A dedicated browser, built for evidence.
Every Provena session runs in a remote browser operated by the platform — not on your machine, and not in your everyday browser. The environment is controlled, the interaction surface is limited, and everything that matters is preserved as you work.
Nothing depends on your machine.
The capture environment is allocated for one session and destroyed afterwards. Your local browser state — extensions, cookies, cached content — never touches the record.
- A dedicated remote worker per session, allocated on demand and destroyed at teardown — allocation and release are themselves custody events.
- Session context recorded up front: label, initial URL, resolution, locale, timezone, and operator.
- Viewport calibration from the real window metrics — the capture area is measured, not assumed.
- A transcription-resistant session code in the PRV-XXXX-XXXX-XXXX format — designed to survive being read over the phone and retyped.
A browser that refuses to misbehave.
The interaction policy is enforced in the runtime, server-side — not in your browser, where it could be bypassed. It is what separates a controlled capture from a browsing session that happened to be recorded.
- System shortcuts refused: modifier combinations, function keys, escape, and print-screen are rejected at the runtime.
- No context menu, no devtools, no save-page, no printing — the operator observes and navigates; the platform preserves.
- Navigation restricted to http and https — local files, browser internals, and data URLs are blocked.
Enforced server-side in the capture runtime — not in the operator's browser.
Preserved as you work.
- Screenshots — viewport and full page — with a provenance mark rendered into the pixels before hashing: the Provena label, ISO 8601 timestamp, and session identifier. Extracted from the package and pasted into a filing, the image still describes itself.
- Video in MP4 with full technical metadata — resolution, frame rate, duration, frame count, codecs — plus navigation aids: thumbnail sprites, cue tracks, and chapters when the session supports them.
- Downloads through a controlled acceptance path: quota is reserved, a custody event is recorded, and only a successful upload turns the file into evidence.
- Page snapshots — one image plus saved HTML per unique page visited, a navigation catalogue that supports the primary evidence without replacing it.
- Technical logs preserved as evidence: the session log, the network log, and a per-origin domain log.
- Server identity per origin: TLS certificate, remote IP, DNS records, and fingerprints — so reviewers can examine which origin was actually contacted.
Limits are policy, not suggestion.
Capture limits are resolved from organization policy when the session is configured — and enforced in the runtime, where they cannot be talked around.
- Seven governed dimensions cover duration, screenshots, video files, download volume and count, and concurrent watchers.
- Organization overrides defaults — and an unset value falls back to the default, never to unlimited.
- Watch mode lets invited witnesses observe the live session read-only — with watcher limits of their own.
Resolved at session configuration; enforced at the capture runtime.
What a session leaves you with.
Every capture feeds the same trust engine as the rest of the Provena line — hashed, chained, sealed, and open to independent verification.
- A structured evidence package — every file inventoried in a manifest, hashed with SHA-512, and linked into the chain of custody.
- A PDF/A report written for scrutiny — generated whenever you need it, with executive, legal, and technical reading modes in one record.
- External proofs — the sealed record is registered with independent timestamp references that outlive Provena.
- Verification the other side can run — a public check experience that needs no account and no explanation.
Straight answers about Capture.
What is Provena Capture?
Capture is Provena's controlled evidence-capture product: a dedicated remote browser, operated by the platform, where everything you see is preserved as you work — screenshots, video, downloads, page snapshots, and technical logs — and sealed into a verifiable evidence package.
How does a capture session work?
You create a session, receive a dedicated remote browser, and navigate to the content you need. While you work, the platform preserves the material and records every step in a hash-linked custody chain. When you finish, everything is sealed into a single evidence package — and you can generate the PDF/A report from it whenever you need one.
What do I get at the end of a session?
A structured evidence package — every file inventoried in a manifest and hashed with SHA-512 — plus a public verification link and external proofs registered with references that operate outside Provena. Whenever you need it, you can generate a PDF/A report with executive, legal, and technical reading modes.
Do I need technical knowledge to use it?
No. You navigate the way you always do; the controlled environment, the hashing, the custody chain, and the sealing all happen on the platform's side. The technical depth exists so reviewers can scrutinize the record — not so you have to.
Why isn't a screenshot from my own browser enough?
A screenshot made on your own machine asks for trust: nothing distinguishes it from an edited one, and nothing documents how it was made. A Capture session runs in a controlled environment you cannot silently alter, records how the material was obtained, and produces a record that can be verified independently — the discussion moves from trust to verification.
Can I capture content behind a login?
Yes. You can sign in to social networks, webmail, or other services inside the remote browser and capture what is displayed. Each session environment is single-use and destroyed at teardown — your everyday browser, extensions, and cookies are never involved.
Can someone watch the capture live?
Yes. Watch mode lets invited witnesses — a lawyer, a client, an expert — observe the live session in read-only mode, with watcher limits governed by organization policy.
Is my machine part of the record?
No. The capture runs on a dedicated remote worker allocated for that one session and destroyed afterwards. Your local browser state never touches the record — which is exactly what makes the record defensible.
How does someone verify a capture later?
Verification is public and needs no account: a session code or a file is enough to check hashes, inspect the custody chain, and confirm the external proofs. An unaltered file always matches; a modified one never does.
Does Provena guarantee the evidence will be accepted in court?
No — and you should distrust anyone who promises that. Admissibility depends on jurisdiction, context, and judicial assessment. What Capture provides is the technical foundation that supports that assessment: a documented method, an auditable custody chain, and independent verification.
Captured is only the beginning.
Everything preserved here flows into the custody chain — hashed, linked, sealed, and open to independent verification.