Search evidence and expert testimony
Abstract hexagonal tile illustration representing Self-Authenticating Electronic Records

IssueFoundationIs the exhibit received?

Self-Authenticating Electronic Records

Governing authority
FRE 902(13) and 902(14), added in 2017, both incorporating the certification requirements of FRE 902(11)
Question at issue
Can this record be authenticated by certification instead of a live witness?
Primary evidence
Server logs, analytics exports, forensic captures, hash values, chain-of-custody records
When it arises
Set up in discovery and served by written notice well before trial

A hash computed at the moment of capture turns a foundation fight into paperwork, and almost nobody in this field does it

What the 2017 rules changed, and what they did not

Rules 902(13) and 902(14) were added to the Federal Rules of Evidence in 2017. They did not lower the standard for authenticity. They changed who has to appear in order to satisfy it. Before them, establishing that a server log was output from the server that generated it, or that a forensic copy matched its original, meant putting a custodian or a technician on a plane to testify to something that was very rarely in genuine dispute. The 2017 rules let a written certification do that work, with notice to the opponent and a fair chance to contest it.

The two rules address different objects, and conflating them is the most common drafting error. Rule 902(13) is about a record generated by a system. Rule 902(14) is about a copy of data. A server log is the first. A forensic image of the folder holding that log is the second. In a search matter you frequently need both, and they call for different certifications from potentially different people.

Neither rule is much used in this vertical. I have not seen a single SEO expert's materials that included a 902(14) certification or a hash computed at capture time, and the omission is not a small one, because the evidence in these matters is almost entirely machine output and copies of files.

Rule 902(13): records generated by an electronic process or system

The rule makes self-authenticating “[a] record generated by an electronic process or system that produces an accurate result, as shown by a certification of a qualified person that complies with the certification requirements of Rule 902(11) or (12).”

It is the certified form of the same showing Rule 901(b)(9) permits by testimony. The certification must establish that the system regularly produces accurate results and that the exhibit accurately reflects output from that system. What that reaches in a search dispute is substantial:

  • web server and content delivery network access logs — the files recording each request received, with the requesting address, the time, the URL, and the response status;
  • analytics exports, where the analytics platform is the client's own measurement system rather than a third party's aggregated estimate;
  • content management system revision histories and publication timestamps;
  • deployment, ticketing, and change-control records showing when a site change was made and by whom;
  • crawl output from a system whose configuration and behavior a qualified person can describe.

The certification is about the system, not about the dispute. A worked example given in the drafting commentary makes the point: a log documenting an address connecting to a website needs a certification of how the server records connections, not expert testimony about what the connection meant.

Rule 902(14) and the hash value, which is the whole hinge

Rule 902(14) makes self-authenticating “[d]ata copied from an electronic device, storage medium, or file, if authenticated by a process of digital identification, as shown by a certification of a qualified person that complies with the certification requirements of Rule 902(11) or (12).”

The Advisory Committee note supplies the method. Data copied from devices, media, and files “are ordinarily authenticated by ‘hash value,’” and “identical hash values for the original and copy reliably attest to the fact that they are exact duplicates.” A hash value is a fixed-length string computed from a file's exact bytes by a published algorithm; change one byte of the file and the resulting value changes completely and unpredictably. It is not encryption and it is not a signature. It is a fingerprint that anyone with the file and the algorithm can recompute and compare.

That is why the hash is the hinge for this entire page. Compute one at the moment of capture, record it in the capture log, and the question “is the exhibit the same file you captured?” stops being a matter of testimony and memory and becomes a calculation the other side can run themselves in a few seconds. The corresponding failure is silent: capture a page, never compute a hash, then annotate and re-save the file three times over the following year, and there is no longer any way to demonstrate what the original looked like.

The certification for a 902(14) exhibit establishes that the copy methodology matched industry standards and that verification confirmed the copy is identical to the original.

The notice requirement, which is where this goes wrong in practice

Both rules incorporate the certification requirements of Rule 902(11). Two obligations come with that, and the second is the one people miss.

The first is that the certification must be made by a qualified person — someone in a position to attest to the matters certified. The second is procedural: the proponent must give the opponent reasonable written notice of the intent to offer the record, and must make the record and the certification available for inspection, so that the opponent has a fair opportunity to challenge them.

The design here is a bargain. The opponent gives up the right to make you produce a live witness for a routine matter; in exchange the opponent gets advance notice and the underlying material, which is a better deal than cross-examining a records custodian who knows nothing about the dispute. Break the notice side of it and the bargain fails. A certification served the week before trial converts what should have been an administrative step into a contested motion, and the party that delayed will be arguing about its own diligence rather than about the evidence.

The operational answer is to draft the certification when you capture, not when you need it. The facts are fresh, the person who performed the work is available, and the document then sits in the file waiting for a notice date that counsel controls.

Who signs, and what the document has to say

A qualified person is someone who can speak to the process being certified. For a 902(13) certification about server logs, that is ordinarily the administrator or engineer responsible for the logging system, not an outside consultant who read the logs afterward. For a 902(14) certification about a copy, it is the person who performed the copy.

Where an expert performs a forensic capture of a web page, that expert is the person with knowledge of the copy process, and there is nothing unusual about the same person both capturing evidence and later analyzing it — though the two roles should be documented separately, because the capture is a factual act and the analysis is an opinion, and they are attacked differently.

The substance of a workable certification is short. For a system record: identify the system, describe how it generates and stores the records at issue, state that it produces an accurate result and does so in the regular course, and state that the attached exhibit is output from it. For a copy: identify the source device, medium, or file; describe the copy process and the digital identification method used; state the algorithm and the values computed for the original and the copy; and state that they are identical. Precision here is cheap. Vagueness is what draws an objection.

