10.1 Purpose
To ensure that any digital evidence connected to a security incident, fraud investigation, harassment/threat report, or legal dispute is preserved in a manner that maintains its integrity and admissibility, consistent with Egyptian evidentiary standards for electronic evidence under the E-Signature/E-Commerce Law.
10.2 Categories of Evidence Covered
- System and application logs (server logs, access logs, audit logs — see Section 12).
- Screenshots, screen recordings, or exports of suspicious in-app conversations (threats, fraud attempts, extortion).
- Network metadata (IP addresses, session timestamps, device fingerprints).
- OTP/notification delivery metadata relevant to a reported abuse incident (delivery timestamps and counts, not the personal content of unrelated messages).
- Payment and transaction records relevant to a fraud investigation.
10.3 Preservation Steps
- Immediate isolation: Upon detection of a relevant incident, all associated data is immediately flagged and excluded from any routine automated deletion/retention-expiry process that would otherwise apply.
- Cryptographic timestamping: Each preserved artifact is hashed (SHA-256) and timestamped at the moment of preservation to create a verifiable, tamper-evident record of its state.
- Chain of custody: Every access to preserved evidence — who accessed it, when, and why — is logged, to maintain a documented chain of custody suitable for potential legal proceedings.
- Secure, segregated storage: Preserved evidence is stored in a segregated, access-restricted location classified as Level 4 (Restricted) under the Data Classification Policy, accessible only to authorized incident-response Personnel under dual-approval controls.
10.4 Retention Period for Evidence
Evidence connected to a security incident or legal matter is retained for a minimum of one year, or until the conclusion of any related legal, regulatory, or law-enforcement proceeding, whichever is longer.
10.5 Handling of Threat and Harassment Reports
For incidents involving direct threats, harassment, or abuse of the OTP/notification system, all related evidence (message content, timestamps, account metadata, and any user-submitted screenshots) is preserved immediately upon report, in parallel with filing a formal report to the competent Egyptian security authorities where the conduct may constitute a criminal offense.
10.6 Coordination with Legal Counsel
For any incident with potential legal exposure, preserved evidence is reviewed jointly with Hirfa's external legal counsel to determine appropriate next steps, including potential referral to law enforcement or civil action.