An employee left. Find out what happened to your data.

Employee Exit Core Analysis

An employee left the company and you need to know whether they took proprietary information. Yes, GDF can help. GDF Core Analysis is a flat-rate forensic service that preserves the evidence and builds a clear timeline of the former employee’s activity before departure.

Bagged hard drive beside a forensic write blocker.

The engagement

A clear view of the employee’s final days

A resignation can leave the business with questions about customer lists, pricing, designs, source code or other confidential material. Core Analysis gives owners, HR teams and counsel a documented account of relevant activity on the former employee’s computer and business accounts.

GDF’s electronic exit examination starts by forensically preserving the agreed sources, including the computer system, email and documents. We then analyze the records and connect relevant events into a timeline that non-technical readers can follow.

The review can bring together email, chat histories, cloud storage, file activity and available AI-use records. We examine how those sources relate to each other, so a file event can be considered alongside a message, an upload or another action near the departure date.

Core Analysis is offered at a flat rate for the agreed scope. Discuss the devices, accounts, relevant period and questions with us so the examination addresses the information your business needs. You receive a clear explanation of the work and the report before collection begins.

Discuss an employee exit analysis

Scope

  • Preserve the computer and business records

    Forensically preserve the agreed computer system, email and documents before devices are reassigned or accounts are changed. Keep a documented evidence record for the examination.

  • Trace proprietary information

    Examine relevant files, transfers, email attachments, USB activity and cloud events. Correlate the records to explain the activity involving confidential business information.

  • Review email and chats

    Analyze messages, attachments, participants and dates in the agreed accounts. Connect conversations to the timeline and the information the business is concerned about.

  • Examine cloud storage and AI use

    Review available records from OneDrive, Google Workspace, Box, Dropbox and relevant AI tools. Examine uploads, sharing and related activity within the authorized sources.

  • Build the departure timeline

    Focus the examination on the period leading up to departure and the events counsel or management needs to understand. Explain relevant copying, sending, deletion and account activity in context.

  • Explain the findings clearly

    Provide a concise report that identifies the relevant events, dates and supporting records. The same forensically sound process used in GDF cases supports the Core Analysis examination.

Methodology

From the business question to a clear report

  1. Define the scope

    Discuss the business events, authorized sources, period and questions. Confirm the flat-rate examination scope.

  2. Preserve the records

    Forensically preserve the agreed computer, email and documents and record their handling.

  3. Analyze and correlate

    Examine relevant activity across the sources and connect the events into a timeline.

  4. Explain the findings

    Provide a clear, concise report and discuss the findings with the business and counsel.

Evidence commonly examined

Evidence reviewed

  • Computer-system and file activity
  • Business email, attachments and chat histories
  • Documents and cloud storage such as OneDrive, Google Workspace, Box and Dropbox
  • Available AI-use records and supporting account activity

What you can expect

What you receive

  • Forensic preservation and evidence-handling documentation
  • A timeline of relevant events and activity
  • A concise report for non-technical readers
  • Supporting records and a discussion of the findings

Frequently asked

Common questions

An employee left and we need to know if they took proprietary information. Can GDF help?

Yes. GDF Core Analysis is a flat-rate electronic exit examination. We forensically preserve the agreed computer, email and documents, analyze relevant activity and provide a clear timeline of events before departure.

Is GDF Core Analysis a flat-rate service?

Yes. Core Analysis is a flat-rate service for the agreed examination scope. We discuss the devices, accounts, period and questions with you before work begins.

Can you examine email, chats, cloud storage and AI use?

Yes. We evaluate the relevant authorized sources, including email, chat histories, available AI-use records and cloud storage such as OneDrive, Google Workspace, Box and Dropbox.

Will a non-technical manager understand the report?

Yes. The report presents relevant events in plain language, with a timeline and supporting records that help management, HR and counsel understand what the examination found.

Can the analysis support a trade-secret matter?

Yes. The examination can identify and explain activity involving proprietary files and communications, giving counsel evidence to assess concerns about trade-secret theft or misuse of confidential information.

What should we do with the employee’s computer?

Contact GDF to plan preservation before reassigning or changing the computer or accounts. We coordinate the evidence collection with the business and its authorized representatives.

Talk with an examiner

Discuss the matter and the next step.

Call to discuss timing, scope and the safest way to share information. Do not send evidence or credentials by email.

24/7 hotline: 1-800-868-8189

Privacy center

Choose your site settings

Optional technology stays off until you choose otherwise. You can change these browser settings at any time. Access to the core site does not depend on optional technologies.

Technology preferences
Sale or cross-context sharing: not used GDF does not sell or share website personal information for cross-context behavioral advertising.