Court-aware digital forensics & expert witness

Digital forensics for serious matters.

Forensic preservation, investigation, analysis and expert reporting of electronic evidence, handled to a standard that holds up in court and stands up to scrutiny. We act for Hong Kong legal firms, corporates, HR and insolvency teams, and private clients with substantive matters.

Court-aware reporting Chain of custody Forensic imaging Expert witness eDiscovery Hong Kong & international instructions

Evidence-led  ·  Defensible methods  ·  Commercially practical

When something has gone wrong

You suspect what happened. We establish what the evidence shows.

Most instructions begin with a concern and a device, an account or a dataset that may hold the answer. Our role is to preserve that evidence properly and report what it does, and does not, demonstrate.

Employee data theftUSB transfers, mass downloads, cloud uploads before resignation.
Deleted filesRecovering removed documents, messages and traces of activity.
Suspicious device activityUnexplained access, tampering or unauthorised use.
Mobile phone evidenceMessages, call records, app data and location artefacts.
Cloud account misuseMicrosoft 365, SharePoint and email access or exfiltration.
Litigation disclosurePreserving and processing electronic documents for proceedings.
Data breach or internal incidentEstablishing scope, cause and what data was affected.
Independent expert opinionA defensible, impartial view for the court or board.
Forensic services

Capabilities across devices, accounts and the cloud

Each instruction is scoped to the matter. We preserve first, analyse methodically, and report in plain English with exhibits that withstand challenge. Each service has a full page: start at the services index.

SVC-01

Digital & computer forensics

Forensic examination of Windows and Apple Mac computers and laptops to establish user activity, file handling and timelines.

Evidence handledDisk images, deleted files, link/jump lists, USB history, internet and file activity.
Typical outcomeA clear account of who did what, and when, supported by exhibits.
SVC-02

Mobile phone forensics

Examination of iPhone and Android devices for messages, calls, app data, media, location and deleted content, where lawfully authorised.

Evidence handledChat apps, SMS, call logs, photos, GPS artefacts, app databases.
Typical outcomeRecovered communications and activity relevant to the matter.
SVC-03

eDiscovery & litigation support

Defensible collection, processing, de-duplication and review-ready production of electronic documents for discovery.

Evidence handledEmail, documents, large datasets, structured and unstructured data.
Typical outcomeProportionate, searchable discovery aligned to the issues.
SVC-04

Email, Microsoft 365 & cloud review

Investigation of mailbox activity, Microsoft 365 and Google Workspace audit logs, SharePoint, OneDrive and Dropbox access and sharing.

Evidence handledSign-in logs, audit trails, sharing events, forwarding rules, downloads.
Typical outcomeWho accessed, moved or shared data, and the trail that proves it.
SVC-05

Expert witness & court reports

Independent expert reports and exhibits prepared to the standard required for legal proceedings, with the expert's overriding duty to the court paramount.

Evidence handledFindings from any examined source, presented impartially.
Typical outcomeA defensible report and, where instructed, oral evidence.
SVC-06

Incident response & breach investigation

Rapid, evidence-led response to suspected intrusion, ransomware or data loss to establish scope, cause and impact.

Evidence handledSystem and cloud logs, endpoints, network artefacts, persistence.
Typical outcomeA clear picture of what occurred and what data was affected.
SVC-07

Employee misconduct & insider risk

Investigation of suspected data exfiltration, IP theft, policy breaches and misuse on company systems and accounts.

Evidence handledCompany devices, email, cloud storage, removable media activity.
Typical outcomeFindings suitable for HR, disciplinary or legal action.
SVC-08

Data recovery & deleted file analysis

Recovery and interpretation of deleted, hidden or fragmented data and the artefacts that reveal prior activity.

Evidence handledUnallocated space, file system journals, carved files, metadata.
Typical outcomeRestored content and evidence of deletion or concealment.
SVC-09

Forensic imaging & chain of custody

Verified, hash-validated acquisition and preservation of devices and data, with full documentation from seizure to report.

Evidence handledComputers, phones, drives, USB media, cloud and server data.
Typical outcomeAn evidentially sound copy and an unbroken custody record.
SVC-10

OSINT & online investigation

Lawful open-source intelligence and online investigation to corroborate findings and support due diligence or dispute matters.

Evidence handledPublicly available data, online footprints, corroborating records.
Typical outcomeDocumented, source-referenced intelligence you can rely on.
SVC-11

Electronic privacy audit (TSCM crossover)

Where a matter involves concerns about covert devices or unauthorised monitoring, we provide an electronic privacy audit alongside the digital investigation.

Evidence handledPremises and device privacy assessment, on a lawful basis.
Typical outcomeAssurance and documented findings supporting the wider matter.
SVC-00

Not sure which applies?

