Forensic Capture of Password-Protected Web Pages: Portals and Private Areas
Most of the digital evidence a business actually needs is not sitting on a public page. It lives inside a supplier portal, a customer area, an e-procurement platform, an internal board, a business system, an online banking interface. Screens that exist only for whoever holds the credentials to open them. A screenshot of one of those screens produces a file no outside party can compare against the original, so a challenge to its conformity is cheap to raise, and the usual objections to a screenshot land immediately. The forensic capture of password-protected pages gets around this by moving the evidentiary weight somewhere else: not onto the reproducibility of the page, which disappears with the session, but onto the verifiability of the act of capture. The method is the one set out in our guide to web evidence acquisition under ISO/IEC 27037, applied to the case where nobody else can open the page at all.
This insight is part of our guide: Web Evidence Acquisition and ISO/IEC 27037
Why a password-protected page is harder to prove than a public one
A password-protected page is a resource the server renders only for an authenticated user, so no copy of it exists anywhere an outside party can consult. That single fact changes the evidentiary regime. When a public page is disputed, an expert reopens the address and compares. Behind a login nobody can do that except the account holder, so the objection almost writes itself: what you produced is not what the portal showed. Under Regulation (EU) 910/2014 (eIDAS), the presumptions that answer that objection do not come from the page at all. Article 35(2) attaches a presumption of integrity and of correctness of origin to data carried by a qualified electronic seal, and Article 41(2) attaches a presumption of accuracy of the date and time indicated by a qualified electronic timestamp. Neither one depends on anybody being able to reach the resource again.
The conformity challenge and the page nobody can reopen
Unlike a public page, a resource behind authentication is unreachable by any crawler, so public web archives are no fallback here. The Internet Archive and similar public crawlers collect only what can be fetched without signing in. The page never entered a snapshot and never will. Its absence proves nothing about whether the content existed, which is why the limits of the Wayback Machine as web evidence bite twice as hard behind credentials. Search the archive, find nothing, and you have learned nothing. Printing the screen changes nothing either. A plain screenshot carries no verified time, no cryptographic binding to the content and no record of the session that produced it. On a public page those gaps can be closed later by anyone who reopens the address. On a private one they stay open, and the party running the portal is the only one in a position to close them.
Where business evidence actually lives
Look at where commercial disputes now start. Tender documents, clarifications and exclusion notices sit on e-procurement platforms. Order confirmations and price lists sit in supplier areas. Personnel announcements sit on intranet boards that get edited without leaving any public trace. Italy's national anti-corruption authority reported in its April 2026 annual review that paper-based procurement procedures had fallen from 21% to 1% in two years. Whatever the market, the pattern holds: the facts that decide a case are increasingly facts only one party can see.
What an authenticated session capture must contain
A forensic capture of a page behind credentials has to record five things a public capture never needs: the navigation chain starting at the login screen, evidence that the operator was entitled to reach the resource, the network address the session ran from, the state of the session itself, and the verified moment the content was sealed. Behind a login the same URL returns different content to different users, so the address on its own establishes almost nothing, and a capture that shows only the final screen leaves every one of those gaps open. What gets contested in court is rarely the pixels. It is who was looking, from where, as whom, and when. Each element on that list answers one of those questions, and the verified moment is the one a qualified electronic timestamp under eIDAS settles.
The technical elements that make the difference
The table isolates the delta against a public capture. Hashing, timestamping and web archiving are needed in both cases and covered in the parent guide.
| Session element | On a public page | What it establishes behind a login |
|---|---|---|
| Navigation chain from the login screen | The address is enough | That the screen was reached through authentication, with the real sequence of requests |
| Entitlement to access | Anyone can reach the page | That the person capturing was authorized to see that content |
| Operator's network address | Immaterial | Where the session ran from, and whether a VPN or proxy was in use |
| Session state | There is no session | Which account was logged in, under which profile, with which active cookies |
| Client user agent | Marginal | How the portal rendered the page for that client, which explains rendering differences |
Auditability, repeatability and reproducibility applied to a non-public page
Reproducibility in a private area does not mean a third party has to be able to log in again. ENISA guidance on electronic evidence for first responders asks that an audit trail of every process applied to digital evidence be created and preserved, so that an independent third party can examine those actions and achieve the same result. Behind an authentication screen, the principle shifts from the object to the act. The expert does not reopen the portal. The expert re-runs the verification on the package, checks that the cryptographic hashes still match and that the seal is intact, and gets the same result years later. That is the methodological frame of ISO/IEC 27037 on the identification, collection, acquisition and preservation of digital evidence, which our guide to acquiring web evidence to a forensic standard unpacks in full. Capture runs on the device of the person who holds the access, so credentials never have to be handed to anyone else.
What a certified authenticated session capture produces
TrueScreen, the Data Authenticity Platform, captures the page inside the authenticated session of the user entitled to access it and seals it at the moment of capture. The operator opens the forensic browser, signs in with their own legitimate credentials and navigates to the screen that matters. Every step enters the session audit trail with a time verified against several independent NTP servers, and every screen gets its own cryptographic hash. The finished package holds the images, the page DOM, a web archive, the network traffic and the certificates of the sites visited, and a Qualified Trust Service Provider seals and timestamps it under eIDAS. Any later alteration becomes detectable, which makes a generic challenge significantly harder to sustain. Choosing among forensic web capture software largely comes down to whether the tool documents the session or only the final screen.
A supplier portal and an intranet board
A supplier signs in to a customer's portal and finds the commercial terms of an accepted order different from what was on screen at confirmation. Nobody else can see that page. Organizations use TrueScreen to preserve terms published in a supplier portal before they are changed, producing a package a third party can verify without repeating the login. What goes into the file is the path from the login screen to the order, not an isolated picture.
The second pattern is internal. A notice posted on a company board, relevant to an employment dispute, comes down the following day. No public archive ever saw it. Whoever read it can capture it inside their authenticated session while it is still online and keep a dated, sealed package that outlives the removal. Wait until the next morning and there is nothing left to capture.
