Computer forensics
We examine laptops, workstations, servers, and related storage to identify, preserve, and analyse relevant digital artefacts. Typical work includes imaging of hard drives and SSDs, review of user activity, file recovery, timeline analysis, and documentation of findings.
This support is used in internal investigations, suspected unauthorised access, data leakage, and disputes where computer records need to be preserved before they change.
Mobile device forensics
Phones and tablets often hold the most current communications and location data. We support forensically sound handling of mobile devices, including preservation of messaging, call records, installed applications, and other artefacts where lawful access is available.
Early preservation matters: devices continue to sync, overwrite, and lock. We advise on isolation, imaging, and the limits of what can reasonably be recovered.
eDiscovery and litigation support
When a matter moves toward legal process, the task is not only to find data—it is to identify, collect, process, and produce it in a defensible way. We support eDiscovery exercises spanning mailboxes, file shares, devices, and exported datasets.
Deliverables are scoped with counsel or the instructing party so that collections remain proportionate, documented, and suitable for review and production.
How we work
Every engagement starts with scope: what is alleged, which devices or sources are in play, and what legal or policy basis exists for access. We then preserve, analyse, and report. We do not claim laboratory accreditations we do not hold. We do commit to careful handling, written methodology, and findings that distinguish fact from inference.