Resource · Evidence and audit
Evidence pack template
What a dated copy of a vendor page has to carry to be worth anything, and one real pack assembled from the record.
Why a screenshot is not enough
A screenshot is a picture of a claim. It shows what somebody says a page said, and the person you are showing it to has only your word for when it was taken.
What turns a reading into evidence is that someone with no interest in the answer attested to the time. Each sweep writes a manifest of hash-and-URL lines, hashes the manifest, and sends that hash to a timestamp authority, which returns a signed token under RFC 3161. The token proves the manifest existed then; the manifest proves those hashes were in it; the hashes prove the content.
The eight sections
The order is an argument. Identity, then the two readings, then the raw difference, and only then our reading of it — a pack that leads with the finding asks to be believed before it has shown anything.
1. What is being evidenced
The vendor, the document, its URL, and the obligation of yours it touches.
A pack with no subject is a folder. The first question is always what this is about, and the second is why it was yours to watch.
2. The two readings
For each: the date and time, the HTTP status, which fetch layer returned it, the URL it finally resolved to, and the hash of the content.
The status and the final URL are what separate a page that changed from a page that moved. A redirect chain ending somewhere else is a different document, not a new version.
3. What differs, verbatim
Every added and removed line between the two readings, unedited.
The pack has to survive someone disagreeing with our reading. An unedited diff is the only part of it that does not depend on us being right.
4. What moved in the record
The facts our extractor read as added, removed or changed — labeled as our reading, kept apart from section 3.
These are two different kinds of statement. A line moved is what the page did; a fact moved is what we made of it. Merging them invites a reader to take the second on the authority of the first.
5. The archived copies
The stored PDF of each reading, with its own SHA-256, byte size and capture time.
A hash proves two things are identical and nothing about what they say. The copy is what a reader opens; the hash is what ties it to this pack.
6. The third-party timestamp
The sweep manifest each reading appears in, the manifest's SHA-256, and the RFC 3161 token a timestamp authority signed over that hash.
Everything above this line is our word. A signed token from a party with no interest in the answer is the section that makes the pack evidence rather than a record.
7. What this does not prove
Stated plainly: what a pack of this kind cannot establish.
A pack that claims more than it holds loses on the first challenge. Naming the limits is what lets the rest stand.
8. Who assembled it, when, and how to check
The date the pack was generated, the method, and the URL to verify it against the live record.
A pack is a copy of a moment. Saying so is the difference between a document that ages honestly and one that quietly misleads.
A real pack · Replit
Selected by measuring rather than chosen: the recorded change with both readings archived, a sub-processor movement, and the shortest difference — so it is a real pack that fits on a page.
- Document
- subprocessors page
- Lines
- 6 added, 2 removed
Before
- Read at
- 2026-09-07 05:15:15 UTC
- HTTP status
- 200
- Resolved to
- https://replit.com/subprocessors
- Content SHA-256
- 2e765024b689cc41…
- Archived copy
- PDF, 126 KB, SHA-256 4dfcf079f9b4ecec…, captured 2026-09-07 05:53:49 UTC
- Timestamped in
- manifest eb0257201942b52b… (338 readings), signed 2026-09-07 05:16:51 UTC
After
- Read at
- 2026-09-11 00:37:12 UTC
- HTTP status
- 200
- Resolved to
- https://replit.com/subprocessors
- Content SHA-256
- 8e2d22c01043c450…
- Archived copy
- PDF, 126 KB, SHA-256 12c5a3d60f5f10dd…, captured 2026-09-11 05:17:49 UTC
- Timestamped in
- manifest 941cd21f14b46a44… (67 readings), signed 2026-09-11 00:39:23 UTC
What differs, verbatim
Unedited. This is the part of the pack that does not depend on our reading being right.
