Digital evidence and security
San Francisco Computer Forensics
Device, cloud and software evidence for San Francisco business disputes and technical security decisions.
Start with the question the evidence needs to answer
A cloud-first company can have a substantial evidence record without a central file server. Source code, identity events, collaboration messages and local caches may sit in different administrative boundaries. GDF helps San Francisco clients identify those boundaries and preserve the records that answer the actual question.
An export is only useful if its meaning and limitations are understood. Record the account, collection method, date range and fields included. Distinguish provider-generated audit events from user-supplied content, and identify what the subscription or retention settings made unavailable.
Evidence priorities in San Francisco and the Bay Area
San Francisco's economic-development material identifies business activity across the Financial District, south of Market and Mission Bay. For an organization operating across those areas or remotely, the location of a custodian is separate from the location and control of the evidence.
Scope the work to the matter
Repository and software evidence
A code dispute may depend on commit history, branches, release artifacts and access controls rather than a single source-file comparison. Preserve the relevant versions and record repository identity and export method. Explain whether a conclusion concerns similarity, access, authorship or deployment; those are different technical questions.
Cloud identity and collaboration
Collect available sign-in, administrative, sharing and messaging records within the authorized scope. Reconcile account identifiers and time zones before building a timeline. A display name is not a reliable identity key, and a successful login does not establish which person physically used an account.
Application and AI security boundaries
For a software or AI-enabled workflow, examine which users and services can access data or invoke tools. Testing should address authorization, tenant separation, retrieval permissions and logging within agreed boundaries. Model behavior alone is not a complete assessment of the surrounding implementation.
Services available through GDF
Use the technical service pages for methods, evidence sources and deliverables.
- Computer and hard drive forensics
- Mobile device forensics
- Email and cloud evidence
- Expert witness support
- Penetration testing
- Vulnerability assessments
- Application penetration testing
- Incident response
- eDiscovery collections
- Departing employee analysis
- Evidence-aware data recovery
- OT and SCADA security
- AI security consulting
Arrange an evidence or security consultation
For a San Francisco engagement, identify the tenants, repositories and devices involved, the administrators who can provide access and any accounts scheduled for closure. Explain whether the immediate need is preservation, an independent technical opinion or a scoped security test.
Frequently asked
Questions about San Francisco engagements
Can cloud records be collected without taking every device?
Sometimes. The right approach depends on the question and the records available from the provider. Local caches, downloads and device activity may still be important even when the business system is hosted.
Does a hash establish who created a file?
No. A cryptographic hash can help verify that the same bytes were retained. Authorship, access and timing require other evidence and an explanation of its reliability.
Before collecting evidence
For an active incident, call 1-800-868-8189.
Talk with an examiner
Discuss the matter and the next step.
Call to discuss timing, scope and the safest way to share information. Do not send evidence or credentials by email.
24/7 hotline: 1-800-868-8189