Chain of Custody Protocol
How EpsteinWiki receives, preserves, verifies, transfers, analyzes, publishes, and audits documentary evidence without losing the story of where it came from
A document can be genuine and still be misunderstood. It can be complete when received and incomplete when published. It can be copied perfectly from a source that mislabeled it. It can carry an official stamp without proving every statement inside it. It can also be accurate, important, and impossible to use responsibly because nobody recorded who obtained it, what changed, or where the original went.
Chain of custody is the history that follows an item from discovery through preservation, review, publication, and eventual disposition. For EpsteinWiki, that history is not courtroom theater. It is how readers can distinguish an original government release from a contributor’s working copy, a complete exhibit from a screenshot, verified metadata from an assumption, and a preserved file from one altered during handling.
This protocol is designed for an investigative archive, not a law enforcement evidence room. It does not make EpsteinWiki a forensic laboratory, confer legal admissibility, or repair missing custody information from before the item reached the project. It creates an honest, reviewable record of what EpsteinWiki received and what happened next.
Snapshot
- Preserve the source before analyzing the content.
- Never work directly on the only copy of a file.
- Keep the received original unchanged and create separate working and publication copies.
- Record who received the item, when, from whom or where, by what method, and in what condition.
- Calculate a modern cryptographic hash for lawful digital files at intake and after every meaningful transfer or preservation event.
- A matching hash shows that file bytes match. It does not prove authorship, authenticity, completeness, legality, or truth.
- Give every item a unique evidence identifier. Never rely on filenames alone.
- Record every transfer, access, conversion, redaction, OCR process, excerpt, and publication decision.
- Preserve original filenames, embedded metadata, source URLs, surrounding pages, and release context.
- Never circulate suspected child sexual abuse material or other illegal content to create a custody record.
- Protect survivor identities, minors, personal data, confidential sources, and sealed information.
- Publish the public use copy, not the preservation master.
- If the chain is incomplete, say so. Do not invent a clean history.
Purpose
This protocol establishes a consistent evidence lifecycle for EpsteinWiki. It is intended to:
- Preserve the integrity of files and physical records
- Document provenance and custody
- Prevent accidental alteration or deletion
- Separate preservation from analysis and publication
- Make editorial conclusions reproducible
- Protect sensitive people and information
- Identify gaps, conflicts, substitutions, and unexplained changes
- Support corrections, audits, and future research
The protocol works alongside Evidence Handling 101, How to Read an Epstein Document, Editorial Standards, Moderation & Flagging Protocols, and Handling Sensitive Material.
Scope
This protocol applies to evidence and source material received, collected, created, analyzed, stored, transferred, cited, or published by EpsteinWiki, including:
- Court filings, dockets, exhibits, transcripts, and orders
- Government disclosures and Freedom of Information Act productions
- EFTA numbered records and other files in the DOJ Epstein Library
- Documents indexed by Epstein Data
- FBI Vault records and agency releases
- Emails, calendars, address books, flight records, financial documents, and corporate records
- Photographs, audio, video, scans, and screenshots
- Web pages, archived pages, social posts, and online databases
- Spreadsheets, exports, structured data, and code generated reports
- Physical letters, photographs, storage media, and printed records
- Survivor, witness, source, and contributor submissions
- OCR text, translations, transcriptions, annotations, and redacted public copies
It applies from first contact through final retention or authorized disposal.
What Chain of Custody Is
Chain of custody is a chronological record of possession, control, transfer, access, handling, and disposition. A useful chain answers:
- What is the item?
- Where did it come from?
- Who first received or collected it?
- When and how was it received?
- Was it complete and readable?
- What identifying information accompanied it?
- Where was it stored?
- Who accessed or transferred it?
- What actions were performed?
- Were any bytes, pages, metadata, filenames, or physical features changed?
- Which copy was analyzed?
- Which copy was published?
- Where is the preserved original now?
The chain is not a ceremonial signature sheet. It is a reconstruction of the item’s life that another qualified person can examine.
What Chain of Custody Is Not
A documented chain does not automatically prove:
- That the item is authentic
- That the source had lawful access
- That the item was complete before EpsteinWiki received it
- That the author told the truth
- That a government stamp is genuine
- That metadata reflects the true creation event
- That a scan has not omitted a page
- That an allegation has been adjudicated
- That a court would admit the item
- That a matching name identifies the correct person
Chain of custody documents handling. Provenance explains origin. Authentication evaluates whether the item is what it is claimed to be. Corroboration tests its content against other evidence. Editorial analysis explains what it proves and does not prove. These functions overlap, but they are not interchangeable.
