Skip to content
MDA-122 Mobile Devices & Apps

How do I distinguish device evidence from provider evidence?

Device evidence comes from the handset or other local hardware.

What this means

Provider evidence comes from the company operating the account, app, network or cloud service.

The distinction matters because the two sources may record different events.

A device may hold messages, app databases, photographs, notifications, browser history, usage records and local timestamps.

A provider may hold account registration, login history, IP addresses, device sessions, delivery events, billing and security records.

The device may show that content was present locally.

The provider may show when the account uploaded, delivered, edited or deleted it.

Neither source is automatically complete.

The handset may contain unique local data that was never synchronised.

The provider may retain activity no longer visible on the phone.

Timestamps may also refer to different stages of the same event.

One may record local creation.

Another may record server receipt or later synchronisation.

Then compare device and provider evidence using stable identifiers such as message IDs, account IDs, device identifiers and session records.

Where they differ, investigate the reason rather than assuming one must be wrong.

The operational takeaway is: device evidence shows what the local hardware recorded; provider evidence shows what the service recorded. Keep the sources separate, then reconcile them to build the complete timeline.

What to check or do next

  • Investigators should label the source of every record.
  • Ask what system created it, what event caused it and what the timestamp means.
Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.