, and damage documentation, capture each subject both with and without the scale.
Three habits make the set defensible rather than merely thorough. Photograph the sequence before introducing markers, then again with them. Never delete a frame. A gap in the numbering invites a foundation challenge, so blurry or redundant frames stay in the set and in the log. And record the sequence in the photo log as it is shot (frame number, subject, position, time), because a log reconstructed afterward is exactly the kind of after-the-fact documentation that FRE 901 challenges feed on.
The same standard applies to civilian disputes such as insurance claims, construction defect documentation, delivery damage, and tenancy handovers. Courts and adjusters apply the same logic everywhere: context frames, relationship frames, detail frames with scale, an unbroken numbered sequence, and originals preserved in RAW. For recurring commercial use cases, an image-based verification workflow turns this from a manual discipline into an automated one.
The Modern Challenge: AI and the Need for Digital Provenance
AI image tools have made subtle alteration cheap, so the question of whether a file has been changed now gets asked about files that look ordinary. A hash and an independent date cost almost nothing to keep on the day of the shoot and cannot be reconstructed later. That is the practical case for a cryptographically checkable chain of custody, more than any rise in the number of challenges.
In the United States, the rules are still catching up. The Advisory Committee on Evidence Rules has drafted a proposed Rule 901(c) that would shift the burden in disputes over AI-fabricated evidence: if a party shows it is more likely than not that an item was altered or generated by AI, the side offering it must then prove the content is authentic. The Federal Judicial Center surveyed federal judges for that work and released the results on March 25, 2026. Of 931 responding judges, 15 had ever seen a litigant challenge audiovisual evidence as a deepfake, two-thirds of those exactly once, most in civil cases; and about four in five said they would require a substantiated initial showing before inquiring further. A separate proposed Rule 707 on machine-generated evidence went out for public comment in 2025; the Advisory Committee did not advance it at its May 2026 meeting, and in June 2026 the Standing Committee took no action on it, keeping it and the deepfake question under study. None of this is settled law. The survey does show that challenges are rare, that judges expect a substantiated showing before they entertain one, and that a substantiated challenge is decided on the records that exist at that point.
The New Standard: C2PA for Automated, Verifiable Trust
The Coalition for Content Provenance and Authenticity (C2PA) has established an open technical standard to combat digital deception by embedding a secure chain of custody directly into a file's code.
- How It Works: C2PA-enabled devices or software cryptographically sign the asset at its point of origin, creating a tamper-evident manifest of its provenance. Every subsequent change is recorded in this manifest.
- Lumethic's Role: Lumethic's records make three claims: that every file on a card existed no later than an independent anchor time, byte for byte when the hash list uses a content-binding checksum; that the hash list can be re-verified by anyone holding the receipt; and that a delivered image is consistent with its camera RAW within stated thresholds. None of that decides admissibility. It gives the person who vouches for the photograph records that the other side can check, and what a record contains describes those checks in detail.
Traditional Chain of Custody vs. C2PA: A Comparison
| Aspect | Traditional | C2PA-Enabled |
|---|---|---|
| Documentation | Manual log entries | Automated manifest in file |
| Human Error | High risk | Minimal |
| Tamper Detection | Separate hash check | Built-in |
| Transfer Tracking | Paper signatures | Cryptographic signatures |
| Verification Speed | Hours | Seconds |
| Court Presentation | Log + testimony | Manifest + testimony |
| Scalability | Labor-intensive | Automatic |
| Cost | Low setup, high labor | Higher setup, lower labor |
For organizations handling significant volumes of evidentiary photography, the efficiency and reliability gains of C2PA-enabled workflows often justify the transition investment.
Conclusion: Evidence is Only as Strong as Its Verifiable History
A photograph is admitted through the person who vouches for it, and a documented chain of custody decides how well that account holds up under questioning. The traditional process has long been the benchmark, and AI-driven editing has made subtle alteration cheaper. Technologies like C2PA and anchored hash lists matter to legal and forensic professionals because they turn the log into something the other side can check independently. Admissibility still turns on testimony. The records are what that testimony rests on.
For photographers and legal teams putting this into practice, the legal evidence workflow shows the complete path from card to exhibit with Lumethic: offload receipts anchored at the first backup, verification of the exhibits, and reports the legal team can check via link. The one-page requirements sheet is the version to paste into an engagement letter.
Chain of Custody FAQ
What is the single most important step in the chain of custody? The initial, verifiable transfer and cryptographic hashing (Step 3) is the most crucial technical step. It establishes the baseline integrity of the digital evidence with a unique, unforgeable fingerprint that can be checked at any point in the future.
Can a photograph be used in court without a formal chain of custody? Yes, and most are. A witness with knowledge who testifies that the photograph fairly and accurately shows the scene is the usual foundation under Rule 901(b)(1). The chain of custody matters when that testimony is challenged on whether the file changed after the fact, which a witness cannot settle from memory.
Does C2PA make the traditional chain of custody log obsolete? C2PA automates and embeds the most critical components of the log directly and securely into the file itself, making the process more efficient and far less susceptible to human error. It is the modern, technical evolution of the traditional paper log.
What software should I use to generate SHA-256 hashes?
On macOS or Linux, use the built-in terminal command shasum -a 256 filename.jpg. On Windows, use certutil -hashfile filename.jpg SHA256 in Command Prompt. For a graphical interface, tools like HashCalc or QuickHash are widely used. Always document the tool and version used.
How long should chain of custody records be retained? Retention periods depend on jurisdiction and case type. For civil matters, retain records for at least the statute of limitations plus any appeals period (often 7-10 years). For criminal cases, retention may be indefinite. Consult local rules and organizational policies.
Can cloud storage break the chain of custody? Cloud storage does not inherently break the chain, but it introduces additional documentation requirements. You must log the upload, document the cloud provider's access controls and audit capabilities, and verify file integrity (hash comparison) upon retrieval. Using a DEMS with built-in cloud integration simplifies this process.
What happens if the original memory card is lost or damaged? If you generated and logged a cryptographic hash immediately after capture, the integrity of your copy can still be verified. However, the loss weakens the chain and may be challenged. Best practice is to create multiple verified copies immediately and store the original media in a secure, controlled environment.