EpsteinWiki Is Not a Law Enforcement Evidence Room
EpsteinWiki preserves and explains public interest records. It does not seize devices, conduct criminal searches, direct witnesses, or promise courtroom admissibility.
Contributors must not represent themselves as law enforcement, forensic examiners, attorneys, or agents of EpsteinWiki unless that role has been formally assigned. They must not trespass, hack accounts, bypass access controls, buy stolen credentials, pressure survivors, or direct anyone to commit an unlawful act to obtain evidence.
The National Institute of Justice guide to digital evidence emphasizes that digital evidence is fragile and that collection, examination, storage, and transfer activities should be documented and preserved. EpsteinWiki adapts those principles to responsible archival and journalistic work while remaining clear about the limits of its role.
Core Preservation Principles
Every evidence handler should follow these rules:
Preserve first. Capture source and context before opening, converting, renaming, annotating, or extracting.
Use separate copies. Keep a preservation master, a working copy, and a public use copy when publication requires processing.
Record actions as they happen. A log recreated from memory is weaker than a contemporaneous record.
Minimize handling. Every unnecessary transfer or conversion creates another opportunity for loss or confusion.
Keep originals unchanged. Never overwrite the received file or alter a physical original.
Protect access. Only people with a defined need should handle sensitive material.
Make uncertainty visible. Missing history must be marked as missing, not filled with assumptions.
Preserve context. A page without its docket, production folder, email thread, release note, or neighboring pages may lose essential meaning.
Roles and Responsibilities
One person may perform more than one role in a small project, but the role used for each action must be recorded.
Submitter: Provides or identifies the item and explains its origin to the extent known.
Intake custodian: Receives the item, creates the initial record, preserves the original, and assigns the evidence identifier.
Evidence custodian: Controls preservation storage, permissions, integrity checks, transfers, and retention.
Reviewer or analyst: Examines an authorized working copy and documents methods, tools, and conclusions.
Editor: Determines how the evidence may be described, cited, redacted, contextualized, and published.
Moderator or safety reviewer: Handles privacy, threats, illegal material, manipulation, and high risk disputes under the moderation protocol.
Publisher: Confirms that the approved public use copy and correct citation are released.
High risk evidence should receive independent review. No contributor should be the sole submitter, custodian, analyst, editor, and final approver for a consequential disputed item when another reviewer is available.
Evidence Identifiers
Assign a unique internal identifier immediately after safe intake. The identifier must remain attached to the item even if the filename changes.
A practical pattern is:
EW-YYYY-NNNNN
Example: EW-2026-00418
Use a suffix to distinguish authorized derivatives:
EW-2026-00418-MASTERfor the preserved received copyEW-2026-00418-W01for working copy oneEW-2026-00418-OCR01for the first OCR outputEW-2026-00418-TRANS01for a transcriptionEW-2026-00418-RED01for a redacted copyEW-2026-00418-PUB01for the approved publication copy
Do not replace official identifiers. Record EFTA numbers, exhibit numbers, Bates numbers, docket numbers, agency production numbers, and original filenames as separate fields. The internal ID connects the custody record. The official identifier connects the item to its external record.
Required Intake Record
The intake custodian must record:
- EpsteinWiki evidence identifier
- Date and time received, including time zone
- Name or protected identifier of the receiver
- Source name, protected source code, or public location
- Exact source URL when public
- Transfer method, such as download, email, upload, physical delivery, or records portal
- Original filename and extension
- File size in bytes
- File type reported by the system and expected format
- Cryptographic hash for lawful digital files
- Page count or item count
- Known EFTA, Bates, exhibit, docket, or production identifiers
- Visible markings, stamps, signatures, redactions, damage, or anomalies
- Accompanying message, folder structure, index, or release note
- Initial sensitivity classification
- Storage location
- Any custody gap known at intake
The record should distinguish what the receiver personally observed from what the source reported.
Step by Step Intake Procedure
Step 1: Stop and Assess Safety
Before opening or copying an item, determine whether it may contain malware, illegal imagery, exposed credentials, private survivor information, sealed material, or an active threat. If suspected child sexual abuse material is involved, do not download, copy, circulate, or attempt to authenticate it. Follow the Moderation & Flagging Protocols and use the NCMEC CyberTipline when appropriate.
