| TL;DR: A screenshot can preserve what was on the internet. But what happens when the original disappears before anyone realizes how important it is? We looked at Page Vault and the changing work of collecting online evidence to find out. |
In March 2022, a fight inside a Maryland bar left a college student stabbed twice and investigators with two very different records of what happened.
The bar’s surveillance cameras had captured the fight, but not the stabbing itself. A day later, a detective found another angle on Facebook: a cellphone video apparently recorded by someone inside the bar.
Then it disappeared.
The video was removed before investigators could preserve it. Detective David Underwood managed to save a single still image, but he did not know who had filmed the video or whose Facebook account had posted it. The image was eventually admitted into evidence after investigators connected details in it to authenticated surveillance footage.
The case exposed an uncomfortable feature of evidence on the modern web: finding it and preserving it are no longer necessarily the same event.
A post can be edited. A story can vanish. A video can disappear while someone is still deciding whether it matters. And once the original is gone, questions that seemed secondary at the moment of discovery, where it came from, when it was captured, what surrounded it, can become much harder to answer.
Nicole Brown has seen the other end of that problem.
Brown is Director of Go-To-Market at Page Vault, which provides software and outsourced services for collecting online material for legal matters. She told SaaSTake about the urgency that can arise when someone realizes they may have waited too long to preserve online material. One caller recently left the company’s general line a voicemail around 10 PM.
“I really need this captured if it’s not too late,” the caller said. “I’m really kicking myself right now.”
The Maryland case and that late-night call are very different situations. But they expose the same timing problem.
As more potential evidence lives on an internet built to change, legal teams face a difficult question much earlier than the courtroom: How soon do you preserve something when you don’t yet know how important it will become?
A Screenshot Can Survive. Its History May Not.
There is a detail in the Maryland case worth lingering on: the Facebook image was not rejected simply because it was a screenshot.
The detective could explain how he found and captured it, and investigators could compare details in the image with authenticated surveillance footage from the bar. Those connections gave the court enough to uphold the decision to admit the image.
That raises a useful question: if a screenshot can make it into evidence, what makes one harder to rely on than another?
An older federal case offers a useful contrast. In Toytrackerz LLC v. Koehler, the problem was not simply that the evidence consisted of website printouts. The record did not establish who retrieved them, when and how they were printed, or why they accurately represented the websites, and the court gave them little weight.
Put the two cases beside each other, and the difference becomes clearer. What matters is not simply what the capture shows, but what can be established about the capture itself.
That distinction matters under Federal Rule of Evidence 901, which generally requires enough evidence to support a finding that an item is what its proponent claims it is. A screenshot may show what appeared online; that is, questions about where it came from, when it was collected, and who collected it can require evidence beyond the image itself.
Those questions become considerably harder once the source has changed or disappeared.
What looks like an authentication problem, then, can begin much earlier as a problem of timing.
The Deadline Can Arrive Before the Evidence Looks Important
Legal teams do not necessarily know how much a post, video, or webpage will matter when they first encounter it.
The web may not give them time to decide.
The American Bar Association recommends collecting and preserving relevant social media evidence as early as possible. The reason is practical as much as evidentiary: accounts change, posts disappear, and material that once supplied useful context may no longer be available later.
Brown sees that pressure in the requests reaching Page Vault’s services team.
“When we ask when someone needs a collection completed, the answer is very often some version of ‘yesterday,’” she told SaaSTake.
With a stable document, there is room to examine it, decide how relevant it is, and return to it later. A social post offers no such promise. By the time its importance becomes clear, the version that mattered may no longer exist.
So the web introduces an uncomfortable tradeoff: sometimes the decision to preserve has to be made before the decision about importance is settled.
That does not mean collecting everything a legal team encounters, nor does it change when legal preservation obligations apply. The narrower point is that once potentially useful online material has been identified, the window for deciding what to do with it may be shorter than the workflow assumes.

Making that capture easier sounds like a problem software should be able to solve. To understand why the answer is more complicated, it helps to look at what the job used to involve.
When Saving the Web Was Still a Manual Job
Page Vault did not emerge because lawyers had no way to save something they found online.
The problem was everything that had to happen around the save.
A 2015 account of Page Vault’s early product described legal teams scrolling through webpages and taking multiple screenshots, manually recording information such as timestamps, or asking outside parties to collect the material for them. The process could work, but it became awkward when the content might disappear before the collection could be arranged.
Page Vault, founded in 2013, approached that problem by moving more of the collection record into the workflow itself. Its browser captured the online material together with associated metadata, while the capture itself happened remotely rather than on the lawyer’s computer.
Saving what appeared on the webpage was only part of the job. Information about how that material had been collected also needed to survive with it. It is a problem that appears elsewhere in legal information workflows too. Our look at Epona’s approach to knowledge management found a related challenge: preserving a document without the context around why it mattered can create a different problem when someone tries to use it later.
More than a decade later, however, that basic problem has not disappeared. What has changed is the web around it.
Page Vault’s human services operation offers a useful view of what happened next.
Some Exceptions Don’t Stay Exceptional
Page Vault now offers Browser software for legal teams that want to handle collections themselves. Yet it also runs Page Vault On Demand, where specialists perform collections for clients.
What still reaches the humans as more repeatable work moves into software?
The answer, Brown says, is the messy stuff.
“We see the difficult platforms, new content formats, unusual requests, and edge cases firsthand,” she said.
Those requests can involve everything from changing social feeds and video to historical sites and collections that require someone to interact manually with the web. But Brown says the more revealing signal is repetition.
“We can see where a problem is becoming common enough that technology should solve it more efficiently.”
Seen that way, Page Vault’s services operation is not simply a fallback for work customers do not handle themselves. It gives the company visibility into which exceptions are becoming patterns.
Better capture can solve only part of the evidentiary problem.
Preserving the Post Doesn’t Prove Who Posted It
Even a perfectly preserved social media post can leave another question unanswered: who was actually behind the account?
That is a different evidentiary problem.
The ABA’s review of social media authentication cases shows courts considering surrounding evidence to connect online activity to particular people or accounts. In other words, preserving a post and establishing its authorship are related but separate tasks.
That puts a useful boundary around what capture technology can do. It can preserve information and record how it was collected. It cannot decide who created it, what it means, or how much it will matter. A similar boundary appears in AI-assisted document review, where technology can take on more of the review process while people remain responsible for defining and validating the judgments behind it.
And that brings the problem back to where it started.
In Maryland, investigators found the Facebook video before they understood how important preserving it would become. By the time they tried, almost all that remained was a single frame.
Page Vault has made more of that collection process repeatable, while its services team keeps encountering the problems that are not repeatable yet.
But none of that technology can move the decision that comes first.
That is what makes Brown’s late-night voicemail so revealing:
“I really need this captured if it’s not too late.”
With online evidence, you may not know yet what will matter. The web does not have to wait for you to decide.






