Sealing and imaging of devices.
Sealing and Imaging of Devices
Sealing and imaging of devices are important procedures in digital investigations, disciplinary inquiries, internal investigations, litigation and criminal investigations. They are intended to preserve electronic evidence in a manner that protects its integrity, authenticity, continuity and admissibility.
Devices may include:
- computers and laptops;
- mobile phones;
- tablets;
- hard drives and SSDs;
- USB drives and memory cards;
- servers;
- DVR/CCTV systems;
- cloud-connected storage;
- wearable devices; and
- other digital storage media.
The central principle is that investigators should preserve the device and its data without unnecessarily altering the original evidence.
1. Meaning of sealing
Sealing means securing a physical electronic device or storage medium after it has been collected so that it cannot be accessed, substituted, damaged or tampered with without detection.
For example, after collecting an employee's laptop:
- the laptop is identified;
- its condition is documented;
- relevant identifying information is recorded;
- it is placed in suitable protective packaging;
- the package is sealed;
- the seal is marked or uniquely identified;
- custody of the device is recorded.
The purpose is to establish that the physical device examined later is the same device that was originally collected.
2. Meaning of forensic imaging
Forensic imaging means creating a forensic copy of a digital storage medium, normally sector-by-sector, so that investigators can analyse the copy instead of repeatedly working on the original.
For example:
Original laptop hard drive → forensic image → analysis
The original drive is preserved while investigators work on the forensic copy.
A forensic image may contain:
- active files;
- deleted files;
- file-system metadata;
- unallocated space;
- hidden information; and
- other sectors that may not be visible through ordinary file-copying.
This makes forensic imaging different from simply copying selected documents.
3. Why sealing and imaging are important
Digital evidence is particularly vulnerable because it can be:
- modified merely by opening a file;
- deleted;
- overwritten;
- remotely accessed;
- encrypted;
- altered through system processes; or
- accidentally contaminated by investigators.
Therefore, the investigation should demonstrate:
What was collected → how it was collected → who possessed it → how it was preserved → how it was examined → whether the examined data corresponds to the original evidence.
This is commonly described through the concept of chain of custody.
4. Basic procedure for sealing a device
A sound procedure generally involves the following steps.
Step 1 — Identify the device
Record:
- device type;
- manufacturer;
- model;
- serial number;
- asset number;
- colour/physical description;
- storage capacity;
- SIM/IMEI details where relevant;
- condition of the device.
Step 2 — Photograph the device
Photographs can document:
- physical condition;
- screen display;
- cables;
- ports;
- labels;
- serial numbers; and
- visible damage.
Step 3 — Record circumstances of collection
The investigator should record:
- date and time;
- location;
- person from whom the device was obtained;
- person collecting it;
- reason for collection; and
- persons present.
Step 4 — Preserve the device
Depending on the circumstances, the device may need to be:
- powered down;
- isolated from networks;
- placed in suitable protective packaging; or
- kept powered on when volatile evidence is important.
The decision should be documented because shutting down a running computer or phone can itself destroy volatile evidence.
Step 5 — Seal
The device is placed in appropriate packaging and sealed.
The seal should be identifiable, and opening/resealing should be recorded.
5. Chain of custody
Chain of custody is one of the most important aspects of digital evidence.
A custody record should ideally identify:
| Information | Purpose |
|---|---|
| Exhibit number | Identifies evidence |
| Date/time collected | Establishes chronology |
| Collector | Establishes responsibility |
| Location | Establishes source |
| Seal number | Shows physical integrity |
| Transfer details | Records movement |
| Storage location | Shows preservation |
| Person receiving exhibit | Establishes continuity |
| Date/time of transfer | Creates audit trail |
| Condition of seal | Detects possible tampering |
An unexplained gap in custody can provide a basis for challenging the reliability of evidence.
However, a custody irregularity does not necessarily mean that the evidence is automatically inadmissible in every case. Courts examine the circumstances and the evidentiary foundation as a whole.
6. Creating a forensic image
A typical forensic imaging procedure involves:
A. Write protection
A write blocker may be used to prevent the forensic workstation from writing data onto the original storage medium.
B. Acquisition
The investigator creates a forensic image of the storage device.
C. Hash calculation
A cryptographic hash is calculated for the acquired data.
