Company information, departures and digital evidence
Employee Data Theft & Trade Secret Forensics
An employee left and you need to know whether they took proprietary information. GDF preserves the computer, email and cloud evidence, traces information movement and gives counsel and business leaders a clear activity timeline.
Reports built for counsel and business leaders
Robert Knudsen's experience includes computer and mobile examinations, evidence handling and expert testimony. GDF documents the activity behind its findings and explains the timeline in language a business decision-maker can use.
Start with flat-rate GDF Core Analysis
Core Analysis is a flat-rate forensic service for an agreed departure-review scope. It preserves relevant email, documents and computer evidence and produces a timeline showing the activity around the departure.
Choose employee exit Core Analysis, executive departure Core Analysis or business partner separation Core Analysis. Each service gives decision-makers an understandable starting account of the evidence.
A broader trade-secret examination can follow identified transfer paths, examine additional sources and prepare detailed exhibits and expert opinions for the dispute.
Trace company files, email and cloud transfers
Relevant activity can include email to an outside account, a shared-folder download, USB copying, synchronization to personal storage or messages discussing a transfer. We correlate computer records with email, cloud activity, chat histories and available AI-use records.
The examination follows the information you identify: customer lists, pricing, source code, designs, business plans or other proprietary records. File versions, timestamps, account identifiers and communications help connect the activity into a supported sequence.
Discuss the information and departure timeline
Start with the proprietary files and the events that raised concern. We can connect computer activity, email, cloud sharing and messages into a documented account of what happened.
A timeline that answers the business question
For an illustrative departure scenario, counsel may ask whether a project folder moved shortly before an employee resigned. The examination can compare file activity on the laptop, a connected USB device, cloud sharing events and email attachments around that period.
The report explains each event, its source and its relationship to the question. Counsel receives the technical findings needed to assess next steps, request additional records and prepare the matter.
Preserve the record during offboarding
Coordinate the preservation plan with HR, counsel and IT before the device is reassigned or the account is closed. GDF identifies the relevant computers, mailboxes, cloud files, logs and date ranges, then documents collection and chain of custody.
Remote email and cloud collection supports employees and administrators working from different locations. Explore Microsoft 365, Google Workspace and cloud application forensics for source-specific services.
From early findings to discovery and testimony
We can prepare a focused early findings memorandum, a detailed transfer timeline, file comparisons, relevant communications and demonstrative exhibits. eDiscovery services organize the collected material for review and agreed production.
Our expert witnesses prepare reports, declarations and testimony that explain the technical evidence. The work can support counsel evaluating trade-secret theft, confidentiality disputes or alleged breaches of fiduciary duty.
Arrange the examination where your team works
Tell us where the people and devices are located, who administers the accounts and which deadlines affect preservation. We coordinate the evidence plan across offices, remote workers and outside counsel.
Use the GDF locations hub to find regional engagement information, or contact the forensic team directly to discuss the information and departure timeline.
Evidence reviewed
- Authorized accounts, files and messages within scope
- Relevant activity logs and supporting device records
- Collection and chain-of-custody documentation
What you receive
- Evidence inventory and documented findings
- Activity timelines and relevant exhibits
- Review-ready material, reports and expert support
Frequently asked
Common questions
Can you analyze employee email theft?
Yes. GDF examines messages, attachments, forwarding, account activity and related computer or cloud records to trace the movement of company information and explain the findings.
Can you determine whether company files were copied to USB?
We examine USB connection records, file activity, device artifacts and relevant storage media to establish the recorded copying and transfer activity.
Is Core Analysis different from a full trade-secret examination?
Core Analysis provides preservation and an activity timeline at a flat rate for the agreed scope. A broader examination can follow additional sources and technical questions, with detailed reporting, discovery support and testimony.
Can you examine an executive or former business partner?
Yes. GDF has distinct Core Analysis services for executive departures and business partner separations, with collection and examination tailored to the authorized records and business questions.
Can you work directly with our attorney?
Yes. We coordinate scope, evidence handling, deadlines and deliverables with counsel and the authorized business contacts.
Can collection include remote workers?
Yes. We coordinate remote collection of email and cloud accounts and plan the appropriate process for relevant computers and phones. Tell us where the devices and account administrators are located.
Follow the movement of company information
Find regional collection and engagement information or meet the forensic team. Ask about the collection method and report format that fit your matter.
Discuss the information and departure timeline
Call to discuss your next step and arrange secure information sharing.