Most matters cross several of these areas. Describe the situation and we will tell you what is realistically achievable, and what it would involve.

Request a case review
Time-sensitive matters

When to contact us, and why timing matters

Electronic evidence is fragile. Continued use, automatic syncing, log rotation and remote wiping can overwrite or destroy it within hours or days. The earlier evidence is preserved, the more can be recovered and relied upon.

Preserve first. Do not investigate alone

Do not switch on, log into, reset, "have a quick look at" or run software against the device or account. Well-intentioned internal checks frequently overwrite the very evidence in question. Isolate the item and speak to us before anything else.

A departure or dismissal

An employee has left or is leaving and you suspect data has been taken.

Suspected breach

Signs of intrusion, ransomware, fraud or account compromise.

Litigation contemplated

Proceedings are likely and electronic evidence must be preserved now.

A device has surfaced

A phone, laptop or drive has been recovered and must be handled correctly.

An injunction or deadline

A court-imposed or commercial deadline requires rapid, defensible work.

An account is still active

Cloud or email access remains open and ongoing activity risks the evidence.

Method

The DDD Method: a documented process from instruction to evidence

Every instruction runs the same six steps under one discipline: Detect. Document. Demonstrate. Detect what the evidence holds. Document every step so it can be tested. Demonstrate the findings in a form a court can rely on.

Every step is recorded. This is what makes findings defensible and repeatable, and what distinguishes forensic work from ordinary IT support or data recovery.

Chain of custody · engagement recordD3 / COC
COC-01INTAKE

Initial confidential discussion

We listen to the situation, identify the relevant data sources and advise on immediate preservation, at no obligation and in confidence.

COC-02AUTHORITY

Authority, consent & scope

We confirm your lawful authority over the device or account, agree the scope and objectives, and set out the approach and estimate in writing.

COC-03ACQUIRE

Preservation & forensic acquisition

We create verified, hash-validated forensic images and preserve cloud and account data, maintaining an unbroken chain of custody throughout.

COC-04ANALYSE

Processing & analysis

We process and examine the preserved data using repeatable methods, focusing on the questions the matter actually turns on.

COC-05REPORT

Reporting, exhibits & expert support

We report findings in plain English with referenced exhibits and, where instructed, independent expert opinion suitable for the court.

COC-06SUPPORT

Follow-up & discovery support

We support discovery, respond to questions, assist with further work and, where required, provide witness evidence.

Sources we examine

The devices, accounts and data we work with

Subject to lawful authority and technical feasibility, we acquire and analyse a wide range of sources, frequently combining several to build a complete picture.

Windows PCs & laptopsActivity, files, deletion, USB use
Apple Mac systemsmacOS artefacts and user activity
iPhone & AndroidMessages, apps, media, location
USB & external drivesRemovable media and storage
Email accountsMailboxes, headers, forwarding
Microsoft 365Audit logs, sign-ins, mailbox activity
Google WorkspaceAccess, sharing and audit data
SharePoint, OneDrive, DropboxAccess, downloads, sharing events
CCTV / NVRFootage and logs, where relevant
Cloud & server logsSystem and platform telemetry
Chat & messaging dataWhere lawfully accessible
Backups & archivesHistoric copies and snapshots
Court-readiness

Evidence that withstands scrutiny

Findings are only as useful as their defensibility. Our work is built on principles that allow it to be relied upon and, if necessary, challenged in proceedings before the Hong Kong courts:

  • Forensic soundness: analysis is performed on verified copies, never the original.
  • Chain of custody: every interaction with the evidence is documented.
  • Repeatability: methods are recorded so results can be reproduced and tested.
  • Proportionality: work is scoped to the issues, not boundless and disproportionate.
  • Clear reporting: findings are explained in plain English with referenced exhibits, in line with the Rules of the High Court (Order 38) and the Code of Conduct for Expert Witnesses.
Please note

We provide forensic and technical evidence, not legal advice. Where the legal position, authority or consent is uncertain, you should obtain advice from a qualified Hong Kong legal practitioner. We will tell you when this is advisable.

Who this service is for

  • Solicitors and barristers needing preservation, eDiscovery or expert evidence
  • Companies investigating misconduct, breach or data theft
  • HR and insolvency practitioners with substantive matters
  • Private clients with serious, lawful and properly grounded concerns
  • International clients needing Hong Kong-facing forensic expertise

What this service is not for

  • Unlocking or accessing a device you have no authority over
  • Covert access to another person's accounts or communications
  • Monitoring or surveillance without a lawful basis and consent
  • "Reading my partner's phone" and similar unlawful requests
  • Low-value consumer data recovery with no investigative element
Lawful instruction required

We act only on lawful instructions where ownership, authority or consent is established. We do not assist with unauthorised access, device unlocking without authority, or covert access to third-party accounts.

