TrueScreen Forensic Browser

Capture, analyse and certify
any online content.

Turn any page, video or file into evidence nobody can dispute, and find out where its content really came from. No forensic expertise needed.

SESSION · live captureSHA-256 223061161c6a…df01d7C2PA · IPTC digital source✓ eIDAS qualified timestampsISO/IEC 27037GEO-ROUTING · 80+ countriesAI DETECTION · deepfake and genAITrueScreen Forensic Browser home screen on macOS

Forensic acquisition

Evidence built to survive cross-examination

You walk away with a record nobody can dismiss: what was on screen, when, from where, and untouched since. It holds because the capture happens in a controlled environment and is sealed the moment the session closes, never reconstructed afterwards.

Capture only what you need, or everything

Targeted capture keeps the package lean: you decide what becomes evidence, shot by shot.

Full recording captures audio and video of the entire session, so nothing has to be rebuilt from memory later.

Choosing the capture mode at the start of a session

Prove what a page showed in another country

Content is served differently depending on where you are, so proving it from your own desk proves the wrong thing. The session is routed through an exit point in the country you choose, and that point of observation is verified and written into the record.

Exit points available across the world map
What the acquisition records

Page snapshots

Rendered screenshot, live DOM source and a full MHTML archive with the page assets.

Continuous video and audio

Session video at 20 fps, with audio taken from the browser process, not the microphone.

Certified downloads

Files and videos fetched from the page, hashed with SHA-256 and SHA-512, bound to the chain.

All network traffic

Full HTTP archive (HAR) with request and response headers, plus raw packet capture (PCAP).

Proved time

Dual timestamps checked against multiple NTP servers, with clock drift measured and recorded.

Hardened environment

DevTools disabled, code injection blocked, debugging flags refused, app files hashed at startup.

Tamper-evident chain

Each step hashed as sha256(previous | step | timestamp | data), so any alteration breaks the chain.

Network transparency

VPN, proxy and Tor exit detection, TLS interception checks and certificate pinning, in the audit log.

Virtual machine detection

Virtualised environments identified and recorded in the session metadata.

Geo-routed capture

Exit points in 80+ countries, with the resulting IP and geolocation verified.

Live source analysis

The rendered DOM hashed next to the HTML fetched independently from the server.

Operator declaration

A signed operator statement, hashed with the session and stored in the package.

Analysis

Know what you are looking at

Two questions on every file you capture: was it made by AI, and where did it come from. Images, video and audio are scored for AI generation and read for their origin records.

Detect content generated with AI

Acting on a fake costs as much as dismissing something real. Manipulated faces, generated video, synthetic voice and AI images are each scored separately, and the model behind them named where it can be recognised.

Every marker carries its probability, so you can weigh it instead of trusting a verdict.

AI analysis of a video, with each marker and its probability

Find out where the content came from

Digital provenance: what the file records about its own origin. C2PA content credentials, the IPTC digital source field and the generator tags left in EXIF and XMP are read and reported as found, independently of the AI score.

Origin and watermark checks on an analysed image
What the analysis reads

Deepfake detection

Face manipulation and AI video generation, scored per file.

Synthetic voice and audio

Generated speech and music, in audio files and video soundtracks.

Generated images

Images scored for AI generation, with the model named where possible.

Media inventory

Media from the DOM and network traffic, with real size, MIME type and dimensions.

Fingerprints on inspection

SHA-256 and MD5 on the fetched bytes, next to the source URL.

Declared format vs real format

Format read from the file header, compared with the declared Content-Type.

C2PA content credentials

The signed C2PA manifest and its assertions, when present.

IPTC digital source

The IPTC digitalSourceType field: captured, composite or trained-algorithmic.

Generator signatures

Generator and software tags in EXIF, XMP and container metadata.

Stated limits

Binary documents are marked not applicable, never as matching.

Separate from the evidence

Inspection sits outside the acquisition and changes nothing.

Certify what you inspect

Any analysed file can be pulled into the package and sealed with the session.

Certified reporting

A report you can hand over without explaining it

Evidence is only worth what someone else can verify on their own. The session closes into a certified report and a complete archive, sealed under eIDAS, so a court or a regulator can check every claim in it without taking your word for anything.

One technical report, certified end to end

Everything captured and everything the analysis found ends up in a single technical report: hashes, times, network data, point of observation and AI results. It carries a qualified seal, so it holds legal value and goes to a court or a counterpart exactly as it is.

