Free data destruction free analysis request →
Services Digital forensics
+32 (0)800 11 400 free analysis request

For police, courts, lawyers and companies

Digital forensics

When data is evidence, it is not only what you find that counts, but how. We work with a closed chain of custody, record every step, and never examine the original.

When this helps you

An ordinary recovery brings data back. A forensic investigation does so in a way that holds up afterwards: in court, with an insurer, in a disciplinary file or during an internal audit.

  • an employee leaves and files or customer data disappear
  • suspicion of fraud, bribery or leaking of trade secrets
  • a break-in or a ransomware attack: what exactly happened, and when
  • an insurance file where the cause and the extent of the damage must be proven
  • a court-appointed expert investigation, or an investigation by police or prosecutors
  • a device that no longer starts while its contents are needed as evidence

The chain of custody

A finding is only worth as much as the path that led to it. That is why the method is fixed in advance and every action is documented.

  1. Write blocking Every acquisition goes through a write blocker. The original is only read, never written to.
  2. Hash values Before and after the acquisition we compute hash values (MD5 and SHA-256). They appear in the report and prove the copy is identical and did not change afterwards.
  3. Work on the copy All work happens on a forensic copy. The original device stays untouched.
  4. Chain of custody For every action we record who, when and what. Between steps the device stays sealed.
  5. Report You get a report with the findings, the method used, the hash values and the chain of custody.
Technical: what a forensic copy is

A forensic copy is a sector-by-sector copy of the whole device, including the space the file system considers empty. Remnants of deleted files live there. We use the common formats (raw/dd and E01), so another expert can check the copy with their own tools. On a damaged device we make the copy in several passes and record, sector by sector, what could be read.

What we examine

Deleted files

Recovering what seemed erased, formatted or overwritten, stating what could and could not be fully restored.

Timeline

When a file was created, opened, changed or copied, and in what order.

Connected devices

Traces of USB sticks and external drives: which device, when connected, and what was copied.

Usage traces

Logins, searches, recently opened files, prints and operating system logs.

Email and documents

Mailboxes, attachments and documents, also from damaged files or older formats.

Mobile devices

Smartphones and tablets, also after drop or water damage, down to chip level.

What we do not do: pronounce on guilt or intent. We record what is on the device and what follows from it. The legal assessment is for the client, the lawyer or the court.

Damaged and encrypted devices

Evidence often sits on a device that is broken: a laptop that fell in water, a drive that no longer starts, a phone with a cracked board. That is exactly what our lab does. X-ray, rework and reballing, nearly 20,000 donor drives and a Class 1 cleanroom let us make the device readable first, and examine it afterwards.

About encryption we are honest: modern encryption (BitLocker, FileVault, a recent iPhone) we do not break. With the password, the recovery key or a key from a management system we can reach the data. Without a key there is often still unencrypted information: logs, metadata, data from before the encryption, or copies on other devices.

More about our lab →

Discretion and security

  • cases in this category are handled by a limited group of staff
  • the work happens in a separate room, with its own storage
  • nothing is recorded in the ordinary case system
  • non-disclosure agreement on request, or following your own template
  • we work to the ISO 27001 standard; certification is under way
  • on request we come on site with a mobile cleanroom, so the device never leaves your building

We have experience as a court-appointed expert and work for police forces and law firms, among others.

What to do, and what not to do

What to do

  • switch the device off and set it aside
  • note who had the device, and when
  • call us before you try anything: we say straight away whether a step could harm the evidence
  • hand the device over sealed, or have us come on site

What not to do

  • keep using the device or restart it
  • run recovery software yourself on the original
  • copy files with the file explorer: that changes timestamps
  • have your own IT department look at the device before a copy exists

Every start of a computer changes hundreds of files. The less happens to the original, the stronger the evidence.

How it works, and what it costs

  1. Intake You call or write. We go through what happened, the question you want answered and which devices are involved.
  2. Acquisition You bring the device, we collect it, or we come on site. The forensic copy is made and hashed.
  3. Examination The examination happens on the copy, aimed at your question.
  4. Report You receive the report, with the findings, the method and the chain of custody. We explain it where needed.

A forensic investigation is priced to the case, because its size depends on the number of devices and on the question. After the intake you know what it costs. If the device has to be repaired first, our normal rates apply.

See the rates →

Why it works here

More about our lab →
  • Nearly 20,000 donor drives The right part is usually ready.
  • X-ray in-house First see, then act.
  • Rework and reballing Chips removed and refitted safely.
  • Our own software Up to hundreds of terabytes.
  • Mobile cleanroom The device stays in your building.
  • Since 1988 Nearly forty years of equipment and experience.

Tell us about your case

Call or write before you touch the device. We say straight away whether a step could harm the evidence, and what the next step is.