Cloud testimony practice

Cloud and SaaS Expert Witness for Federal Matters

Party-retained testimony on Microsoft 365, Google Workspace, AWS, Azure, Slack, Teams, Salesforce and other enterprise SaaS: preservation adequacy, production sufficiency and cross-tenant correlation for federal court and MDL.

Bagged hard drive beside a forensic write blocker.

The engagement

Cloud evidence explained in the units the tribunal will decide on

Federal court cloud disputes turn on preservation adequacy, production sufficiency and provider-specific record availability. FRCP 26 and 34 govern the production; FRCP 37(e) governs sanctions for spoliation of electronically stored information; the underlying question is always the same, which is what the provider actually kept, for how long, under which license and audit configuration, and whether the production reasonably reflects it.

The technical examination answers those questions from the produced record. It compares tenant configuration exports, license and audit settings, retention policies, connector and OAuth grants, and the actual provider-side records that survived to the collection date. The opinion states, for each source, what was available, what was collected, and what would have been available at earlier points that has since aged out.

Coverage spans Microsoft 365 and Entra, Google Workspace, AWS CloudTrail and S3, Azure Activity and Azure AD, Salesforce, Slack, Microsoft Teams, Box, Dropbox, Zoom, Okta and Duo, and the connector and audit exports that surround them. The opinion is written so a rebuttal examiner can pull the same provider records using the same queries and reach a reproducible conclusion.

Scope

  • Preservation and production adequacy analysis

    Review of preservation notices, tenant configuration exports, retention-policy changes, connector activity and produced records. Technical findings on preservation timing, scope and production coverage for counsel's FRCP 37(e) analysis. Counsel determines the legal significance.

  • Microsoft 365 and Entra examination

    Unified audit log completeness, mailbox retention, message trace availability, Entra sign-in and identity-protection records, inbox rules, OAuth application consents and administrative-change history. E5 license capability compared against actual audit-configuration state.

  • AWS, Azure and cloud infrastructure

    CloudTrail management and data-event coverage, S3 access logs, Athena queries against the trail archive, Azure Activity and Azure AD sign-in exports, IAM policy history, KMS audit records and network-flow-log retention.

  • Salesforce, ServiceNow and enterprise SaaS

    Field-history tracking, Setup audit trail, Event Monitoring logs, integration user and connected-app grants, and API-side production analysis. Coverage across Salesforce, ServiceNow, Workday and comparable enterprise systems where the record supports it.

  • Slack, Teams, Zoom and collaboration

    Workspace exports, channel and DM completeness, retention overrides, connector activity, Teams eDiscovery premium exports and Zoom cloud recording and audit-log retention. Chain-of-custody documented across export tooling.

  • Cross-source correlation and timeline reconstruction

    Sign-in, mailbox, content, sharing and endpoint events correlated on one normalized timeline with provider identifiers retained. Time-zone conventions stated. Reproducibility appendix so a rebuttal examiner can re-run the correlation.

  • Rebuttal and FRCP 37(e) motion support

    Rebuttal declarations on opposing cloud expert reports, technical support for counsel addressing FRCP 37(e), and question sets for cloud fact witnesses and administrators.

Methodology

How the cloud expert engagement runs

  1. Retention and cloud-tenant scope

    Retention letter, conflict check across cloud providers and connected applications, and a scope note stating the cloud sources the opinion will address, the review period and the license and audit configuration relevant to the analysis.

  2. Preservation and production reconciliation

    Reconciliation of preservation notices, tenant configuration and produced records against the actual provider-side retention available at the collection date. Gaps become documented limits, not silent omissions.

  3. Report drafting under FRE 702

    A written expert report stating what each provider kept, what was collected, what has aged out, and how the events correlate on one timeline. Every opinion is tied to a specific artifact and a specific query.

  4. Deposition, hearing and trial testimony

    Preparation, deposition in person or by remote hookup, testimony at hearing or trial bounded by the report, and post-testimony workpaper retention for appellate review.

Evidence commonly examined

Evidence reviewed

  • Tenant configuration and license exports (Microsoft 365, Entra, Google Workspace)
  • AWS CloudTrail archives, S3 access logs, Athena query records
  • Slack, Teams and Zoom workspace and audit exports
  • Salesforce Setup audit trail, field history and Event Monitoring logs
  • Preservation-notice records and litigation-hold configuration
  • Opposing cloud expert reports, workpapers and tool output
  • Court orders, protective orders and ESI protocol stipulations

What you can expect

What you receive

  • Technical report on preservation timing, scope and production coverage
  • Cross-source event timeline with time-zone conventions stated
  • Reproducibility appendix with queries, ranges, counts and checksums
  • Rebuttal declaration on opposing cloud expert reports
  • Technical declaration supporting counsel's FRCP 37(e) analysis on request
  • Deposition and trial testimony bounded by the report

Frequently asked

Common questions

Does an E5 license mean the audit record exists for the relevant period?

No. E5 provides capability. Whether the record exists depends on the actual audit configuration, retention policy, event age and any provider-side changes for the period. The report states what was available at the collection date rather than what the license theoretically allowed.

Do you take FRCP 37(e) spoliation work on either side?

The technical work may support plaintiff or defense counsel. It is grounded in tenant configuration and provider records, while counsel and the court determine the legal consequences under FRCP 37(e).

Can you testify on Salesforce or ServiceNow evidence, not just Microsoft 365 and Google Workspace?

Yes. Enterprise SaaS coverage includes Salesforce field-history and Event Monitoring, ServiceNow, Workday and comparable systems where the record supports it. The report states what the platform actually preserved and what would require additional production.

How do you handle a case where the provider has been changed or the tenant migrated during the relevant period?

Migration and provider changes are documented on the tenant configuration timeline. The report states which records survived migration, which were transformed and which cannot be recovered because they were not preserved in transit.

Can you appear in ITC 337 and Federal Circuit cloud-related matters?

Yes. The examiner has testified in federal district court and can appear in ITC 337 proceedings, arbitration and multidistrict litigation. Any appearance follows the tribunal's rules and the terms of the retention.

Talk with an examiner

Discuss the matter and the next step.

Call to discuss timing, scope and the safest way to share information. Do not send evidence or credentials by email.

24/7 hotline: 1-800-868-8189

Privacy center

Choose your site settings

Optional technology stays off until you choose otherwise. You can change these browser settings at any time. Access to the core site does not depend on optional technologies.

Technology preferences
Sale or cross-context sharing: not used GDF does not sell or share website personal information for cross-context behavioral advertising.