Digital Forensics
Acquisition and examination of devices, files and system artefacts, preserved so the analysis can be independently repeated.
We recover, preserve and analyse digital evidence to a standard that holds up under scrutiny — with documented chain of custody from the moment material reaches us.
Engagements are scoped against a lawful basis before work begins. We decline instructions that would require unauthorised access to systems, accounts or communications.
Acquisition and examination of devices, files and system artefacts, preserved so the analysis can be independently repeated.
Discreet factual enquiry conducted lawfully, with evidence documented to the standard required for formal proceedings.
Structured research across publicly available sources. Every output is graded by how well it is corroborated.
Tracing fraudulent instructions, altered documents and financial irregularities — including business email compromise.
Determining how an intrusion occurred, what was reached, and what the evidence does and does not establish.
Containment and authorised endpoint collection under a documented mandate, preserving forensic value while you recover.
Material is never altered. Originals are hashed on arrival, stored write-once, and every action against them is recorded in a tamper-evident log.
Logged against a case, with source and collector recorded.
SHA-256 computed before any tool touches the file.
Scanning and extraction run on copies, never the original.
Stored immutably and re-verified against its recorded hash.
Findings stated with their evidential weight made explicit.
Tell us what happened. An investigator reviews every enquiry personally — submitting this form does not open an investigation, and you are under no obligation.