Step 2: Capture the Source Context
Record the page URL, portal, docket entry, production folder, email headers, release date, surrounding description, and access date. For a web source, save enough context to show how the file was presented. A naked download can lose the evidence that it came from an official agency page.
Step 3: Preserve the Received Item
Save the item to controlled intake storage without renaming or editing it. Preserve the original directory structure when receiving a batch. Do not resave a PDF through a viewer, rotate pages in place, or run OCR against the only copy.
Step 4: Record Technical Characteristics
Record the original filename, exact byte size, detected format, page count, and hash. If a batch includes a manifest, preserve it. If a website supplied checksums, record those separately and compare them.
Step 5: Assign the Internal Identifier
Create the unique EpsteinWiki evidence ID and associate it with every part of the intake record. Never use a person’s name as the sole identifier for sensitive evidence.
Step 6: Classify and Store
Apply the correct access level, store the preservation master in the approved location, and create a working copy only for authorized review.
Step 7: Confirm Intake
When appropriate, tell the submitter that the item was received. Do not confirm authenticity, publication, or investigative action before review.
Source Acquisition Records
The method of acquisition matters. Record enough detail to allow a reviewer to repeat or evaluate the collection.
Official Website Download
Record the full URL, page title, agency, publication or update date, access date and time, filename, and any page text describing the release. Preserve the landing page as well as the file.
Court Record
Record the court, case caption, docket number, docket entry number, filing date, exhibit designation, page or attachment number, and access system. Link to CourtListener or the official court source when publicly available. PACER derived copies should retain their receipt or docket context when lawful and useful.
Epstein Data Record
Record the exact EFTA identifier and direct Epstein Data record link. Preserve the relationship between the indexed record and any underlying DOJ release. Do not cite only a screenshot of search results when the source document is available.
Email or Direct Submission
Preserve the original message and available headers. Record whether the attachment was forwarded, compressed, renamed, or downloaded through a service. Protect the source’s identity according to the agreed level of confidentiality.
Physical Delivery
Photograph the package and condition before opening when safe and appropriate. Record seals, labels, postmarks, tracking information, page order, damage, and included notes. Use clean handling appropriate to the material. Do not write on, staple, laminate, repair, or rearrange the original.
Original, Master, Working, and Public Use Copies
These terms must be used consistently.
Received original: The exact physical item or digital bytes as EpsteinWiki received them. This term does not claim that the item is the author’s original or the first generation copy.
Preservation master: The controlled, unchanged copy retained for integrity and future verification. For a digital submission, the received original and preservation master may have identical bytes but different storage roles.
Working copy: A duplicate used for review, OCR, annotation, conversion, extraction, transcription, or analysis.
Public use copy: The approved version prepared for publication. It may include redactions, compression, watermarks, accessibility text, or format conversion.
Never describe a public use copy as the unaltered original. The record should map every derivative back to its parent evidence ID and document the process that created it.
Cryptographic Hashes
A cryptographic hash is a value calculated from file bytes. If the bytes change, the resulting value will ordinarily change. Hashes support fixity checking, duplicate identification, transfer verification, and audit.
EpsteinWiki should record SHA 256 for new digital evidence unless a documented technical reason requires another approved modern algorithm. If a source supplies MD5 or SHA 1, preserve the supplied value for comparison but also calculate SHA 256. Older values remain useful as identifiers, but they should not be the project’s only integrity control.
The hash record must include:
- Algorithm
- Complete value
- Date and time calculated
- Evidence ID
- File size
- Tool and version, when available
- Person or automated system that performed the calculation
- Which copy was hashed
The NIST Digital Evidence Preservation report discusses the distinct preservation challenges of digital evidence. The National Archives Digital Preservation Program states that files should have recorded fixity, actions should be tracked, audits should occur, and separate public use copies should be created.
What a Matching Hash Proves and Does Not Prove
If two files produce the same SHA 256 value, that is strong evidence that their bytes are identical.
A matching hash does not establish:
- Who created the file
- Whether the source had authority to release it
- Whether the content is truthful
- Whether pages were missing before hashing
- Whether the file was fabricated before intake
- Whether a date inside the document is accurate
- Whether the displayed extension matches the real format
- Whether a named person is correctly identified
- Whether a screenshot captures the full context
Write: “The archived copy matches the SHA 256 value recorded at intake.”
Do not write: “The hash proves the document is authentic.”
Hash integrity is one part of authentication, not a substitute for it.
Metadata Preservation
Metadata can include creation and modification times, author fields, software identifiers, email headers, camera information, embedded object data, filenames, folder paths, and document properties.
