Computer forensics
We image, preserve and analyse workstations, servers and removable media using write-blocking and forensic-grade tooling. Every step is logged so the evidence remains admissible and defensible.
- Forensic imaging of hard drives, SSDs and external storage with hash verification.
- File system, registry and event-log analysis to reconstruct user activity and timeline.
- Deleted file and artefact recovery using industry-standard techniques.
- Email and communication analysis for fraud, harassment or data-leak cases.
- Malware and intrusion artefact extraction to support incident-response decisions.
- Court-ready reports with clear explanations for technical and non-technical audiences.
Mobile forensics
Smartphones and tablets often hold the most relevant evidence. We extract and interpret mobile data while protecting integrity and respecting privacy boundaries.
- Logical and physical extraction from Android and iOS devices where supported.
- Recovery of messages, call logs, contacts, location history and application data.
- Analysis of cloud backups, synced accounts and third-party messaging applications.
- Verification of device timestamps, geolocation and communication patterns.
- Secure handling of personal and sensitive data throughout the investigation.
Incident response & evidence handling
Forensics is most valuable when tied to a structured response. We help contain the incident, preserve evidence, determine root cause and produce the documentation regulators and insurers expect.
- Rapid remote or on-site response to contain active threats and secure evidence.
- Chain-of-custody documentation from collection through analysis and archiving.
- Root-cause analysis linking attacker behaviour to affected systems and data.
- Support for regulatory notification, law-enforcement referral and insurance claims.
- Post-incident recommendations to close the gaps the attacker exploited.
What you receive
Our deliverables are designed to be actionable — whether the outcome is legal action, regulatory reporting, or internal remediation.
- Forensic acquisition report with hashes, timestamps and device details.
- Investigation summary mapping findings to the questions that triggered the case.
- Timeline reconstruction showing user, system and network activity.
- Expert witness statement or affidavit preparation on request.
- Remediation advice to prevent recurrence of the incident.
Frequently asked questions
How quickly can you respond to an incident?
We aim to begin remote triage within hours of engagement and can deploy on-site within one business day for local clients. A retainer arrangement guarantees faster response times.
Will the evidence hold up in court or before a regulator?
Yes — we follow forensic best practices, maintain chain of custody, use write-protected acquisition, and document every step. Reports are written to be understood by legal and non-technical audiences.
Can you analyse encrypted or damaged devices?
We can attempt recovery and decryption where credentials or backups are available. Severely damaged media is referred to specialised hardware-recovery partners with full documentation.
Do you support internal HR or fraud investigations?
Yes. We work with legal and HR teams under clear terms of reference, ensuring proportionality, confidentiality and compliance with data-protection requirements.