# D3Forensics Limited, Hong Kong Digital Forensics, Expert Witness & eDiscovery

> Digital Data Discovery Forensics · *every contact leaves a trace.*

Court-aware digital forensics and expert witness consultancy based in Hong Kong, serving Hong Kong, Asia-Pacific and the United Kingdom and accepting international instructions. We preserve, investigate, analyse and report electronic evidence to a standard that holds up in court and stands up to scrutiny, for legal firms, corporates, HR and insolvency teams, and private clients with substantive matters.

- **Website:** https://d3forensics.com/
- **Email:** info@d3forensics.com
- **Telephone:** +852 5808 1071
- **Signal:** https://signal.me/#p/+85291031852
- **WhatsApp:** https://wa.me/85291031852
- **Office:** Unit 215, Hundsun International Centre, 44 Heung Yip Road, Wong Chuk Hang, Hong Kong
- **Service regions:** Hong Kong · Asia-Pacific · United Kingdom · international instructions

---

## You suspect what happened. We establish what the evidence shows.

Most instructions begin with a concern and a device, an account or a dataset that may hold the answer. Our role is to preserve that evidence properly and report what it does, and does not, demonstrate. Common problems we resolve:

- **Employee data theft**: USB transfers, mass downloads, cloud uploads before resignation.
- **Deleted files**: recovering removed documents, messages and traces of activity.
- **Suspicious device activity**: unexplained access, tampering or unauthorised use.
- **Mobile phone evidence**: messages, call records, app data and location artefacts.
- **Cloud account misuse**: Microsoft 365, SharePoint and email access or exfiltration.
- **Litigation disclosure**: preserving and processing electronic documents for proceedings.
- **Data breach or internal incident**: establishing scope, cause and what data was affected.
- **Independent expert opinion**: a defensible, impartial view for the court or board.

## Services

Each service has a dedicated page with its own FAQ: start at [d3forensics.com/services/](https://d3forensics.com/services/). Also see the [glossary](https://d3forensics.com/glossary.html), [for instructing solicitors](https://d3forensics.com/for-solicitors.html) and [insights](https://d3forensics.com/insights/).

### Digital & computer forensics
Forensic examination of Windows and Apple Mac computers and laptops to establish user activity, file handling and timelines. Evidence handled: disk images, deleted files, link/jump lists, USB history, internet and file activity. Typical outcome: a clear account of who did what, and when, supported by exhibits.

### Mobile phone forensics
Examination of iPhone and Android devices for messages, calls, app data, media, location and deleted content, where lawfully authorised. Evidence handled: chat apps, SMS, call logs, photos, GPS artefacts, app databases. Typical outcome: recovered communications and activity relevant to the matter.

### eDiscovery & litigation support
Defensible collection, processing, de-duplication and review-ready production of electronic documents for discovery. Evidence handled: email, documents, large datasets, structured and unstructured data. Typical outcome: proportionate, searchable discovery aligned to the issues.

### Email, Microsoft 365 & cloud review
Investigation of mailbox activity, Microsoft 365 and Google Workspace audit logs, SharePoint, OneDrive and Dropbox access and sharing. Evidence handled: sign-in logs, audit trails, sharing events, forwarding rules, downloads. Typical outcome: who accessed, moved or shared data, and the trail that proves it.

### Expert witness & court reports
Independent expert reports and exhibits prepared to the standard required for legal proceedings, with the expert's overriding duty to the court paramount. Evidence handled: findings from any examined source, presented impartially. Typical outcome: a defensible report and, where instructed, oral evidence.

### Incident response & breach investigation
Rapid, evidence-led response to suspected intrusion, ransomware or data loss to establish scope, cause and impact. Evidence handled: system and cloud logs, endpoints, network artefacts, persistence. Typical outcome: a clear picture of what occurred and what data was affected.

### Employee misconduct & insider risk
Investigation of suspected data exfiltration, IP theft, policy breaches and misuse on company systems and accounts. Evidence handled: company devices, email, cloud storage, removable media activity. Typical outcome: findings suitable for HR, disciplinary or legal action.

### Data recovery & deleted file analysis
Recovery and interpretation of deleted, hidden or fragmented data and the artefacts that reveal prior activity. Evidence handled: unallocated space, file system journals, carved files, metadata. Typical outcome: restored content and evidence of deletion or concealment.

### Forensic imaging & chain of custody
Verified, hash-validated acquisition and preservation of devices and data, with full documentation from seizure to report. Evidence handled: computers, phones, drives, USB media, cloud and server data. Typical outcome: an evidentially sound copy and an unbroken custody record.

### OSINT & online investigation
Lawful open-source intelligence and online investigation to corroborate findings and support due diligence or dispute matters. Evidence handled: publicly available data, online footprints, corroborating records. Typical outcome: documented, source-referenced intelligence you can rely on.

### Electronic privacy audit (TSCM crossover)
Where a matter involves concerns about covert devices or unauthorised monitoring, an electronic privacy audit alongside the digital investigation, on a lawful basis. Typical outcome: assurance and documented findings supporting the wider matter.