Metadata may be relevant, but it is not automatically reliable. Copying, exporting, scanning, emailing, uploading, editing, or migrating a file can change it. Device clocks can be wrong. Users can alter fields deliberately. Some platforms strip metadata.
At intake:
- Preserve the original file before inspecting metadata
- Extract metadata from a working copy or through a method that does not alter the master
- Record the tool and version used
- Save the extraction output as a derivative record
- Distinguish file system timestamps from embedded metadata
- Do not convert a metadata date into a factual event date without corroboration
When publication would expose a survivor, source, location, device, or private identity, remove sensitive metadata from the public use copy and document that removal.
File Naming and Folder Structure
Original filenames must be preserved in the intake record. Storage filenames may add the internal evidence ID, but do not silently replace the source name.
A controlled structure may use:
EW-2026-00418/
01_MASTER/
02_WORKING/
03_ANALYSIS/
04_PUBLIC/
05_LOGS/
Avoid filenames such as final.pdf, real_final.pdf, or newest2.pdf. Use explicit version and derivative labels. Record dates in YYYY-MM-DD format. Do not place unredacted survivor names or private data in filenames because filenames may appear in logs, links, backups, or search indexes.
Storage and Access Control
The preservation master should be stored in controlled, backed up, access logged storage. Sensitive evidence requires stronger restrictions than ordinary public records.
Access should follow least privilege. A person should receive only the access necessary for the assigned task. Administrative access is not permission to browse evidence.
Storage controls should include:
- Unique user accounts
- Multi factor authentication
- Encryption in transit and at rest where available
- Access logs
- Version history or write protection
- Tested backups
- Recovery procedures
- Separation of preservation and public storage
- Periodic fixity audits
- Prompt revocation when a role ends
Shared passwords and untracked personal drives are not acceptable evidence storage. A cloud link sent through chat is a transfer method, not a custody system.
Transfer Procedure
Every transfer of custody or control must be logged. This includes movement between people, systems, storage locations, or organizations.
The transfer record should include:
- Evidence ID
- Date and time sent
- Sender
- Recipient
- Transfer purpose
- Method
- File or item description
- Hash and byte size before transfer
- Hash and byte size after receipt
- Date and time receipt was confirmed
- Any encryption or packaging used
- Any error, interruption, mismatch, or missing component
- New storage location
The receiver confirms the item before the sender closes the transfer. A hash mismatch requires quarantine and investigation. Do not overwrite either copy while resolving the discrepancy.
For physical evidence, both parties should record condition, packaging, seals, page count, and any damage at transfer.
Access and Examination Log
Opening a preservation master can itself create risk. Every significant access should be attributable and purposeful.
Record:
- Evidence ID
- Person accessing
- Date and time opened and closed
- Authorized purpose
- Copy accessed
- Tool and version used
- Actions performed
- Outputs created
- Whether metadata or content changed
- Location of notes and derivatives
- Any anomaly or accidental alteration
Routine automated integrity scans may be recorded as system events. Sensitive manual review should still identify the human reviewer. Analysts must not use tools that automatically upload evidence to a third party service unless that transfer has been approved and documented.
OCR, Transcription, and Translation
OCR text, transcripts, and translations are derivatives. They are not substitutes for the source image, audio, video, or document.
For OCR:
- Run the process on a working copy
- Record the tool, version, language, settings, and date
- Preserve the raw OCR output
- Check names, numbers, dates, currency, handwriting, headers, and page breaks against the image
- Mark uncertain text rather than guessing
- Link corrected text to the source page
For transcription:
- Identify speakers only when supported
- Preserve timestamps
- Mark inaudible or uncertain passages
- Record whether the transcript was human, automated, or hybrid
For translation:
- Preserve the source language
- Identify the translator or method
- Record material ambiguities
- Obtain a qualified review for consequential language
Never alter the preservation master to make OCR easier.
Conversion, Compression, Rotation, and Repair
Format changes can improve access while changing bytes, metadata, image quality, color, fonts, layers, embedded files, signatures, or functionality. Every conversion creates a derivative.
Document:
- Parent evidence ID and hash
- Conversion purpose
- Original and output formats
- Tool and version
- Settings
- Date and operator
- Output hash and byte size
- Known losses or changes
Page rotation, deskewing, contrast adjustment, audio cleanup, video transcoding, and PDF repair must occur on working copies. Preserve a before and after relationship. Do not use enhancement to create detail that was not visible in the source.