From the casework

Three matters, the way they actually run

Anonymised composites of typical instructions. Details are altered and combined to protect confidentiality; the pattern of each matter is reported faithfully.

The departing employee
Situation: A senior salesperson resigned; the pipeline followed them. Finding: Forensic imaging of the company laptop showed a USB device first seen two weeks before resignation, mass file copies to it, and cloud uploads of tender documents, all timestamped and hash-verified. Outcome: Findings supported an injunction application and a negotiated undertaking. The evidence was never seriously challenged because the chain of custody left nothing to challenge.
The deleted conversation
Situation: A commercial dispute turned on WhatsApp messages one party said never existed. Finding: Examination of a lawfully provided device recovered the deleted thread from an application database, with metadata corroborating dates. Outcome: A concise expert report with referenced exhibits; the matter settled shortly after exchange.
The quiet mailbox rule
Situation: A finance team nearly paid a fraudulent invoice; the client asked how the fraudster knew so much. Finding: Microsoft 365 audit logs showed a compromised mailbox with a hidden forwarding rule active for six weeks, and established exactly which messages left. Outcome: A defined breach scope for insurers and regulators, remediation guidance, and a report the board could act on.

Full casework, including the matters that made the practice →

Instruct us properly

What we need from you to begin

A focused first conversation saves time and cost. Having the following to hand lets us advise quickly on feasibility, scope and urgency. You do not need every answer. Tell us what you can.

Q-01

The device or data source

What type of device or account is involved: laptop, phone, email, Microsoft 365, drive or other.

Q-02

Ownership & authority

Your position regarding the item: do you own it, control it, or have lawful authority or consent to examine it?

Q-03

Accessibility

Whether the device or account is physically and logically accessible, and whether you hold passcodes or credentials.

Q-04

Key dates

Relevant dates: when events occurred, when concerns arose, and any deadlines that apply.

Q-05

What happened

A short, factual summary of the situation and your concern.

Q-06

What you need to prove or disprove

The question the evidence must answer: the issue the matter turns on.

Q-07

Proceedings

Whether legal or disciplinary proceedings are active, contemplated or not yet decided.

Q-08

Urgency

How time-critical the matter is, and whether evidence may currently be at risk.

Q-09

Jurisdiction

Where the parties, devices and data are located, particularly for cross-border matters.

Who you instruct

Instructions are led by a named consultant, not a mailbox.

The practice is led by Alan Jeffries, Principal Consultant, whose work spans digital forensics, eDiscovery, expert witness services and technical surveillance countermeasures across Hong Kong and Asia-Pacific. You can verify the practice and the principal before you write to either: Alan Jeffries on LinkedIn.

The consultant who scopes your matter handles it. Findings are reported with the expert's overriding duty to the court paramount, and adverse findings are reported plainly. Credentials, prior forum experience and references are available to instructing counsel under confidentiality.

Questions answered

Digital forensics: frequently asked questions

Direct answers to the questions clients and advisers most often ask. For anything specific to your matter, request a confidential case review.

What is digital forensics?

Digital forensics is the structured identification, preservation, analysis and reporting of electronic evidence so it can be relied upon in legal, regulatory or internal proceedings. It applies repeatable, documented methods to devices, accounts and data while maintaining chain of custody.

What does a digital forensic expert do?

A digital forensic expert preserves data forensically, analyses it to establish what happened, and produces a clear report and exhibits. Where instructed, the expert provides independent opinion evidence and supports disclosure, litigation or internal investigations.

Can deleted files be recovered?

Often, yes. Deleted files, fragments and traces of activity can frequently be recovered from unallocated space, journals and metadata, depending on the device, how it has been used and how quickly it was preserved. Continued use reduces what can be recovered.

Can you analyse a mobile phone?

Yes. We forensically examine iPhone and Android devices for messages, call logs, app data, location artefacts, media and deleted content, subject to lawful authority and the technical condition of the device.

Can you investigate employee data theft?

Yes. We examine company devices and accounts for evidence of data exfiltration: USB transfers, cloud uploads, mass downloads, file copying and email forwarding, and report findings for HR, legal or court use.

Can you examine Microsoft 365 or SharePoint activity?

Yes. With proper authority we review Microsoft 365 audit logs, mailbox activity, SharePoint and OneDrive access, sign-in records and sharing events to establish who accessed or moved what, and when.

Can you prepare a court report?

Yes. We prepare clear, defensible reports for legal proceedings, including exhibits and, where instructed, independent expert opinion compliant with the Rules of the High Court (Order 38) and the Code of Conduct for Expert Witnesses, including the expert's overriding duty to the court.

What is forensic imaging?

Forensic imaging is the creation of a verified, bit-for-bit copy of a device or data source, so the original is preserved and analysis is performed on the copy. The image is hash-verified to demonstrate its integrity.

