Corporate evidence

Trade Secret & Employee Forensics

Establish what information moved, when it moved, how it moved and which conclusions the surviving evidence can support.

Bagged hard drive beside a forensic write blocker.

The engagement

Preserve the transfer path early

Departing-employee and insider matters move quickly. Laptops are reissued, cloud logs expire, mobile devices leave the company and routine synchronization obscures the sequence of events.

GDF coordinates preservation with counsel, examines endpoint and cloud activity, and reconstructs transfer paths across USB devices, personal accounts, messaging, file-sharing services and remote access. Findings are framed for injunction, internal decision-making or later testimony without assuming that suspicious activity proves intent.

Scope

  • Electronic exit examinations

    Targeted preservation and review of company devices and accounts before reassignment or departure.

  • USB and removable media analysis

    Connection history and file activity assessed against available devices and system artifacts.

  • Cloud and personal-account activity

    Authorized review of synchronization, upload, sharing and browser artifacts across relevant platforms.

  • Deletion and anti-forensic behavior

    Assessment of wiping, cleanup, log removal and other activity without treating tool use alone as proof of intent.

  • Document provenance

    Comparison of versions, metadata, paths and surrounding activity to establish a defensible file history.

  • Injunction and testimony support

    Rapid factual reporting, declarations, exhibits and expert support aligned to the litigation schedule.

Methodology

How the examination works

  1. Preserve

    Secure devices and short-lived account logs before reimaging, offboarding or normal retention changes them.

  2. Frame

    Define the protected information, relevant period, custodians and suspected pathways with counsel.

  3. Trace

    Correlate access, copying, upload, deletion and account activity across the evidence sources.

  4. Support

    Deliver findings in the form needed for business action, injunction practice or expert testimony.

Evidence commonly examined

Evidence reviewed

  • Issued computers and mobile devices
  • USB and external storage
  • Email and cloud audit records
  • File shares and source repositories
  • Browser and synchronization artifacts
  • HR, access-control and timeline records

What you can expect

What you receive

  • Rapid preservation and triage memorandum
  • File-transfer and access timeline
  • Artifact schedules and demonstrative exhibits
  • Declaration, deposition and trial support

Frequently asked

Common questions

Can you tell whether files were copied to USB?

System artifacts may show device connections and file activity, but the strength of the conclusion depends on the operating system, retained logs and whether the media is available.

Should IT inspect the laptop first?

Routine inspection can change timestamps and other evidence. Preserve the device and call before opening files, running cleanup tools or reissuing it.

Can you work through outside counsel?

Yes. Counsel can structure the engagement and determine how privilege or work-product considerations apply.

Talk with an examiner

Discuss the matter and the next step.

Call to discuss timing, scope and the safest way to share information. Do not send evidence or credentials by email.

24/7 hotline: 1-800-868-8189

Privacy center

Choose your site settings

Optional technology stays off until you choose otherwise. You can change these browser settings at any time. Access to the core site does not depend on optional technologies.

Technology preferences
Sale or cross-context sharing: not used GDF does not sell or share website personal information for cross-context behavioral advertising.