The National Archives Digital Preservation Framework provides format risk and preservation planning resources. EpsteinWiki should review formats over time rather than assuming a file that opens today will remain usable forever.
Screenshots and Web Evidence
A screenshot preserves appearance, not the full web record. It may omit the URL, time, page source, links, metadata, comments, edits, or content outside the frame.
For a web page or social post, record:
- Full URL
- Account or site name
- Displayed publication date
- Collection date and time with time zone
- Screenshot dimensions
- Visible context before and after the relevant passage
- Page title
- Any post or record identifier
- Whether login or personalization affected the view
- Available archive link
- A saved page or structured export when lawful and feasible
Do not crop the only capture. Create a cropped publication derivative from the complete preserved capture. If content is dynamic, note that later visitors may see a different version.
Email Evidence
Forwarded email text is not equivalent to the original message. A screenshot of an inbox is not equivalent to a message file with headers.
When lawfully received, preserve:
- Original message format when available
- Full headers
- Sender, recipients, carbon copy fields, and timestamps
- Subject line
- Attachments and their hashes
- Thread order
- Folder or export context
- Delivery or authentication results shown in headers
- Redactions applied for publication
Email headers can support analysis, but they require expertise and can be misunderstood. Display names can be spoofed. A message may be authentic while an attachment is unrelated or altered. Authenticate each component and explain limitations.
Photographs, Audio, and Video
Preserve the received media file without recompression. Record the source, filename, byte size, duration or dimensions, hash, container, codec, and available metadata.
For analysis:
- Work from a duplicate
- Preserve full duration and original frame boundaries
- Record every edit, enhancement, stabilization, noise reduction, or frame extraction
- Keep extracted frames tied to exact timestamps
- Distinguish visual observation from identity inference
- Seek expert review before making consequential manipulation claims
A photograph can accurately depict a meeting without proving when, why, or what participants knew. Audio can be genuine while edited. Video can be complete while its caption is false. The custody record preserves the item; contextual evidence establishes meaning.
Physical Documents and Objects
Physical evidence should be handled as little as possible. Use a clean, secure workspace appropriate to the item. Preserve original order.
Record:
- Dimensions and page count
- Paper, binding, envelope, and packaging condition
- Handwriting, stamps, impressions, tears, folds, stains, and attachments
- Front and back of every page
- Numbering and blank pages
- Date, method, resolution, and equipment used for digitization
- Color target or scale when relevant
- Condition before and after handling
Do not use tape, adhesive notes, ink, staples, lamination, household cleaners, or improvised repairs. If conservation is needed, stop and seek a qualified professional. The scan is a derivative. The physical item remains the received original.
Batch Productions and Folder Context
Large government releases often arrive as folders, archives, indexes, manifests, or sequentially numbered files. Their structure can be evidence.
At intake:
- Preserve the original archive file
- Record its hash and byte size
- Extract only to a controlled working location
- Preserve directory paths and timestamps
- Inventory every file
- Record missing, duplicate, corrupt, or zero byte items
- Preserve manifests and readme files
- Compare stated totals with observed totals
- Record extraction tool and errors
Do not flatten a production into one folder if paths convey relationships. Do not renumber pages to make them look complete. If an EFTA sequence has gaps, report the observed gap without assuming why it exists.
Sensitive, Sealed, Privileged, and Illegal Material
Chain of custody never overrides safety or law.
If an item may contain suspected child sexual abuse material, do not download, copy, hash, forward, store, or inspect it merely to complete this protocol. Restrict access and follow the site’s critical incident process.
For exposed survivor identities, minors, doxxing, credentials, sealed records, privileged communications, or protected medical and financial data:
- Stop ordinary circulation.
- Limit access.
- Record the location without repeating unnecessary sensitive content.
- Notify the designated safety or senior editorial reviewer.
- Determine lawful handling and publication status.
- Create a redacted public use copy only after approval.
Do not put sensitive names in chat messages, filenames, task titles, or widely visible logs.
Confidential Sources
A source’s identity and an evidence item’s provenance may need separate records. Use a protected source code in the general custody log and store identity information in a more restricted record.
Before accepting confidentiality, clarify:
- What identity information will be protected
- Who may know the identity
- Whether the source may be described by role or proximity
- How EpsteinWiki may verify the material
- Whether the material may be published
- Legal or safety limits on confidentiality
- How future contact will occur
Do not promise absolute anonymity. Do not weaken the provenance record so much that editors cannot assess credibility. Where the public cannot see the full chain, the article should describe the basis for confidence without exposing the source.
