TrueScreen Forensic Browser
Capture, analyse and certify
any online content.
Turn any page, video or file into evidence nobody can dispute, and find out where its content really came from. No forensic expertise needed.
Evidence built to survive cross-examination
You walk away with a record nobody can dismiss: what was on screen, when, from where, and untouched since. It holds because the capture happens in a controlled environment and is sealed the moment the session closes, never reconstructed afterwards.
Capture only what you need, or everything
Targeted capture keeps the package lean: you decide what becomes evidence, shot by shot.
Full recording captures audio and video of the entire session, so nothing has to be rebuilt from memory later.
Prove what a page showed in another country
Content is served differently depending on where you are, so proving it from your own desk proves the wrong thing. The session is routed through an exit point in the country you choose, and that point of observation is verified and written into the record.
Page snapshots
Rendered screenshot, live DOM source and a full MHTML archive with the page assets.
Continuous video and audio
Session video at 20 fps, with audio taken from the browser process, not the microphone.
Certified downloads
Files and videos fetched from the page, hashed with SHA-256 and SHA-512, bound to the chain.
All network traffic
Full HTTP archive (HAR) with request and response headers, plus raw packet capture (PCAP).
Proved time
Dual timestamps checked against multiple NTP servers, with clock drift measured and recorded.
Hardened environment
DevTools disabled, code injection blocked, debugging flags refused, app files hashed at startup.
Tamper-evident chain
Each step hashed as sha256(previous | step | timestamp | data), so any alteration breaks the chain.
Network transparency
VPN, proxy and Tor exit detection, TLS interception checks and certificate pinning, in the audit log.
Virtual machine detection
Virtualised environments identified and recorded in the session metadata.
Geo-routed capture
Exit points in 80+ countries, with the resulting IP and geolocation verified.
Live source analysis
The rendered DOM hashed next to the HTML fetched independently from the server.
Operator declaration
A signed operator statement, hashed with the session and stored in the package.
Know what you are looking at
Two questions on every file you capture: was it made by AI, and where did it come from. Images, video and audio are scored for AI generation and read for their origin records.
Detect content generated with AI
Acting on a fake costs as much as dismissing something real. Manipulated faces, generated video, synthetic voice and AI images are each scored separately, and the model behind them named where it can be recognised.
Every marker carries its probability, so you can weigh it instead of trusting a verdict.
Find out where the content came from
Digital provenance: what the file records about its own origin. C2PA content credentials, the IPTC digital source field and the generator tags left in EXIF and XMP are read and reported as found, independently of the AI score.
Deepfake detection
Face manipulation and AI video generation, scored per file.
Synthetic voice and audio
Generated speech and music, in audio files and video soundtracks.
Generated images
Images scored for AI generation, with the model named where possible.
Media inventory
Media from the DOM and network traffic, with real size, MIME type and dimensions.
Fingerprints on inspection
SHA-256 and MD5 on the fetched bytes, next to the source URL.
Declared format vs real format
Format read from the file header, compared with the declared Content-Type.
C2PA content credentials
The signed C2PA manifest and its assertions, when present.
IPTC digital source
The IPTC digitalSourceType field: captured, composite or trained-algorithmic.
Generator signatures
Generator and software tags in EXIF, XMP and container metadata.
Stated limits
Binary documents are marked not applicable, never as matching.
Separate from the evidence
Inspection sits outside the acquisition and changes nothing.
Certify what you inspect
Any analysed file can be pulled into the package and sealed with the session.
A report you can hand over without explaining it
Evidence is only worth what someone else can verify on their own. The session closes into a certified report and a complete archive, sealed under eIDAS, so a court or a regulator can check every claim in it without taking your word for anything.
One technical report, certified end to end
Everything captured and everything the analysis found ends up in a single technical report: hashes, times, network data, point of observation and AI results. It carries a qualified seal, so it holds legal value and goes to a court or a counterpart exactly as it is.
Sealed, stored, and ready to send
The sealed package is stored on European infrastructure. You get an identifier you can share, and the full archive stays retrievable the moment anyone asks for it.
Qualified seal
XAdES seal and qualified timestamp from a QTSP under eIDAS, binding the JSON record and the PDF.
Certified report
A PDF stating what was captured, when, from where, by whom and with which hashes, ready to file.
Complete archive
Screenshots, page sources, MHTML, files, media and logs, exactly as collected.
Recomputable chain
The chain and its formula ship inside the package, verifiable without our software.
Report identifier
A shareable identifier per certification, with the package retrievable from the TrueScreen cloud.
Audit trail
Every action logged in order, from the operator declaration to the final seal.
EU data residency
Packages stored on European cloud infrastructure, under GDPR.
Forensic method
Acquisition, identification and preservation following ISO/IEC 27037.
What professionals use it for
Lawyers, investigators, journalists, brand protection, HR and compliance teams use it to get there first.
01
IP and brand protection
Capture counterfeit listings and misuse of your brand assets before infringers take them down.
02
Defamation and harassment
Preserve defamatory posts, threats and cyberbullying from any website or social platform.
03
Social media
Certify posts, comments, profiles and stories exactly as the platform served them, before they are edited or deleted.
04
Chat and messaging
Capture a conversation from its web client, message by message, with the timestamps and the account it was read from.
05
Litigation and disputes
Certified web evidence for contract disputes and regulatory investigations, with full chain of custody.
06
Fraud investigations
Document fraudulent sites, phishing pages and scam listings with verified timestamps.
07
Deepfakes and synthetic media
Check a video, a voice note or a photo for AI generation before you act on it.
08
Journalism and fact-checking
Preserve a source and check its media before publication, so the story holds when it is challenged afterwards.
09
Insurance claims
Capture listings, damage reports and third-party statements as certified evidence on a claim.
10
Content that will not last
Download and certify a social video before it is deleted, with its own hash and timestamp.
11
Certified downloads
Preserve a document, invoice or report with proof of its source and the moment of capture.
Scroll to move through the cases →
Frequently Asked Questions
What professionals ask before their first session.
Can it tell me if a video is a deepfake or an image was made by AI?
Does analysing a file change the evidence?
Why should I use Forensic Browser instead of a regular screenshot?
Will this evidence be accepted in court?
Do I need technical expertise to use it?
How is it different from a browser extension?
What do I receive after a certification session?
Stop losing evidence.
Join 20,000+ professionals who turn volatile web content into certified evidence with full legal value.