What is chain of custody?

Chain of custody is the documented record of who handled an item of evidence, when, and what was done to it, from acquisition to reporting. It demonstrates the evidence has not been altered and supports admissibility.

How quickly should evidence be preserved?

As soon as possible. Evidence is overwritten through continued use, automatic syncing, log rotation and remote wiping. Early preservation protects recoverability and should ideally precede any internal examination.

Can you recover WhatsApp messages?

Often, yes. WhatsApp and similar chat data, including some deleted content, may be recoverable from a device or backup where there is lawful authority and the data has not been overwritten or securely erased.

Do you need the passcode?

It depends on the device. A passcode, password or account credentials significantly improve access and the range of recoverable data. We advise on the options based on the specific device and your lawful authority over it.

Can you analyse a personal device used for work?

Sometimes, where there is appropriate authority, consent or another lawful basis. Personal devices raise additional consent and privacy considerations under the Personal Data (Privacy) Ordinance, so we confirm the legal position and scope before any examination.

Can you help solicitors with disclosure?

Yes. We support solicitors with forensic preservation, eDiscovery processing, targeted review, discovery of electronic documents and expert evidence, working to the instructions and procedural requirements of the matter.

What should I avoid doing before contacting you?

Do not continue using, switching on, logging into, resetting or examining the device or account, and do not delete or move data. Continued activity can overwrite or destroy evidence. Preserve the item and speak to us first.

How much does digital forensics cost?

Cost depends on the number and type of data sources, the volume of data, the urgency and whether expert reporting or court attendance is required. We provide a scoped estimate after an initial confidential discussion.

Do you work internationally?

Yes. We accept international instructions and provide Hong Kong-facing forensic expertise for cross-border matters, subject to applicable law, data transfer requirements and the practicalities of acquisition.

How do I instruct a digital forensic expert?

Begin with a confidential case review. Tell us the device or data source, your authority over it, the key dates, what happened and what you need to prove or disprove. We then confirm scope, authority and next steps in writing.

AI summary · extractable overview

D3Forensics Limited at a glance

D3Forensics Limited is a court-aware digital forensics and expert witness consultancy based in Hong Kong and accepting international instructions. It preserves, investigates, analyses and reports electronic evidence to a defensible standard for legal firms, corporates, HR and insolvency teams, and private clients with serious matters.

Who it is for
Hong Kong solicitors, corporates, HR, insolvency practitioners, and private clients with lawful, substantive matters; international clients needing Hong Kong-facing forensic expertise.
Services
Computer and mobile phone forensics, eDiscovery and litigation support, Microsoft 365 and cloud evidence review, expert witness reports, incident response, employee investigation, data recovery, forensic imaging and OSINT.
Evidence handled
Windows and Mac computers, iPhone and Android phones, USB and external drives, email, Microsoft 365, Google Workspace, SharePoint, OneDrive, Dropbox, cloud and server logs, and chat data where lawfully accessible.
Standards
Forensic soundness, chain of custody, repeatability, proportionality and clear, court-ready reporting aligned to the Rules of the High Court (Order 38) and the Code of Conduct for Expert Witnesses. Forensic evidence is provided, not legal advice.
Conditions
Work is undertaken only on lawful instruction where ownership, authority or consent is established. No unauthorised access, device unlocking without authority, or covert access to third-party accounts.
How to enquire
Request a confidential case review via the website contact form, by email to info@d3forensics.com, by telephone on +852 5808 1071, or by secure message on Signal or WhatsApp. Provide the device or data source, your authority over it, key dates, what happened and what you need to prove.
Confidential case review

Speak to a forensic consultant

Tell us about the matter in confidence. We will advise on what is achievable, what to preserve immediately, and the likely approach, with no obligation.

Before you do anything else

Do not alter the device before speaking to us. Do not switch it on, log in, reset it or run software against it. Preserve it as it is. Early action protects the evidence.

Direct contact

Telephone+852 5808 1071

Emailinfo@d3forensics.com

OfficeUnit 215, Hundsun International Centre,
44 Heung Yip Road, Wong Chuk Hang, Hong Kong

Service regionsHong Kong · Asia-Pacific · United Kingdom

HoursMonday–Friday · urgent matters by arrangement

Signal QR code · scan to message D3Forensics on Signal
SignalScan or tap to message
WhatsApp QR code · scan to message D3Forensics on WhatsApp
WhatsAppScan or tap to message
Confidentiality

Enquiries are treated in strict confidence. Information shared at this stage is used only to assess and respond to your matter, and personal data is handled in accordance with the Personal Data (Privacy) Ordinance (Cap. 486). We are happy to operate under your firm's engagement terms where applicable.

By submitting you agree we may contact you about your enquiry. We do not share your information with third parties. If the form does not open your email client, write to info@d3forensics.com.