Common algorithms include:
- SHA-256;
- SHA-1; and
- MD5.
Modern forensic practice generally prefers stronger algorithms such as SHA-256.
D. Verification
The hash of the image can be compared with the relevant source hash or verified through the acquisition software and documented procedures.
E. Analysis of the copy
Investigators normally conduct examination on the forensic image rather than altering the original device.
7. Hash values and integrity
A hash value is effectively a digital fingerprint of data.
For example:
Original image → SHA-256 hash → ABC123...
If the underlying data changes, the hash will ordinarily change.
Thus:
Same data → same hash
and, subject to the characteristics and limitations of the algorithm:
Changed data → different hash
Hashing does not prove who created a file or whether its contents are truthful. Its principal function is to help demonstrate data integrity.
8. Imaging a mobile phone
Mobile-phone imaging is more complicated than imaging a traditional hard disk.
Investigators may encounter:
- device encryption;
- locked screens;
- secure enclaves;
- application-specific databases;
- cloud synchronisation;
- deleted messages;
- changing app data;
- SIM information;
- metadata;
- remote wiping.
Accordingly, the investigator should document:
- device state at collection;
- whether it was locked/unlocked;
- network connectivity;
- SIM status;
- extraction method;
- software/tool used;
- relevant version;
- extraction date and time; and
- integrity verification.
9. Cloud evidence
Sealing a physical device does not necessarily preserve all information associated with it.
For example, an employee's laptop may contain access to:
- Gmail;
- Microsoft 365;
- Google Drive;
- OneDrive;
- Dropbox;
- company databases; or
- messaging services.
Cloud evidence may therefore require separate preservation measures, such as legal holds, preservation requests, account logs or authorised acquisition.
The physical sealing of a laptop alone does not freeze information stored remotely.
10. Legal significance in India
Digital evidence in India is governed principally by the Bharatiya Sakshya Adhiniyam, 2023 (BSA), which replaced the Indian Evidence Act, 1872.
Electronic records can be admitted subject to the statutory requirements concerning electronic/digital records and their authentication.
The Information Technology Act, 2000 also remains important for electronic records and electronic evidence.
For investigations, therefore, the technical process and the statutory evidentiary requirements need to be considered together.
11. Important Case Laws
1. Anvar P.V. v. P.K. Basheer (2014)
The Supreme Court gave major importance to the statutory requirements governing electronic evidence under the then Section 65B of the Indian Evidence Act.
The Court held that electronic records could not simply be admitted through ordinary oral evidence where the statutory certificate requirement applied.
Relevance to imaging
A forensic image, extraction or electronic copy must be supported by the applicable evidentiary requirements. Merely saying that the data was taken from a computer is not necessarily sufficient.
Principle: The manner in which electronic evidence is produced and authenticated matters.
2. Arjun Panditrao Khotkar v. Kailash Kushanrao Gorantyal (2020)
The Supreme Court reaffirmed and clarified the principles concerning Section 65B certification of electronic evidence.
The Court explained when certification is required and the circumstances in which the requirement operates.
Relevance
Where investigators create forensic copies, extracted files, screenshots or other electronic outputs, the evidentiary foundation for those records must be properly established under the applicable law.
Principle: Electronic evidence requires appropriate statutory authentication; technical copying alone does not automatically establish admissibility.
3. Tomaso Bruno v. State of Uttar Pradesh (2015)
The Supreme Court emphasised the importance of electronic evidence such as CCTV footage in modern investigations.
The Court observed that scientific and electronic evidence can play a significant role in establishing facts.
Relevance to imaging
CCTV systems and electronic storage devices should be preserved promptly because digital data may be overwritten.
Proper preservation, copying and documentation can therefore become critical.
Principle: Investigators should not ignore available electronic evidence, particularly where it may objectively establish events.
4. Shafhi Mohammad v. State of Himachal Pradesh (2018)
The Supreme Court addressed aspects of electronic evidence and the requirement of a certificate under the then Section 65B.
The decision recognised difficulties that parties may face when electronic devices or systems are controlled by another person or entity.
Relevance
In digital investigations, the party possessing the original device or system may have greater control over the technical information needed to establish authenticity.
