Answers for attorneys and business leaders

Digital Forensics FAQ

Need to preserve evidence, understand an employee departure or prepare for testimony? Start with these practical answers about digital forensic services and the work GDF delivers.

Discuss your evidence and case needs

Bagged hard drive beside a forensic write blocker.

What digital forensics can establish

Digital forensics preserves and examines information from computers, mobile devices, email and cloud systems. GDF connects file activity, messages, sign-ins and sharing records to explain what happened, when it happened and which records support the findings.

A useful examination begins with a business or case question. That question guides the sources we collect, the time period we examine and the report we prepare. Our computer, email and cloud forensic service brings those sources together.

What happens after you contact GDF

  1. Discuss the matter. Tell us the question, relevant people and organizations, devices or accounts, and deadline.
  2. Agree on scope and cost. We explain collection, analysis and reporting options, including the flat-rate Core Analysis service for an agreed departure review.
  3. Preserve and examine. We coordinate access, collect evidence using documented procedures, verify integrity and analyze the relevant activity.
  4. Use the findings. Receive an understandable report, supporting records and the expert or discovery assistance your matter needs.

Discuss your evidence and case needs

Tell us what happened and which devices or accounts may hold the answer. We can explain collection options and the next step.

Discuss your evidence and case needs Call 1-800-868-8189

Evidence preservation and clear reporting

Professional collection retains original messages, attachments, file information and relevant logs together with a record of their handling. Chain of custody identifies the source and transfer history; integrity checks help establish that collected data has been preserved.

The report connects each finding to its supporting evidence. A timeline can show a file being created, attached to an email and shared through cloud storage. Counsel receives an explanation that can be used in a client discussion, discovery review, deposition or testimony.

For background on digital-evidence handling, see the NIST guide to integrating forensic techniques. GDF applies an examination plan suited to the evidence and assignment.

Choose the service your matter needs

Explore Microsoft 365 email forensics, Google Workspace forensics, remote mobile collection, employee data-theft analysis and eDiscovery support. Our forensic expert profiles describe relevant experience and qualifications.

Frequently asked

Common questions

Can you collect evidence remotely?

Yes. GDF collects email and cloud evidence remotely and coordinates supported computer and mobile collection workflows. We plan access with the account holder or authorized administrator and document the collection.

Can my client keep using their phone?

Yes. Our remote mobile collection service lets clients retain their phones. We guide the client through connecting the phone to a computer and the collection setup, making the process convenient for clients and counsel.

Can users keep using their email account during collection?

Yes. Routine remote email collection allows users to continue working in their accounts. We agree on the access and preservation plan before collection begins.

Can GDF tell whether an employee took proprietary information?

Yes. We examine computer activity, email, chats, cloud sharing and relevant records to trace the movement of company information. Core Analysis offers flat-rate preservation and an activity timeline for the agreed scope.

Can you determine whether email is authentic or altered?

Yes. GDF examines original messages, headers, attachments, mailbox records and related logs. We explain the authentication findings and the evidence supporting them.

How much does a forensic examination cost?

Cost follows the questions, sources, data volume and deliverables. We discuss those details before engagement. For employee exits, executive departures and partner separations, ask about flat-rate Core Analysis for the agreed scope.

Can you help with an eDiscovery stipulation and a limited budget?

Yes. GDF helps review collection requirements, keyword lists and production specifications. Focused processing, internal tools and cost-effective hosting help control the work and review volume.

What do I receive from the examination?

The agreed deliverables can include a collection inventory, chain-of-custody records, an activity timeline, relevant data, a clear forensic report and supporting exhibits. We also provide expert reports and testimony when retained.

Can your experts explain the findings in court?

Yes. Our experts prepare reports, affidavits and declarations and provide deposition and trial testimony. We make complex technology understandable to judges, juries and counsel.

How do you approach deleted information?

We assess the device, backups, cloud versions and other sources to choose the appropriate recovery and examination methods. The collection plan identifies the evidence to preserve and the work needed to examine it.

Talk through your evidence question

Find regional collection and engagement information or meet the forensic team. Ask about the collection method and report format that fit your matter.

Discuss your evidence and case needs

Call to discuss your next step and arrange secure information sharing.

Discuss your evidence and case needs Call 1-800-868-8189

Privacy center

Choose your site settings

Optional technology stays off until you choose otherwise. You can change these browser settings at any time. Access to the core site does not depend on optional technologies.

Technology preferences
Sale or cross-context sharing: not used GDF does not sell or share website personal information for cross-context behavioral advertising.