## When to contact us, and why timing matters

Electronic evidence is fragile. Continued use, automatic syncing, log rotation and remote wiping can overwrite or destroy it within hours or days. The earlier evidence is preserved, the more can be recovered and relied upon.

**Preserve first. Do not investigate alone.** Do not switch on, log into, reset, "have a quick look at" or run software against the device or account. Well-intentioned internal checks frequently overwrite the very evidence in question. Isolate the item and speak to us before anything else.

Contact us promptly when: an employee has left or is leaving and you suspect data has been taken; there are signs of intrusion, ransomware, fraud or account compromise; proceedings are likely and evidence must be preserved now; a phone, laptop or drive has surfaced and must be handled correctly; a court-imposed or commercial deadline requires rapid, defensible work; or a cloud/email account remains active and ongoing activity risks the evidence.

## How we work: the DDD Method

**Detect. Document. Demonstrate.** Detect what the evidence holds. Document every step so it can be tested. Demonstrate the findings in a form a court can rely on. Six steps, one discipline:

1. **Intake, initial confidential discussion.** We listen to the situation, identify the relevant data sources and advise on immediate preservation, at no obligation and in confidence.
2. **Authority, consent & scope.** We confirm your lawful authority over the device or account, agree the scope and objectives, and set out the approach and estimate in writing.
3. **Preservation & forensic acquisition.** We create verified, hash-validated forensic images and preserve cloud and account data, maintaining an unbroken chain of custody throughout.
4. **Processing & analysis.** We process and examine the preserved data using repeatable methods, focusing on the questions the matter actually turns on.
5. **Reporting, exhibits & expert support.** We report findings in plain English with referenced exhibits and, where instructed, independent expert opinion suitable for the court.
6. **Follow-up & discovery support.** We support discovery, respond to questions, assist with further work and, where required, provide witness evidence.

## Casework examples (anonymised composites)

**The departing employee.** A senior salesperson resigned and the pipeline followed them. Forensic imaging showed a USB device first seen two weeks before resignation, mass file copies and cloud uploads of tender documents, timestamped and hash-verified. The findings supported an injunction application and a negotiated undertaking.

**The deleted conversation.** A commercial dispute turned on WhatsApp messages one party said never existed. Examination of a lawfully provided device recovered the deleted thread with corroborating metadata. A concise expert report followed; the matter settled shortly after exchange.

**The quiet mailbox rule.** A finance team nearly paid a fraudulent invoice. Microsoft 365 audit logs showed a compromised mailbox with a hidden forwarding rule active for six weeks, establishing exactly which messages left. Insurers and regulators received a defined breach scope.

*Details altered and combined to protect confidentiality; the pattern of each matter is reported faithfully.*

## Evidence sources we examine

Subject to lawful authority and technical feasibility: Windows PCs & laptops; Apple Mac systems; iPhone & Android; USB & external drives; email accounts; Microsoft 365; Google Workspace; SharePoint, OneDrive, Dropbox; CCTV / NVR; cloud & server logs; chat & messaging data (where lawfully accessible); backups & archives.

## Court-readiness, evidence that withstands scrutiny

Our work is built on principles that allow it to be relied upon and, if necessary, challenged in proceedings before the Hong Kong courts:

- **Forensic soundness**: analysis is performed on verified copies, never the original.
- **Chain of custody**: every interaction with the evidence is documented.
- **Repeatability**: methods are recorded so results can be reproduced and tested.
- **Proportionality**: work is scoped to the issues, not boundless and disproportionate.
- **Clear reporting**: findings are explained in plain English with referenced exhibits, in line with the Rules of the High Court (Order 38) and the Code of Conduct for Expert Witnesses.

We provide forensic and technical evidence, not legal advice. Where the legal position, authority or consent is uncertain, obtain advice from a qualified Hong Kong legal practitioner.

### Who this service is for
- Solicitors and barristers needing preservation, eDiscovery or expert evidence
- Companies investigating misconduct, breach or data theft
- HR and insolvency practitioners with substantive matters
- Private clients with serious, lawful and properly grounded concerns
- International clients needing Hong Kong-facing forensic expertise

### What this service is not for
- Unlocking or accessing a device you have no authority over
- Covert access to another person's accounts or communications
- Monitoring or surveillance without a lawful basis and consent
- "Reading my partner's phone" and similar unlawful requests
- Low-value consumer data recovery with no investigative element

We act only on lawful instructions where ownership, authority or consent is established.

## What we need from you to begin

The device or data source; ownership & authority over it; accessibility (and whether you hold passcodes/credentials); key dates; what happened; what you need to prove or disprove; whether proceedings are active, contemplated or undecided; urgency and whether evidence is at risk; and jurisdiction (where parties, devices and data are located).