Principle: Courts have to consider the practical circumstances surrounding access to electronic evidence and its certification.
5. Sonu @ Amar v. State of Haryana (2017)
The Supreme Court considered objections concerning the manner in which electronic evidence was introduced.
The case illustrates the importance of raising evidentiary objections at the appropriate stage.
Relevance
Challenges to the collection, certification or production of digital evidence should be properly identified and raised rather than being treated as purely technical matters at a much later stage.
Principle: Procedural objections concerning evidence can have significant consequences depending on when and how they are raised.
6. State (NCT of Delhi) v. Navjot Sandhu (2005)
The Supreme Court considered electronic records in the context of the Parliament attack case and examined the evidentiary treatment of computer-generated records.
Although later decisions clarified the statutory approach to electronic evidence, the case remains historically important in the development of Indian electronic-evidence jurisprudence.
Relevance
It demonstrates the evolution of Indian law concerning the authenticity and evidentiary use of computer-generated material.
7. P. Gopalakrishnan @ Dileep v. State of Kerala (2020)
The Supreme Court considered access to electronic material, including digital evidence, in criminal proceedings.
The case is important because electronic evidence can contain extensive information and may raise questions involving privacy, confidentiality and fair trial rights.
Relevance
Preserving an electronic device does not mean that every piece of information contained on it can automatically be disclosed to every person. Access must be controlled according to applicable law.
12. Sealing vs imaging
| Sealing | Imaging |
|---|---|
| Protects the physical device | Creates a forensic copy |
| Primarily establishes physical integrity | Primarily facilitates examination and digital preservation |
| Uses packaging/seals | Uses forensic acquisition techniques |
| Prevents unauthorised access/substitution | Allows analysis without repeatedly altering original |
| Creates physical chain of custody | Creates digital integrity record |
| Relevant to original exhibit | Relevant to working forensic copy |
Both procedures complement each other.
13. Common mistakes
Mistake 1 — Simply copying files
Dragging files from a laptop to a USB drive is not necessarily a forensic image.
It may omit:
- deleted data;
- metadata;
- unallocated space;
- hidden files; and
- other forensic information.
Mistake 2 — Working directly on the original
Repeatedly opening or modifying files on the original device can alter timestamps and other metadata.
Mistake 3 — No hash calculation
Without appropriate integrity verification, it becomes more difficult to demonstrate that the forensic copy remained unchanged.
Mistake 4 — Poor chain of custody
If nobody records who possessed the device between collection and examination, authenticity can be challenged.
Mistake 5 — Breaking the seal without documentation
An unexplained broken seal creates an obvious integrity issue.
Mistake 6 — Ignoring volatile data
Immediately switching off a running computer may cause loss of:
- RAM contents;
- active network connections;
- encryption keys;
- running processes; and
- other volatile information.
The appropriate approach depends upon the investigative objective.
14. Workplace investigations
Sealing and imaging are also relevant to employee misconduct investigations.
For example, if an employee is suspected of:
- unauthorised data copying;
- deletion of company files;
- intellectual-property theft;
- manipulation of records;
- unauthorised access; or
- violation of company IT policy,
the employer may preserve the relevant company device.
A defensible procedure would generally include:
Device identification → authorisation → collection → documentation → isolation → sealing → forensic imaging → hashing → analysis → report → preservation
The employer should also consider:
- employee privacy;
- applicable employment policies;
- data-protection requirements;
- privilege;
- proportionality; and
- whether personal data is mixed with business information.
15. Conclusion
Sealing and imaging are complementary evidence-preservation procedures. Sealing protects the physical integrity and continuity of the original device, while forensic imaging creates a controlled copy that can be examined without unnecessarily altering the original evidence.
For legally defensible digital evidence, investigators should maintain a clear chain of custody, document the collection process, use appropriate forensic acquisition methods, preserve the original device, calculate and record integrity hashes where appropriate, and comply with the applicable rules governing electronic evidence.
The Indian case law—particularly Anvar P.V., Arjun Panditrao Khotkar, Tomaso Bruno, Shafhi Mohammad, Sonu @ Amar, Navjot Sandhu and P. Gopalakrishnan—shows that courts pay significant attention to the authenticity, integrity, preservation and lawful production of electronic evidence.

comments