Corporate evidence
Trade Secret & Employee Forensics
Establish what information moved, when it moved, how it moved and which conclusions the surviving evidence can support.
The engagement
Preserve the transfer path early
Departing-employee and insider matters move quickly. Laptops are reissued, cloud logs expire, mobile devices leave the company and routine synchronization obscures the sequence of events.
GDF coordinates preservation with counsel, examines endpoint and cloud activity, and reconstructs transfer paths across USB devices, personal accounts, messaging, file-sharing services and remote access. Findings are framed for injunction, internal decision-making or later testimony without assuming that suspicious activity proves intent.
Scope
Electronic exit examinations
Targeted preservation and review of company devices and accounts before reassignment or departure.
USB and removable media analysis
Connection history and file activity assessed against available devices and system artifacts.
Cloud and personal-account activity
Authorized review of synchronization, upload, sharing and browser artifacts across relevant platforms.
Deletion and anti-forensic behavior
Assessment of wiping, cleanup, log removal and other activity without treating tool use alone as proof of intent.
Document provenance
Comparison of versions, metadata, paths and surrounding activity to establish a defensible file history.
Injunction and testimony support
Rapid factual reporting, declarations, exhibits and expert support aligned to the litigation schedule.
Methodology
How the examination works
-
Preserve
Secure devices and short-lived account logs before reimaging, offboarding or normal retention changes them.
-
Frame
Define the protected information, relevant period, custodians and suspected pathways with counsel.
-
Trace
Correlate access, copying, upload, deletion and account activity across the evidence sources.
-
Support
Deliver findings in the form needed for business action, injunction practice or expert testimony.
Evidence commonly examined
Evidence reviewed
- Issued computers and mobile devices
- USB and external storage
- Email and cloud audit records
- File shares and source repositories
- Browser and synchronization artifacts
- HR, access-control and timeline records
What you can expect
What you receive
- Rapid preservation and triage memorandum
- File-transfer and access timeline
- Artifact schedules and demonstrative exhibits
- Declaration, deposition and trial support
Frequently asked
Common questions
Can you tell whether files were copied to USB?
System artifacts may show device connections and file activity, but the strength of the conclusion depends on the operating system, retained logs and whether the media is available.
Should IT inspect the laptop first?
Routine inspection can change timestamps and other evidence. Preserve the device and call before opening files, running cleanup tools or reissuing it.
Can you work through outside counsel?
Yes. Counsel can structure the engagement and determine how privilege or work-product considerations apply.
Related capabilities
Related services
Talk with an examiner
Discuss the matter and the next step.
Call to discuss timing, scope and the safest way to share information. Do not send evidence or credentials by email.
24/7 hotline: 1-800-868-8189