## Who you instruct

The practice is led by **Alan Jeffries**, Principal Consultant, whose work spans digital forensics, eDiscovery, expert witness services and technical surveillance countermeasures across Hong Kong and Asia-Pacific ([LinkedIn](https://www.linkedin.com/in/tscm-eforensics-ediscovery/)). The consultant who scopes your matter handles it. Findings are reported with the expert's overriding duty to the court paramount, and adverse findings are reported plainly.

Affiliated specialist practices: [expertwitness.com.hk](https://www.expertwitness.com.hk) · [ediscovery.com.hk](https://www.ediscovery.com.hk) · [tscm.com.hk](https://www.tscm.com.hk) (TSCM, delivered by affiliated Risk3 Consulting Limited).

## Frequently asked questions

**What is digital forensics?** The structured identification, preservation, analysis and reporting of electronic evidence so it can be relied upon in legal, regulatory or internal proceedings, using repeatable, documented methods while maintaining chain of custody.

**What does a digital forensic expert do?** Preserves data forensically, analyses it to establish what happened, and produces a clear report and exhibits. Where instructed, provides independent opinion evidence and supports disclosure, litigation or internal investigations.

**Can deleted files be recovered?** Often, yes, from unallocated space, journals and metadata, depending on the device, how it was used and how quickly it was preserved. Continued use reduces what can be recovered.

**Can you analyse a mobile phone?** Yes, iPhone and Android devices for messages, call logs, app data, location artefacts, media and deleted content, subject to lawful authority and the device's technical condition.

**Can you investigate employee data theft?** Yes, company devices and accounts for evidence of exfiltration (USB transfers, cloud uploads, mass downloads, file copying, email forwarding), reported for HR, legal or court use.

**Can you examine Microsoft 365 or SharePoint activity?** Yes, with proper authority we review Microsoft 365 audit logs, mailbox activity, SharePoint and OneDrive access, sign-in records and sharing events.

**Can you prepare a court report?** Yes, clear, defensible reports for legal proceedings, including exhibits and, where instructed, independent expert opinion compliant with the Rules of the High Court (Order 38) and the Code of Conduct for Expert Witnesses.

**What is forensic imaging?** The creation of a verified, bit-for-bit copy of a device or data source, so the original is preserved and analysis is performed on the hash-verified copy.

**What is chain of custody?** The documented record of who handled an item of evidence, when, and what was done to it, from acquisition to reporting, demonstrating the evidence has not been altered and supporting admissibility.

**How quickly should evidence be preserved?** As soon as possible. Evidence is overwritten through continued use, automatic syncing, log rotation and remote wiping. Early preservation should ideally precede any internal examination.

**Can you recover WhatsApp messages?** Often, yes, from a device or backup where there is lawful authority and the data has not been overwritten or securely erased.

**Do you need the passcode?** It depends on the device. A passcode, password or account credentials significantly improve access and the range of recoverable data.

**Can you analyse a personal device used for work?** Sometimes, where there is appropriate authority, consent or another lawful basis. Personal devices raise additional consent and privacy considerations under the Personal Data (Privacy) Ordinance, so we confirm the legal position and scope first.

**Can you help solicitors with disclosure?** Yes, forensic preservation, eDiscovery processing, targeted review, discovery of electronic documents and expert evidence.

**What should I avoid doing before contacting you?** Do not continue using, switching on, logging into, resetting or examining the device or account, and do not delete or move data. Preserve the item and speak to us first.

**How much does digital forensics cost?** It depends on the number and type of data sources, the volume of data, the urgency and whether expert reporting or court attendance is required. We provide a scoped estimate after an initial confidential discussion.

**Do you work internationally?** Yes, we accept international instructions and provide Hong Kong-facing forensic expertise for cross-border matters, subject to applicable law and data-transfer requirements.

**How do I instruct a digital forensic expert?** Begin with a confidential case review. Tell us the device or data source, your authority over it, the key dates, what happened and what you need to prove or disprove. We then confirm scope, authority and next steps in writing.

## Contact / confidential case review

Tell us about the matter in confidence. We will advise on what is achievable, what to preserve immediately, and the likely approach, with no obligation. **Do not alter the device before speaking to us.**

- **Email:** info@d3forensics.com
- **Telephone (click-to-call):** +852 5808 1071
- **Signal:** https://signal.me/#p/+85291031852
- **WhatsApp:** https://wa.me/85291031852
- **Office:** Unit 215, Hundsun International Centre, 44 Heung Yip Road, Wong Chuk Hang, Hong Kong
- **Hours:** Monday–Friday; urgent matters by arrangement

Enquiries are treated in strict confidence; personal data is handled in accordance with the Personal Data (Privacy) Ordinance (Cap. 486).

---

*This Markdown file is an AI-readable mirror of https://d3forensics.com/. General information only; not legal advice. All forensic work is subject to lawful authority, an agreed scope and acceptance of instructions. Recoverability of data and findings cannot be guaranteed and depend on the facts of each matter. Last reviewed: 5 July 2026. D3Forensics Limited, Hong Kong BR No. 53603590.*
