Frequently Asked Questions
1. What should I verify about evidence before handing it off to an eDiscovery tool?
Confirm the evidence was acquired with write-blocking and hash-verified (MD5/SHA-256) at the point of collection, and that a documented chain of custody travels with the file. An eDiscovery tool’s ingestion process generally assumes the underlying acquisition was already forensically sound — it isn’t designed to independently verify how the evidence was originally collected, so that check has to happen before handoff, not after.
2. Can I load a forensic image (E01/L01) directly into an eDiscovery tool, or does it need to be converted first?
Most eDiscovery tools accept common forensic image formats, but supported formats vary by platform — check the specific tool’s ingestion requirements before acquisition, so the format your collection tool produces on-scene isn’t something the review platform can’t read. Confirming this upfront avoids a re-acquisition trip later in the case.
3. What do I do if a hash value doesn’t match once evidence is loaded into the eDiscovery tool?
Treat it as a potential integrity failure, not a formatting glitch. Flag the discrepancy immediately, document it, and re-verify against the original acquisition-time hash before continuing review — proceeding with mismatched evidence is a common way a case’s admissibility gets challenged later.
4. Can an eDiscovery tool process DVR/CCTV video evidence on its own, or does that need separate handling?
Generally no. Standard eDiscovery tools are built around documents, email, and structured data; proprietary DVR/NVR file systems and fragmented or deleted footage need to be recovered with a purpose-built forensic video tool first, then the resulting file handed to the eDiscovery tool alongside the rest of the evidence set — not loaded directly from the DVR.
5. If evidence turns out to have been improperly collected, does that affect what’s already loaded in the eDiscovery tool?
Yes — the eDiscovery tool has no way to retroactively validate or fix a flawed acquisition. If a collection issue surfaces after evidence is already in review (a broken chain of custody, a missed write-blocker, an unverified hash), it can put everything downstream from that evidence into question, regardless of how far along the review already is.