Digital evidence and security

San Francisco Computer Forensics

Device, cloud and software evidence for San Francisco business disputes and technical security decisions.

Bagged hard drive beside a forensic write blocker.

Start with the question the evidence needs to answer

A cloud-first company can have a substantial evidence record without a central file server. Source code, identity events, collaboration messages and local caches may sit in different administrative boundaries. GDF helps San Francisco clients identify those boundaries and preserve the records that answer the actual question.

An export is only useful if its meaning and limitations are understood. Record the account, collection method, date range and fields included. Distinguish provider-generated audit events from user-supplied content, and identify what the subscription or retention settings made unavailable.

Evidence priorities in San Francisco and the Bay Area

San Francisco's economic-development material identifies business activity across the Financial District, south of Market and Mission Bay. For an organization operating across those areas or remotely, the location of a custodian is separate from the location and control of the evidence.

City of San Francisco: business context

Scope the work to the matter

Repository and software evidence

A code dispute may depend on commit history, branches, release artifacts and access controls rather than a single source-file comparison. Preserve the relevant versions and record repository identity and export method. Explain whether a conclusion concerns similarity, access, authorship or deployment; those are different technical questions.

Related service detail

Cloud identity and collaboration

Collect available sign-in, administrative, sharing and messaging records within the authorized scope. Reconcile account identifiers and time zones before building a timeline. A display name is not a reliable identity key, and a successful login does not establish which person physically used an account.

Related service detail

Application and AI security boundaries

For a software or AI-enabled workflow, examine which users and services can access data or invoke tools. Testing should address authorization, tenant separation, retrieval permissions and logging within agreed boundaries. Model behavior alone is not a complete assessment of the surrounding implementation.

Related service detail

Arrange an evidence or security consultation

For a San Francisco engagement, identify the tenants, repositories and devices involved, the administrators who can provide access and any accounts scheduled for closure. Explain whether the immediate need is preservation, an independent technical opinion or a scoped security test.

Frequently asked

Questions about San Francisco engagements

Can cloud records be collected without taking every device?

Sometimes. The right approach depends on the question and the records available from the provider. Local caches, downloads and device activity may still be important even when the business system is hosted.

Does a hash establish who created a file?

No. A cryptographic hash can help verify that the same bytes were retained. Authorship, access and timing require other evidence and an explanation of its reliability.

Talk with an examiner

Discuss the matter and the next step.

Call to discuss timing, scope and the safest way to share information. Do not send evidence or credentials by email.

24/7 hotline: 1-800-868-8189

Privacy center

Choose your site settings

Optional technology stays off until you choose otherwise. You can change these browser settings at any time. Access to the core site does not depend on optional technologies.

Technology preferences
Sale or cross-context sharing: not used GDF does not sell or share website personal information for cross-context behavioral advertising.