Cloud monitoring |+ SideGuide Technologies, Inc. d/b/a Firecrawl |+ USA |+ Web data extraction for AI applications | Stripe | USA |… Company- [About Us](/about)[News](/news)[Careers](/careers)[Brand Center](/brand)[Contact Us](/enterprise)+ [About](/about)[News](/news)[Careers](/careers)[Brand Center](/brand)[Contact Us](/enterprise) Social- [Twitter/X](https://x.com/replit)[YouTube](https://www.youtube.com/@replit)[Linkedin](https://www.linkedin.com/company/repl-it/)[Instagram](https://www.instagram.com/replit)[Facebook](https://www.facebook.com/replit/)[Tiktok](https://www.tiktok.com/@replit)+ [X / Twitter](https://x.com/replit)[YouTube](https://www.youtube.com/@replit)[Linkedin](https://www.linkedin.com/company/repl-it/)[Instagram](https://www.instagram.com/replit)[Facebook](https://www.facebook.com/replit/)[TikTok](https://www.tiktok.com/@replit)
What moved in the record
Our reading of the difference above, kept separate from it. A line moved is what the page did; a fact moved is what we made of it.
| Fact | Movement | Before | After |
|---|---|---|---|
| subprocessor | added | — | SideGuide Technologies, Inc. d/b/a Firecrawl · Web data extraction for AI applications · USA |
The same difference carries a footer link renamed and a social handle relabeled. The page changed in three places and one of them is a fact, which is why the pack shows both and why an alert is decided on the fact rather than the line.
What a pack of this kind does not prove
A pack that claims more than it holds loses on the first challenge. Naming the limits is what lets the rest stand.
- That the vendor served this page to everyone. It is what the URL returned to our reader, at that time, from where it fetched.
- That the change happened on the date we recorded. It happened at some point between the two readings, and the pack states both.
- That the vendor did or did not send notice. The pack evidences a page; whether an email went out is a separate question.
- That nothing else changed. A pack covers the pages we read, and a gap in the reading is a gap in the pack rather than a quiet week.
- What the change means. The pack quotes and hashes; the reading of it is the reader's, or their counsel's.
How much of the record is covered
1,220 of 2,481 readings are held as an archived copy, and 416 of 1228 recorded changes have both readings archived. 26 sweep manifests carry a signed timestamp token.
A reading with no archived copy still carries its content hash, its fetch time and its status; what it lacks is the file a reader can open. Stated rather than omitted, because a coverage figure printed without its gap reads as complete.
Take it with you
The eight sections and the worked pack as a Word document. It is generated when you download it, so the pack inside is the one the record holds that day.
How this was assembled
The sections are written. Everything in the worked pack is read from stored rows: the two readings and their hashes, the difference between them as recorded, the fact movements our extractor wrote, the archived copies, and the timestamped manifests each reading appears in. How the record is kept.
Common questions
- What is an evidence pack?
- A dated, hashed record of what a page said before and after it changed, assembled so somebody else can check it. Two readings with their times and content hashes, the verbatim difference, the archived copies, and a third-party timestamp over the whole reading.
- Why is a screenshot not enough?
- A screenshot shows what somebody says a page said, and the person you show it to has only your word for when it was taken. Nothing in the image ties it to a time that a party with no interest in the answer will vouch for.
- What is an RFC 3161 timestamp?
- A signed token from a timestamp authority attesting that a given hash existed at a given moment. Each sweep hashes a manifest of the readings it took and has that hash signed, so the time on a reading does not rest on our own clock.
- Does an evidence pack prove the vendor changed the page on a particular date?
- No. It proves the page said one thing at the first reading and another at the second. The change happened somewhere between them, and the pack states both times rather than picking one.
- Why does the pack include the raw difference and not just the finding?
- They are two different kinds of statement. A line moved is what the page did; a fact moved is what we made of it. A pack showing only the second asks a reader to take our reading on trust, and it has to survive someone disagreeing with it.
Evidence and audit
Prove what a page said, and when.
- Vendor onboarding: day-one capture
What to capture and what to ask on day one — five of the ten answers worth having are published by fewer than a fifth of vendors.
This is not legal advice, and whether a pack of this shape is accepted depends on who is asking and why. The readings shown are pages we fetched on the dates stated; naming a vendor here records what its page said and implies nothing else about it. The record is free to read, and corrections are free to request.