Authentication Review
Authentication asks whether the item is what it is claimed to be. Review may include:
- Comparison with an official source copy
- Matching EFTA, Bates, exhibit, docket, or production numbers
- Pagination and sequence analysis
- Letterhead, stamps, signatures, formatting, and document conventions
- Metadata and file structure
- Email headers
- Independent references to the same item
- Source access and explanation
- Known exemplars
- Expert examination
- Internal consistency and external corroboration
No single feature is decisive in every case. Official appearance is not enough. Metadata is not enough. A source’s confidence is not enough. A matching hash to a known official copy is strong evidence of file identity, but the claims inside still require separate evaluation.
Use the Disinfo & Manipulated Media Guide for disputed or synthetic content.
Evidence Status Labels
Every consequential item should receive a status that reflects the current review, not the preferred theory.
Verified official copy: Matches a record obtained directly from an official public source or an independently verified official production.
Authenticated copy: Evidence supports that the item is what it claims to be, although it may not have been obtained directly from the issuing source.
Corroborated: Key content is supported by independent reliable evidence.
Partially verified: Some features or claims are confirmed, while others remain unresolved.
Unverified: Insufficient evidence currently exists to authenticate the item.
Disputed: A specific authenticity or completeness challenge exists and must be described.
Altered derivative: The item was intentionally processed for analysis or publication, with the parent preserved.
Rejected: Evidence shows the item is fabricated, materially manipulated, misidentified, or falsely described.
Statuses may change. Record who changed the status, when, why, and based on what evidence.
Analysis Notes and Reproducibility
An analyst should leave enough information for another qualified reviewer to repeat the work.
Record:
- Question being tested
- Evidence IDs examined
- Exact pages, timestamps, fields, or rows used
- Tools and versions
- Search terms, filters, code, formulas, and settings
- Transformations or exclusions
- Results
- Contradictory evidence
- Limitations and unresolved questions
- Reviewer identity and date
Do not alter data to fit a conclusion. Keep manual corrections, normalization, deduplication, and entity matching transparent. A spreadsheet derived from source documents needs its own evidence ID, version, methodology, and link back to every source row.
Publication Protocol
Before evidence is published, the editor and publisher should confirm:
- The correct evidence item and approved public use copy are selected
- The preservation master remains unchanged
- The source and provenance are accurately described
- Direct links point to the underlying record where available
- EFTA, Bates, exhibit, docket, page, and date identifiers are correct
- Redactions protect survivors, minors, sources, and private data
- OCR, transcript, translation, or enhancement is labeled
- Allegations, testimony, arguments, findings, convictions, denials, and open questions are distinguished
- The article says what the evidence proves and does not prove
- Relevant custody gaps or authenticity disputes are disclosed
- The published file hash is recorded when useful
- The article, attachment, caption, alt text, metadata, tags, and social preview agree
Publish from the approved public folder. Never publish directly from intake or preservation storage.
Citation Standard
A chain of custody record is not useful to readers unless the article identifies the evidence precisely.
A strong citation includes:
- Document title or descriptive name
- Issuing body or source
- Date
- EFTA, Bates, exhibit, docket, or production identifier
- Page or timestamp
- Direct clean link
- Access date for changeable web material
- Status or limitation when needed
For EFTA material, link directly through Epstein Data whenever the record is available there, and preserve the relationship to the DOJ Epstein Library. For litigation, use the official docket or a stable source such as CourtListener.
Do not cite a search results page when a direct document link exists. Do not cite a screenshot when the complete filing is available.
Corrections and Replacement Files
Never overwrite a published evidence file without recording the replacement.
When correcting or replacing a file:
- Preserve the old public version and its hash.
- Identify the reason for replacement.
- Create the corrected derivative from the proper parent.
- Assign a new derivative version.
- Record the new hash and approval.
- Update every affected article, caption, download, index, and social preview.
- Add a correction note when the change affects meaning.
If the wrong document was published, remove public access promptly while preserving the internal incident record. Follow the Corrections Policy and Moderation & Flagging Protocols.
Broken Chain, Missing History, and Conflicts
A broken chain does not automatically make an item false. It changes how confidently the item can be described and used.
Common problems include:
- Unknown original source
- Unexplained filename or page changes
- Missing attachments or pages
- Hash mismatch
- Transfer without receipt confirmation
- Public copy that cannot be matched to a master
- Screenshot without URL or date
- Physical item stored without access records
- Derivative with no documented parent
- Metadata inconsistent with the claimed origin
When a problem appears:
- Stop further transformation.
