Every evidence management system claims to track chain of custody. Most do, in the sense that they write a log entry when someone checks an item in or out.
The harder question is what happens to that log afterward. Can someone change it? Can an administrator delete a line? Can the vendor?
For most software, the honest answer is yes. Logs live in a database table, and anyone with enough access can edit a database table. That’s fine for a shipping system. It’s a serious problem for evidence.
Why this matters more than it sounds
Chain of custody is the record that proves an item is what you say it is, and that it went where you say it went. When that record is questioned, the software behind it becomes part of the argument.
“The chain of custody, the continuity of that item and that paperwork, could make or break a case. There’s a lot of integrity built into the chain of custody for every single item that we receive into this building.”
Frank McCully, Investigator — Madison County Sheriff’s Office, NY
If a log can be quietly edited, a reasonable person can ask whether it was. That doubt is the whole game. Nobody needs to prove tampering to damage a case — they only need to establish that it was possible.
What ERIN7 does differently
ERIN7‘s audit trail is append-only. Entries can be added. They cannot be edited or removed through the application — not by a regular user, not by an agency administrator, and not by ERIN Technology support staff. There is no screen for it, because the capability does not exist.
Entries are also hash-chained. Each record is cryptographically linked to the one before it. If an earlier entry is altered by some other route, every record after it stops matching, and the break is detectable when the chain is verified. The record doesn’t just resist tampering — it reveals it.
That combination is why we treat audit integrity as a product requirement rather than a configuration setting. If the audit trail isn’t defensible, the evidence it describes isn’t defensible either.
What actually gets recorded
The audit trail captures more than most agencies expect:
- Before and after. Every event stores the complete record state on both sides of a change, not a summary of which fields were touched.
- Reads, not just writes. Who looked at a record, and when, is recoverable. Viewing is logged alongside editing.
- Who and where. Each event carries a unique record ID, the acting user, a timestamp, and the originating IP address.
- Failed attempts. Denied access and failed logins are recorded with their status, not silently discarded.
- Configuration changes. Role definitions, field setup, and system settings are audited too. Changing the rules is itself an event.
- Searchable. Records can be searched by user, module, date range, object value, or IP address, and each carries a plain-language description alongside the structured data.
Separately, every evidence file stored in ERIN7 carries a SHA-256 integrity hash. If a stored file changes, that’s detectable independently of whatever storage platform sits underneath — which matters when the storage isn’t yours to vouch for.
What this looks like in a courtroom
One ERIN7 customer runs a high-volume digital forensics lab, processing between 1,500 and 2,000 devices a month and holding roughly 10,000 items in storage at any time. The unit is subpoenaed regularly, and cases often reach court long after the examination is finished — sometimes years later, when the examiner who did the work has moved on.
In one multi-defendant trial, the defense challenged whether the evidence shown in photographs was the same evidence that had been processed. It’s a smart line of attack. Photographs of a phone look like photographs of a phone.
It went nowhere. The lab records unique device identifiers — IMEI numbers and similar — in ERIN7, in its examination reports, and in its photographs. The identifiers matched across all three records. There was nothing left to argue about.
The point isn’t that software won an argument. It’s that the argument ended quickly, because the record said the same thing everywhere it appeared, and there was no plausible way for it to have been changed after the fact.
It travels
This isn’t a feature of one hosting arrangement. The audit trail behaves identically whether ERIN7 runs in our Azure Government cloud, in a dedicated private cloud, or on infrastructure inside your own building with no internet connection at all. The controls live in the application, so they go where the software goes.
The point of all of it
Cases come back years later. People retire. Memories fade. What survives is the record.
“The ERIN System is fantastic, a huge time saver and easy to use functions. We are glad we switched over to this program as it helped us get organized and accredited through our state for the first time.”
Det. Lonnie Tuthill, Jr. — Greene County Sheriff’s Office, VA
An audit trail that can’t be edited isn’t a technical nicety. It’s the difference between a record you can defend and a record you have to explain.
See how ERIN7 handles chain of custody in your evidence room. Book a demo or call (855) 558-3746.
