Hand the evidence to your legal team without handing them your monitoring console
Recording every session sounds powerful in a sales meeting. The moment you actually need to use the recording - to defend a wrongful termination, support a fraud investigation, respond to an e-discovery request, or hand evidence to law enforcement - the question becomes harder: how do you give a recorded session to someone who doesn’t have access to your monitoring platform, in a form their lawyer will accept as evidence? Many platforms answer this with “export a video file” or “download a screen recording.” Those work, until opposing counsel asks how you can prove the video wasn’t edited. SHA256 hash? Where? Password protection? None. Standalone player your forensic team can use without a Management Tool license? You’re emailing them an MP4 and hoping they have VLC. Syteca Forensic Export is built for the moment a recording leaves the platform and becomes evidence. Sessions export as encrypted.efe files with a SHA256 hash for integrity verification, optional password protection, optional restriction to a specific time window inside a session, and playback in the Syteca Forensic Player - a standalone Windows/macOS/Linux application that opens .efe files without needing Management Tool access. The Forensic Export History tab is the audit trail of every export performed, by whom, with what comment, and with what hash.
- Produce legal-grade evidence for litigation, e-discovery requests, or law enforcement, with SHA256-verifiable integrity.
- Support HR investigations and wrongful-termination defense with session recordings the HR team can review independently.
- Comply with SOC 2 incident response evidence requirements, ISO 27001 incident records, GDPR data subject access requests, or PCI DSS forensic investigation needs.
- Share specific session evidence with third-party investigators, auditors, or insurance carriers without granting them access to your monitoring platform.
- Maintain a chain-of-custody audit trail for every recording that leaves the platform - who exported it, when, what comment they attached, what hash it produced.
How Forensic Export works
Every Forensic Export produces an encrypted file that can be played back outside the Management Tool. Two file formats depending on the recording mode:Export a single session (or a session fragment)

The Session Forensic Export dialog - fragment-or-full export, optional text data, optional password protection, and an audit-trail Comment.
Open the session
Open the Forensic Export dialog
Choose what to export
- Export session fragment starting from current Player position - enter the From and To dates and times for the slice to export.
- Export full session - export the whole session.
Choose options
Export and download
Export multiple sessions in bulk
Use this entry point when you need to export many sessions at once - for example, all sessions from a specific user across a specific time window for an investigation.Open the Sessions List
Filter to the sessions you need
Select sessions
Start the export
Choose options
- Optionally select Protect with password and enter a password in both fields.
- Optionally enter a Comment that will appear in the Forensic Export History.
Download from the history
The Forensic Export History tab

The Forensic Export History tab - every export ever performed, with SHA256 hashes for chain-of-custody verification and a download link for the standalone Syteca Forensic Player.
.efe files. See Play an exported session below.
The grid
Export types
Play an exported session
Exported.efe files play in the Syteca Forensic Player - a standalone application that doesn’t require Management Tool access. Useful for forensic investigators, third-party auditors, legal teams, and anyone else outside the Syteca user base who needs to review session evidence.
Download the Forensic Player
Install (per OS)
- Windows
- macOS / Linux
Open the .efe file
.efe file. If the file is password-protected, enter the password when prompted.What you see in the Syteca Forensic Player
The Forensic Player mirrors the layout of the in-product Session Viewer:Forensic Player controls
Verify the integrity of an exported session
The whole point of a SHA256 hash on the Forensic Export History tab is to prove the file you’re handing over is byte-identical to what came out of Syteca. Any opposing counsel, auditor, or forensic investigator can independently verify the file by recomputing the SHA256 on their copy and comparing it to what’s on the Forensic Export History tab.Get the hash from Syteca
Compute SHA256 on the file
- Windows (PowerShell)
- macOS
- Linux
Compare