Answers for attorneys and business leaders
Digital Forensics FAQ
Need to preserve evidence, understand an employee departure or prepare for testimony? Start with these practical answers about digital forensic services and the work GDF delivers.
What digital forensics can establish
Digital forensics preserves and examines information from computers, mobile devices, email and cloud systems. GDF connects file activity, messages, sign-ins and sharing records to explain what happened, when it happened and which records support the findings.
A useful examination begins with a business or case question. That question guides the sources we collect, the time period we examine and the report we prepare. Our computer, email and cloud forensic service brings those sources together.
What happens after you contact GDF
- Discuss the matter. Tell us the question, relevant people and organizations, devices or accounts, and deadline.
- Agree on scope and cost. We explain collection, analysis and reporting options, including the flat-rate Core Analysis service for an agreed departure review.
- Preserve and examine. We coordinate access, collect evidence using documented procedures, verify integrity and analyze the relevant activity.
- Use the findings. Receive an understandable report, supporting records and the expert or discovery assistance your matter needs.
Discuss your evidence and case needs
Tell us what happened and which devices or accounts may hold the answer. We can explain collection options and the next step.
Evidence preservation and clear reporting
Professional collection retains original messages, attachments, file information and relevant logs together with a record of their handling. Chain of custody identifies the source and transfer history; integrity checks help establish that collected data has been preserved.
The report connects each finding to its supporting evidence. A timeline can show a file being created, attached to an email and shared through cloud storage. Counsel receives an explanation that can be used in a client discussion, discovery review, deposition or testimony.
For background on digital-evidence handling, see the NIST guide to integrating forensic techniques. GDF applies an examination plan suited to the evidence and assignment.
Choose the service your matter needs
Explore Microsoft 365 email forensics, Google Workspace forensics, remote mobile collection, employee data-theft analysis and eDiscovery support. Our forensic expert profiles describe relevant experience and qualifications.
Frequently asked
Common questions
Can you collect evidence remotely?
Yes. GDF collects email and cloud evidence remotely and coordinates supported computer and mobile collection workflows. We plan access with the account holder or authorized administrator and document the collection.
Can my client keep using their phone?
Yes. Our remote mobile collection service lets clients retain their phones. We guide the client through connecting the phone to a computer and the collection setup, making the process convenient for clients and counsel.
Can users keep using their email account during collection?
Yes. Routine remote email collection allows users to continue working in their accounts. We agree on the access and preservation plan before collection begins.
Can GDF tell whether an employee took proprietary information?
Yes. We examine computer activity, email, chats, cloud sharing and relevant records to trace the movement of company information. Core Analysis offers flat-rate preservation and an activity timeline for the agreed scope.
Can you determine whether email is authentic or altered?
Yes. GDF examines original messages, headers, attachments, mailbox records and related logs. We explain the authentication findings and the evidence supporting them.
How much does a forensic examination cost?
Cost follows the questions, sources, data volume and deliverables. We discuss those details before engagement. For employee exits, executive departures and partner separations, ask about flat-rate Core Analysis for the agreed scope.
Can you help with an eDiscovery stipulation and a limited budget?
Yes. GDF helps review collection requirements, keyword lists and production specifications. Focused processing, internal tools and cost-effective hosting help control the work and review volume.
What do I receive from the examination?
The agreed deliverables can include a collection inventory, chain-of-custody records, an activity timeline, relevant data, a clear forensic report and supporting exhibits. We also provide expert reports and testimony when retained.
Can your experts explain the findings in court?
Yes. Our experts prepare reports, affidavits and declarations and provide deposition and trial testimony. We make complex technology understandable to judges, juries and counsel.
How do you approach deleted information?
We assess the device, backups, cloud versions and other sources to choose the appropriate recovery and examination methods. The collection plan identifies the evidence to preserve and the work needed to examine it.
Talk through your evidence question
Find regional collection and engagement information or meet the forensic team. Ask about the collection method and report format that fit your matter.
Discuss your evidence and case needs
Call to discuss your next step and arrange secure information sharing.