Skip to content

Feature

Evidence Packs

Entitled alerts package the evidence actually captured, with timestamps plus explicit completeness and provenance for registrar, compliance, and legal review.

Last reviewed:

Full-page screenshot

Visual capture of the suspected page at the time of detection, timestamped and stored securely.

WHOIS / RDAP data

Registrar, creation date, nameservers, and registrant information where available.

DNS records

A, AAAA, MX, TXT, and NS records for the suspect domain.

HTTP headers & redirects

Full response headers, redirect chain, and final destination URL.

Certificate chain

SSL/TLS certificate details including issuer, validity, and Subject Alternative Names.

AI verdict & reasoning

Explainable risk assessment with specific indicators that triggered the alert.

Why evidence matters

For registrar takedowns

Registrars and hosting providers require specific evidence to act on abuse reports. A screenshot alone is not enough — they need WHOIS proof that the domain is not yours, evidence of malicious content, and clear documentation of the threat.

For compliance audits

NIS2, ISO 27001, and cyber-insurance questionnaires may require documented incident response. Evidence packs can support that record, but their completeness metadata and your response records determine what they actually demonstrate.

For legal review

If a threat escalates to legal action, contemporaneous evidence matters. Evidence packs preserve the source material captured at detection time and state when an artifact or byte digest is unavailable; legal sufficiency requires separate review.

Frequently asked questions

What is an evidence pack?

An evidence pack is the bundle of source material impersona.io captures for an entitled alert: full-page screenshots, WHOIS/RDAP data, DNS records, HTTP headers and redirects, the SSL/TLS certificate chain, and the AI verdict with its reasoning. Completeness and provenance metadata state what was actually captured and verified, so you know exactly what the pack does and does not contain.

What evidence do registrars need for a takedown request?

Registrars and hosting providers require specific evidence to act on abuse reports. A screenshot alone is not enough — they need WHOIS proof that the domain is not yours, evidence of malicious content, and clear documentation of the threat. Evidence packs assemble that material for each entitled alert so an abuse report can reference concrete, timestamped captures.

Can evidence packs be used in legal proceedings?

Evidence packs preserve the source material captured at detection time, with timestamps, and explicitly state when an artifact or byte digest is unavailable. That makes them useful contemporaneous documentation if a threat escalates, but legal sufficiency requires separate review — impersona.io does not provide legal services or file UDRP claims.

Do evidence packs help with compliance audits?

They can support the documented incident-response record that NIS2, ISO 27001, and cyber-insurance questionnaires may require. What a pack actually demonstrates is determined by its completeness metadata and your own response records — the pack is supporting material for that record, not the record itself.

When do I get access to full evidence packs?

Run a free brand check first, then verify domain ownership to claim the brand. Full evidence fields for detected threats require an active Starter+ plan, from €49/month. The free brand check shows a limited preview; the complete captures — screenshots, WHOIS/RDAP, DNS, HTTP, certificates, and verdict reasoning — unlock with the paid entitlement.

Get the evidence on threats targeting you

Run a free brand check, verify your domain to claim the brand, then activate Starter+ to access full evidence fields for detected threats.