What certification reaches in a search matter, and what it cannot

The reach is real but narrower than it first looks, and the boundary is worth stating carefully because overselling it is how a certification gets attacked.

A 902(14) certification establishes that the exhibit is an exact duplicate of the file that was captured. It says nothing at all about whether the capture faithfully represents what the server sent, or what a visitor would have seen. That is a Rule 901(b)(1) or 901(b)(9) question about the capture process, and the hash does not answer it. The two showings work together: the process establishes what was captured, and the hash establishes that the exhibit is still that.

Records generated by systems your client controls are the natural home for Rule 902(13): its own servers, its own analytics property, its own content management system. Records generated by a third-party platform are not yours to certify. Data exported from a search engine's webmaster console, or from a commercial rank-tracking service that runs queries on a schedule and records positions, cannot be self-authenticated by the party who downloaded it, because that party cannot attest to how the system produced the numbers. The routes there are a certification or witness from the producing party, or authentication under Rule 901 with a candid account of what the export does and does not represent.

Archived web pages sit outside these rules as well. The Fifth Circuit observed in Weinhoffer v. Davie Shoring, Inc., 23 F.4th 579 (5th Cir. 2022), that archived pages are not inherently or self-evidently reliable in the same way as the documents Rule 902 designates as self-authenticating. They are authenticated under Rule 901, not certified into evidence by the party that printed them.

Self-authentication is not admission, and it is not immunity

A certification under Rule 902(13) or (14) answers the authentication question. It answers only that question.

The opponent may still contest authenticity with evidence — self-authentication removes the need for a foundational witness, not the ability to argue that the exhibit is not what it claims to be. Hearsay remains a separate hurdle with a separate answer; a certified record offered to prove the truth of what it records still needs one. Rule 403 remains available. And weight is untouched: a properly certified log that shows very little is still a log that shows very little.

What certification buys is the removal of a fight that has nothing to do with the merits. That is worth more than it sounds. Foundation objections to machine evidence consume hearing time, invite the impression that the proponent's evidence is fragile, and occasionally succeed against exhibits that were entirely accurate. Trading that for a one-page document served with a notice date is a good trade, and it is available to anyone in this field who is willing to compute a hash before saving a file.

The current text of Rule 902, including subsections (13) and (14) and the certification requirements they incorporate, is published by the Legal Information Institute at Cornell.

Frequently Asked Questions

What is the difference between FRE 902(13) and FRE 902(14)?

902(13) covers a record generated by an electronic process or system that produces an accurate result — a server log, a system-generated report, an analytics export from a system you can describe. 902(14) covers data copied from a device, storage medium, or file, authenticated by a process of digital identification. The first certifies that a system made the record; the second certifies that a copy is identical to its original. Both require a certification by a qualified person meeting the certification requirements of Rule 902(11) or (12).

Do server logs need a live witness to be admitted?

Not for authentication, if a qualified person certifies them under Rule 902(13). The certification must establish that the logging system produces an accurate result and that the exhibit is output from it, and the proponent must give the opponent reasonable written notice and make the record and certification available for inspection. Certification resolves authentication only. Whether the log is offered for the truth of what it records, and whether it is relevant and not unfairly prejudicial, remain separate questions.

Why does a hash value matter for web evidence?

Because the Advisory Committee note to Rule 902(14) states that copied data is ordinarily authenticated by hash value, and that identical hash values for an original and a copy reliably attest that they are exact duplicates. A hash is a fixed-length value computed from a file's exact bytes; altering one byte changes it completely. Computing and recording a hash at the moment of capture means the question of whether the exhibit is still the file that was captured can be answered by recomputation rather than by testimony.

What notice does the opposing party get?

Rules 902(13) and 902(14) incorporate the certification requirements of Rule 902(11), which include reasonable written notice of the intent to offer the record and making the record and the certification available for inspection, so that the opponent has a fair opportunity to challenge them. That is the trade at the heart of these rules: the opponent gives up a live foundational witness and receives advance notice and access instead. A certification served late tends to produce a contested motion rather than an administrative step.

Can a Wayback Machine printout be self-authenticated?

Not by the party that printed it. In Weinhoffer v. Davie Shoring, Inc., 23 F.4th 579 (5th Cir. 2022), the Fifth Circuit observed that archived webpages are not inherently or self-evidently reliable in the same way as the documents Rule 902 designates as self-authenticating. Archived material is authenticated under Rule 901, ordinarily through a witness with personal knowledge of the archive's capture and storage process, through comparison with an independently authenticated copy, or through a showing about the archiving process itself.

Can an expert sign a 902(14) certification for a capture the expert made?

The rule calls for a certification by a qualified person, meaning someone who can attest to the matters certified. Where the expert performed the copy, that expert is the person with knowledge of the copy process, the digital identification method used, and the values computed. It is worth documenting the capture separately from the analysis, because a factual account of how a file was copied and an opinion about what the file shows are challenged in entirely different ways and should not be entangled in one document.

Does a certification stop the other side from objecting to the exhibit?

No. Self-authentication removes the need to call a foundational witness; it does not remove the opponent's ability to contest authenticity with evidence, to raise hearsay, to invoke Rule 403, or to argue that the record shows nothing useful. What it removes is a procedural fight unrelated to the merits. That is the practical value: an accurate exhibit should not consume hearing time on whether the server that wrote a log wrote the log.
Keep reading

Read the guides

An entry states what a rule requires or what a dispute turns on. A guide walks the sequence — what you do, in what order, before the evidence is gone.

Top