- Preserve all competing copies.
- Record the discrepancy.
- Compare hashes, sizes, pages, metadata, and surrounding context.
- Contact prior custodians when safe and appropriate.
- Seek an independent source copy.
- Reclassify the item if necessary.
- Disclose the unresolved gap in publication.
Never backdate a log or create a transfer event that did not occur.
Incident and Escalation Triggers
Escalate immediately when:
- A hash mismatch cannot be explained
- A preservation master was modified or deleted
- An unauthorized person accessed sensitive material
- Evidence was sent to an unapproved third party service
- A survivor or minor identity was exposed
- Credentials, financial identifiers, or home addresses appear
- A file may contain malware or illegal content
- A legal restriction, sealing order, or privilege claim is credible
- A contributor fabricated provenance or altered evidence deceptively
- A confidential source may have been identified
- Published evidence differs from the approved copy
- A batch has unexplained missing or substituted files
Preserve lawful logs, contain the exposure, notify the evidence custodian and senior moderator, and create an incident record. Do not quietly repair the problem and erase the history.
Audits and Fixity Checks
Evidence integrity requires ongoing review. Storage failure, corruption, accidental changes, migration, and account compromise can occur long after intake.
Audits should verify:
- Recorded files exist
- Current hashes match approved values
- Masters and public use copies remain separated
- Permissions reflect current roles
- Logs are complete and attributable
- Backups can be restored
- Formats remain readable
- Sensitive evidence remains appropriately restricted
- Published links and citations still resolve
- Derivatives map to their correct parents
The National Archives digital preservation program describes authenticity, accuracy, functionality, risk assessment, data integrity, information security, and ongoing usability as central preservation concerns. EpsteinWiki should use scheduled and event driven audits, especially after migration, restoration, security incidents, or large imports.
Retention and Disposition
Evidence should not be retained forever merely because storage is available. Retention decisions must consider historical value, legal obligations, source agreements, privacy, safety, ongoing research, correction needs, and the risk of keeping sensitive material.
A disposition record should include:
- Evidence ID
- Item description
- Retention authority or policy
- Reason for disposition
- Approver
- Date
- Method
- Related holds, disputes, or source agreements checked
- Confirmation that public links and derivatives were addressed
Do not destroy evidence subject to litigation, a legal hold, an active correction, a credible investigation, or an unresolved safety incident. Destruction must be authorized, documented, and appropriate to the medium. Deleting a link is not the same as securely disposing of stored data.
Chain of Custody Log Template
| Field | Required entry |
|---|---|
| Evidence ID | Unique EpsteinWiki identifier |
| Official identifiers | EFTA, Bates, exhibit, docket, agency, or production number |
| Item description | Neutral description without unnecessary sensitive detail |
| Source | Public URL, named source, or protected source code |
| Received | Date, time, time zone, receiver, and method |
| Original filename | Exact name as received |
| Technical details | Format, byte size, page count or duration |
| Intake hash | Algorithm and complete value |
| Sensitivity | Public, internal, restricted, or critical |
| Storage | Controlled location of preservation master |
| Custody gap | Known missing history before or after intake |
| Action | Access, copy, transfer, OCR, conversion, analysis, redaction, publication, audit, or disposition |
| Actor | Named person or attributable system |
| Date and time | Include time zone |
| Purpose | Reason action was authorized |
| Output | Derivative ID, location, size, and hash |
| Notes | Errors, anomalies, limitations, and approvals |
Transfer Receipt Template
Evidence ID:
Description:
Sender:
Recipient:
Purpose:
Transfer method:
Date and time sent with time zone:
Filename or physical item count:
Byte size or physical condition before transfer:
Hash algorithm and value before transfer:
Date and time received with time zone:
Byte size or physical condition after receipt:
Hash algorithm and value after receipt:
Mismatch, damage, or missing component:
New controlled storage location:
Sender confirmation:
Recipient confirmation:
Publication Review Checklist
- The evidence ID is correct
- The public use copy maps to the preservation master
- The source URL and release context were preserved
- File integrity was checked
- Official identifiers and page references were verified
- The correct derivative was approved
- Redactions were checked on the actual published file
- Hidden text, layers, metadata, and filenames do not expose protected information
- OCR and transcription were compared with the source
- Conversion or enhancement is disclosed
- Authentication status is accurate
- Custody gaps are disclosed
- The article distinguishes record appearance from proof of misconduct
- Direct Epstein Data, DOJ, court, or agency links are embedded
- The source list includes the primary record
- The final download and social preview were tested
- Publication date, reviewer, approver, and published hash were logged
Common Failures
Renaming before intake. The original filename and context disappear.