Certified technical report of a forensic acquisition session

Sealed, stored, and ready to send

The sealed package is stored on European infrastructure. You get an identifier you can share, and the full archive stays retrievable the moment anyone asks for it.

Certification completed, with the report identifier
What you receive

Qualified seal

XAdES seal and qualified timestamp from a QTSP under eIDAS, binding the JSON record and the PDF.

Certified report

A PDF stating what was captured, when, from where, by whom and with which hashes, ready to file.

Complete archive

Screenshots, page sources, MHTML, files, media and logs, exactly as collected.

Recomputable chain

The chain and its formula ship inside the package, verifiable without our software.

Report identifier

A shareable identifier per certification, with the package retrievable from the TrueScreen cloud.

Audit trail

Every action logged in order, from the operator declaration to the final seal.

EU data residency

Packages stored on European cloud infrastructure, under GDPR.

Forensic method

Acquisition, identification and preservation following ISO/IEC 27037.

Use cases

What professionals use it for

Lawyers, investigators, journalists, brand protection, HR and compliance teams use it to get there first.

IP and brand protection

01

IP and brand protection

Capture counterfeit listings and misuse of your brand assets before infringers take them down.

Defamation and harassment

02

Defamation and harassment

Preserve defamatory posts, threats and cyberbullying from any website or social platform.

Social media evidence

03

Social media

Certify posts, comments, profiles and stories exactly as the platform served them, before they are edited or deleted.

Chat and messaging evidence

04

Chat and messaging

Capture a conversation from its web client, message by message, with the timestamps and the account it was read from.

Litigation and disputes

05

Litigation and disputes

Certified web evidence for contract disputes and regulatory investigations, with full chain of custody.

Fraud investigations

06

Fraud investigations

Document fraudulent sites, phishing pages and scam listings with verified timestamps.

Deepfakes and synthetic media

07

Deepfakes and synthetic media

Check a video, a voice note or a photo for AI generation before you act on it.

Journalism and fact-checking

08

Journalism and fact-checking

Preserve a source and check its media before publication, so the story holds when it is challenged afterwards.

Insurance claims

09

Insurance claims

Capture listings, damage reports and third-party statements as certified evidence on a claim.

Ephemeral content

10

Content that will not last

Download and certify a social video before it is deleted, with its own hash and timestamp.

Certified downloads

11

Certified downloads

Preserve a document, invoice or report with proof of its source and the moment of capture.

Scroll to move through the cases →


FAQ

Frequently Asked Questions

What professionals ask before their first session.

Can it tell me if a video is a deepfake or an image was made by AI?
Yes. Images, video and audio are checked for AI generation and manipulation: a swapped face, a generated video, a synthetic voice, an image produced by a model, and where the engine can name it, the model itself. Each marker carries its estimated probability. The app also reads what the file declares about its origin: C2PA content credentials, the IPTC digital source field and generator signatures. The result is a technical opinion, recorded alongside the evidence.
Does analysing a file change the evidence?
No. Opening a file’s details reads its data and origin records without touching the capture. Nothing joins the package unless you pick it.
Why should I use Forensic Browser instead of a regular screenshot?
A screenshot can be edited and proves neither when nor where it was taken. Forensic Browser captures the whole context: verified timestamps, network data, operator identity and page source, sealed with a qualified timestamp.
Will this evidence be accepted in court?
Yes. Every certification carries a qualified timestamp and a certified seal compliant with eIDAS, and the acquisition follows ISO/IEC 27037. The evidence is admissible across Europe and internationally.
Do I need technical expertise to use it?
No. It works like any browser: open a page, click Certify, browse normally. The forensic data is captured in the background, and ending the session creates and certifies the package with no manual steps.
How is it different from a browser extension?
Extensions run inside a standard browser, where the page can be manipulated before capture. Forensic Browser is a standalone app with a hardened environment: developer tools disabled, code injection blocked, integrity verified at every launch.
What do I receive after a certification session?
A certified PDF report, a JSON report with the forensic metadata, and the archive with screenshots, video, page source and network logs, all sealed with a qualified timestamp.

Stop losing evidence.

Join 20,000+ professionals who turn volatile web content into certified evidence with full legal value.

macOS · .dmg installerWindows · .exe installer
TrueScreen Forensic Browser