Who may still hold the content of an encrypted message?¶
Readable content may be held by any participant or authorised endpoint, and by people or systems to which a participant copied it. A provider's inability to read the message does not remove those copies.
Map every plausible copy¶
Start with sender and recipient devices, then consider linked phones, tablets, desktop applications and browser sessions. A participant may also have created screenshots, chat exports, quoted replies or forwarded messages. Notification histories can preserve previews, while attachments may remain in downloads, galleries, shared folders or backups.
Organisational systems may add another layer. Depending on configuration, managed devices, compliance archives or workplace retention tools may capture communications or associated files. Their presence and completeness must be established rather than assumed.
Compare copies by provenance¶
An original device database, native export and screenshot expose different amounts of context. Retain the supplied file or device, collection method, account identifiers, message IDs, sequence, times and attachment details. Compare copies for omissions, edits, expiry, synchronisation differences and time-zone handling.
Recipient-supplied content can establish what that endpoint displayed, but it does not automatically establish completeness or the human author. A backup may likewise be useful without being current, complete or readable.
The point to remember
Trace encrypted content across participants, linked endpoints, copied material and retained attachments, then assess each copy according to its provenance and limits.