What should be preserved from a payment application?¶
A payment application can contain live, changing evidence, so preservation should be purposeful and cautious.
Avoid the dangerous assumption¶
The dangerous assumption is that opening the application and taking a few screenshots preserves everything relevant.
Record the device, application name, version, account identifier, displayed user details, date, time and network state.
Preserve visible transaction history, balances, payment handles, linked cards or accounts, beneficiaries, devices, security alerts and relevant messages.
Capture complete transaction details rather than only the summary list.
Record transaction IDs, status, timestamps, amounts, currencies, fees, recipient details and funding sources.
Where the application shows active devices, sessions or recent logins, preserve those details before security changes are made.
Do not explore beyond lawful authority or unnecessarily trigger new synchronisation, notifications, authentication or account changes.
Opening transactions, refreshing screens or switching networks may update access logs or alter local application data.
Screenshots are useful, but they are not a substitute for provider records or forensic acquisition. Where an export function exists, preserve the original export and record how it was obtained.
Where proportionate, obtain specialist support to preserve the device and application data.
Record every action taken, including whether the application was already open and authenticated.
Do not log out, remove devices, change passwords or revoke sessions until the evidential and safeguarding consequences are considered.
Where immediate loss prevention is required, document the balance between preservation and account security.
Operational takeaway¶
Preserve payment-application identifiers, transactions, linked accounts, devices and sessions with a full action log, then obtain provider and specialist records for completeness.