Articles
Trending

How to Capture, Archive, and Preserve Evidence When Gendered Disinformation Lands

DIGITAL SAFETY EXPLAINER  |  Issue 03  |  July 2026

BY: Olasupo Abideen

A practical documentation guide for the months when the attacks start coming — because you cannot defend what you have not documented

BBYDI × FactCheck Africa  |  Strengthening Digital Integrity and Inclusive Participation for Nigeria 2027  |  July 2026

Documentation is the single most undervalued skill in digital defence.

The first two articles in this series set out the threat landscape and walked through the account-hardening work that closes most of the common attack vectors. This month we turn to the discipline that matters most once the attacks actually start landing: how to capture, archive, and preserve evidence in a way that stands up to platform review, fact-checker verification, and — where necessary — legal proceedings.

Most women in Nigerian politics know to take screenshots. Few have a structured documentation practice that produces evidence robust enough to serve any of those downstream purposes. The difference is not intelligence or effort. It is method. With an hour of setup work this weekend, you can build a system that runs as background practice for the rest of your political career.

Why documentation matters more than it feels like it should

There are five specific reasons to invest in documentation, and it is worth being clear about each of them because they compound.

First: evidence disappears. Posts get deleted, sometimes by the attacker realising they have been noticed, sometimes by the platform’s own moderation, sometimes by pure accident. Accounts get suspended, renamed, or repurposed. URLs change silently. Without contemporaneous capture, the evidence of what was done to you can simply vanish — and with it, your ability to seek any recourse whatsoever.

Second: verification requires evidence. Fact-checkers cannot verify a claim from a description; they need to see the original. Platforms cannot review content from a description either. Documentation is what makes everything else possible — every referral, every complaint, every request for platform action begins with what you have captured.

Third: pattern detection requires accumulation. A single attack can look like an unfortunate incident. A pattern of attacks documented across months tells a different story — one that civil-society partners can use to build cases for systemic platform response, one that journalists can cover as a story of coordination rather than a single episode, and one that funders and international bodies can respond to as evidence of a broader phenomenon.

Fourth: the Liar’s Dividend is defeated by evidence. When perpetrators dismiss authentic evidence as AI-generated, the defence is provenance — time-stamped, metadata-preserved, chain-of-custody-documented capture from the moment the content appeared. That defence has to be built before, not after. If you wait until your evidence is contested to build it, you have already lost the argument.

And fifth: documentation is empowering. The single most demoralising feature of sustained harassment is the feeling that it is happening to you and you have no record of it happening. Documentation puts you back in the position of someone holding the evidence, not someone being acted upon. That psychological shift is not incidental — it is one of the most consistent things that women who have weathered attacks well describe as having made a difference.

The capture-and-archive method

The recommended documentation practice has three components: capture, archive, and log. Each happens within minutes of an attack landing. None of them is difficult, but they must be done in this order, and they must be done for every significant incident.

Capture

For any significant incident, the minimum capture includes: a full-screen screenshot of the offending content with the platform interface visible (so the platform is identifiable); a screenshot of the author’s profile page (so the account is identifiable); a screenshot of any visible engagement metrics (likes, shares, comments, views); the URL of the content copied to plain text; if the content is a video or audio, a screen recording of it being played; and if the content is a thread, screenshots of the full thread rather than just the offending post.

Take all of these as quickly as possible. Attackers frequently delete content within minutes of realising it has been noticed, particularly when the person targeted starts screenshotting. The window between the attack landing and the evidence disappearing can be shorter than you expect.

Archive

Web-archive services preserve content at a specific moment in time, independent of whether the original is later deleted. Two matter most:

  • The Internet Archive’s Wayback Machine (web.archive.org): click “Save Page Now” and paste the URL. The archive saves a snapshot of the page at that moment. Anyone — including fact-checkers, platforms, and courts — can later view exactly what was at that URL when you archived it. This is often more authoritative than a screenshot because it is harder to manipulate and easier to independently verify.
  • Archive.today (also known as archive.ph): an alternative web-archive service. Useful as a second copy because the Wayback Machine occasionally cannot save certain pages, particularly on some social-media platforms with anti-scraping measures.

Archive every piece of significant content within the first 48 hours of capture. This is not overcautious — the platform-moderation churn during a Nigerian election cycle is fast enough that entries archived a week after the fact routinely find the original content gone.

Log

Maintain a running log of every incident. Each log entry should contain: the date and time you first saw the content; the date and time the content was posted (where visible); the platform; the account that posted it (handle, display name, and follower count if relevant); the URL; the web-archive URL; file paths to your local screenshots and screen recordings; a brief description in your own words of what the content is and why it is being logged; and a severity rating on a 1-to-5 scale with any immediate action taken.

The log can be a simple spreadsheet. The point is consistency: every incident, the same fields, the same place. Consistency across incidents is what allows patterns to become visible; scattered notes across different documents do not.

Timestamping and chain of custody

Two concepts from forensic practice materially affect how seriously your documentation is taken by external parties.