Editing the only copy. There is no unchanged reference for comparison.
Treating a screenshot as the document. The surrounding pages, metadata, and source may be lost.
Hashing after conversion only. The received bytes were never recorded.
Calling a hash proof of authenticity. File identity is confused with origin and truth.
Flattening a batch. Folder relationships and release structure vanish.
Using shared accounts. Access cannot be attributed.
Uploading to an AI or conversion service without approval. Evidence and private data leave controlled custody.
Correcting OCR silently. Readers cannot tell machine output from reviewed transcription.
Publishing the master. Sensitive metadata or unredacted content may escape.
Repairing a gap with memory. The record becomes cleaner than reality.
Keeping everything. Unnecessary sensitive retention becomes its own risk.
Frequently Asked Questions
Does every public PDF need a full custody log?
Every item needs enough provenance to reproduce the source. Consequential, disputed, sensitive, or transformed evidence requires the full protocol. Routine public records may use automated intake fields, but the source URL, access time, filename, size, hash, identifier, and storage location should still be preserved.
Can I rename a file so people understand it?
Keep the original filename in the intake record and preservation storage. A derivative may use a clearer controlled filename that includes the evidence ID.
Is downloading from DOJ enough to prove authenticity?
It strongly supports official provenance when the file and source context are preserved. It does not prove every statement within the document or eliminate the possibility of an incomplete production.
Can I use an online OCR or AI tool?
Not unless the transfer is approved for that evidence classification and documented. Public records may still contain private data. Restricted evidence must not be uploaded to an unapproved service.
What if two copies look identical but have different hashes?
Preserve both. Differences may come from metadata, compression, linearization, page rotation, hidden objects, or substantive changes. Compare them with appropriate tools and document the result.
What if the chain before EpsteinWiki is unknown?
State the earliest known source and mark the earlier chain as unknown. Seek corroboration. Do not invent continuity.
Can a broken chain still support an article?
Sometimes, with clear limitations and independent corroboration. The editorial weight must match the confidence in provenance and content.
Should a hash be published?
It can help identify a public file or release. Do not publish a hash if doing so creates a safety, legal, or prohibited content issue. Internal recording is normally sufficient for restricted evidence.
Related EpsteinWiki Policies and Guides
- Evidence Handling 101
- How to Read an Epstein Document
- Editorial Standards
- Moderation & Flagging Protocols
- Contributor Instructions
- Contributor Onboarding Guide
- Handling Sensitive Material
- Handling Contradictory Evidence
- Document Redaction Integrity
- Disinfo & Manipulated Media Guide
- Trauma-Informed Writing Toolkit
- Privacy Safeguards for Minors
- Digital Safety for EpsteinWiki Contributors & Researchers
External Standards and Resources
- NIST Digital Evidence Preservation: Considerations for Evidence Handlers
- NIST Digital Evidence Program
- NIJ Forensic Examination of Digital Evidence
- National Archives Digital Preservation Program
- National Archives Digital Preservation Framework
- DOJ Epstein Library
- Epstein Data
- CourtListener
- NCMEC CyberTipline
Closing Principle
Evidence does not become trustworthy because it has been copied many times. It becomes usable when its origin, condition, handling, limitations, and meaning can be examined.
EpsteinWiki’s responsibility begins at the moment an item reaches the project. From that point forward, every change should be deliberate, every transfer attributable, every derivative traceable, and every uncertainty visible. The archive should be able to show not only what it published, but how the record survived the journey.
Preserve the original. Document the path. Separate integrity from authenticity. Say exactly what the evidence can carry.
Editorial Note
This protocol is a living policy. It should be reviewed after any evidence integrity incident, storage migration, major import, material change in preservation standards, or recurring custody failure.
Suggested review cycle: At least annually, with fixity and access audits performed on a documented schedule.
Policy owner: EpsteinWiki editorial leadership and designated evidence custodian.
Applies to: Contributors, researchers, editors, moderators, administrators, contractors, and official EpsteinWiki systems.
This protocol provides editorial and archival guidance. It is not legal advice, a forensic laboratory standard, or a guarantee of admissibility in any legal proceeding.