Private Messenger conversations — including end-to-end encrypted ones — and Instagram Direct threads, collected by walking back up the conversation without losing the messages already scrolled out of view.
No option to tick, no separate module to buy, no extra cost: it is the Web pages module, at its own rate.
A private conversation is a different evidentiary object from public content, and it deserves its own pipeline: here there is no service to query. On end-to-end encrypted Messenger there is no network channel from which to obtain the text — verified in the field: zero responses containing cleartext. The only possible source is what the application decrypted and drew on screen, and this module documents exactly that, and nothing more.
There is a trap, though: Messenger recycles the page. As you walk back up the conversation, messages scrolled out of view are removed — measured: 27, then 44, 55, 81, 68, 94, 65 messages present at different moments. Anyone who scrolls to the top and only then collects gets a badly incomplete bundle with no error signal at all. So here collection happens at every step and accumulates, recognising duplicates.
Only what the program actually does: every item matches a collection that exists in the code and has been tested on real acquisitions.
Text, author and direction (sent or received), collected at every step of the walk-up and deduplicated, because in the page the messages carry no identifier to rely on.
The conversation as it appeared on screen step after step, with the hash of every image.
The bundle states that the source is the content rendered on screen and not a network channel, because on an encrypted conversation that channel does not exist. It is information whoever weighs the evidence needs.
Recognition looks at the domain and the shape of the address. If it recognises nothing, it stays an ordinary web page acquisition: nothing is lost.
facebook.com/messages/t/<id>Messenger conversationfacebook.com/messages/e2ee/t/<id>end-to-end encrypted conversationinstagram.com/direct/t/<id>Instagram Direct threadFolders inside the BagIt bundle, alongside everything else from the web acquisition: WACZ archive, screenshots, network traffic, certificates, report.
social/messaging/The bundle's interactive.html dashboard presents them in tables with search and sorting, and works offline, on a double click, even on a computer without C.E.R.T.O. installed.
Where collection goes through a service, every response is preserved verbatim with its provenance envelope: queried address, method, status, moment of receipt. Anyone contesting the data can go back to the source rather than trusting our table.
A BagIt 1.0 bundle with an Ed25519 signature, a double RFC 3161 timestamp and a CASE/UCO description, verifiable by anyone, offline, with the included verifiers.
The document reports how many items the platform announces, how many were collected and why collection stopped. A stated limit is worth more than an asserted completeness.
The questions we are asked most often about this platform.
All inside the Web pages module, all recognised from the address, all at the same rate.
Register for free and download C.E.R.T.O. Desktop for Windows and macOS from your client area.