A timestamp is documentary proof that a piece of content existed at a particular moment. Three timestamps matter: the platform timestamp (what the platform records as the posting time, usually preserved in archive captures), your capture timestamp (when you took the screenshot, recorded automatically by your device), and the web-archive timestamp (when Wayback Machine or archive.today captured the page, which is the most independently verifiable because it comes from a third party). Where authenticity is later contested, the convergence of these three timestamps is much harder to argue with than any single one in isolation.

Chain of custody is the documented record of who has handled evidence between the moment it was captured and the moment it is presented. The principles in digital documentation are simple: originals stored in a write-once location that you do not edit; edits and annotations work on copies, not on originals; and the log records every time evidence is shared, with whom, and for what purpose. For most documentation this discipline does not need to be more rigorous than “originals here, copies for sharing there, log of who got what.” For legal proceedings it becomes more demanding, and your legal-aid partner will guide you through the additional steps.

The two-copy principle For every piece of documented content, maintain two copies: an evidentiary copy with full metadata, stored in your write-once archive; and a sharing copy with sensitive metadata stripped, used for any public or external sharing. The evidentiary copy is the one that matters if authenticity is challenged. The sharing copy protects you from inadvertently revealing personal information — your location, your device, your movements — through the metadata that modern phones embed in every photograph and screenshot.

Working with fact-checkers

Fact-checkers can debunk disinformation directed at you — but they need things from you. The smoother the handoff, the faster the verdict. What Nigerian fact-checkers need from a complainant:

  • The specific claim being made about you, expressed as a single factual assertion (not a general description of the harassment, but the precise claim);
  • The URLs and archive URLs where the claim appears;
  • Your evidence that the claim is false — documents, photographs, witness statements, official records, whatever supports the rebuttal;
  • Consent for the verdict to be published, with clarity about what personal information can be referenced;
  • An assessment of urgency — is there a time-sensitive context (an upcoming event, an ongoing campaign, an escalating threat) that argues for faster verification?

Approach fact-checkers with a documentation package, not a request to investigate from scratch. Their resources are limited; well-prepared submissions get acted on materially faster. In the Nigerian context the principal fact-checking organisations are members of the Nigerian Fact-Checkers’ Coalition — Dubawa, FactCheck Africa, AFP Fact Check, TheCable Fact-Check, Nigerian Democratic Report, PRNigeria CableCheck, CDDFactCheck, and FactCheckHub. Any of them can act on a well-documented submission.

What goes into a documentation file for a serious incident

For a major incident — one significant enough that you might bring it to a fact-checker, a lawyer, a journalist, or law enforcement — the single documentation file should contain: a cover note in your own words (three to five sentences describing what the incident was and why it is significant); all screenshots ordered chronologically and labelled; any screen recordings as separate video files; a text file with the URLs of the original content; a text file with the URLs of the web-archive captures; any related communications you have had about the incident (emails from supporters, platform reporting confirmations, correspondence with civil-society partners); and your incident log entry exported as a single-page PDF or text file.

Compress the whole thing into a single zipped folder, name it with the date and platform (for example, “2026-11-15_Facebook_impersonation”), and store it in your write-once archive. When you need to share it — with a lawyer, a fact-checker, a partner — share the whole folder rather than piece by piece. This preserves the integrity of the package and makes it easier for the recipient to assess.

One thing to do this month

Run a documentation drill on an ordinary post Pick any recent post on your public account — one of your own, if you like. Screenshot it, archive it on the Wayback Machine, and enter it into a log. The whole exercise should take under ten minutes. The first time will feel slow and slightly silly. The second time will be faster. By the third time the muscle memory will be there. When a real incident lands — and one likely will — the process will run automatically rather than requiring you to remember the steps under stress. The drill matters not because the ordinary post needs documenting, but because the discipline needs to exist before it is tested.

Resources for this month

  • Wayback Machine — web.archive.org — the primary web-archive service; free, browser-based, takes seconds to save a page.
  • Archive.today (archive.ph) — the backup web-archive service; use for content the Wayback Machine cannot capture.
  • Nigerian Fact-Checkers’ Coalition (NFC) — the professional network of Nigerian fact-checkers, including Dubawa, FactCheck Africa, CDDFactCheck, TheCable Fact-Check, and others.
  • BBYDI Rapid Response Desk — brainbuilderedu@gmail.com — for routing documented incidents to the appropriate consortium partner. From November 2026, expanded response hours during the peak election period.
  • BBYDI Digital Safety Toolkit — the full documentation-strategies chapter (Section 5) with templates and step-by-step protocols; available on request.
Coming in August Next month’s article walks through the first 24 hours when an attack lands — the tested response playbook that women in Nigerian politics need to know before they need it. What to do in the first five minutes; when to call whom; and the three things never to do in the first hour that make almost every situation worse.

This explainer is part of the Strengthening Digital Integrity and Inclusive Participation for Nigeria 2027 project, implemented by Brain Builders Youth Development Initiative (BBYDI) and FactCheck Africa, with the support of the Digital Democracy Initiative (DDI) and CIVICUS. The series is distributed under a Creative Commons Attribution-NonCommercial 4.0 licence — please share, translate, and adapt, with credit.

To receive the series by email each month, write to brainbuilderedu@gmail.com with the subject line “Digital Safety Series Subscription.”

Related Articles

Back to top button