Services · Hong Kong & Asia-Pacific
Eleven ways evidence problems arrive. One discipline behind all of them.
Every service below runs under the DDD Method: Detect. Document. Demonstrate. Verified acquisition, documented method, findings a court can rely on.
Digital & computer forensics
Windows and Mac examination: user activity, file movement, USB history, timelines. Full detail →
Windows and Mac examination: user activity, file movement, USB history, timelines. Full detail →
Mobile phone forensics
iPhone and Android: messages, calls, app data, locations and deleted content. Full detail →
iPhone and Android: messages, calls, app data, locations and deleted content. Full detail →
eDiscovery & litigation support
Defensible collection, processing and review-ready production for proceedings. Full detail →
Defensible collection, processing and review-ready production for proceedings. Full detail →
Email, Microsoft 365 & cloud review
Audit logs, mailbox rules, sign-ins, sharing: what happened and what left. Full detail →
Audit logs, mailbox rules, sign-ins, sharing: what happened and what left. Full detail →
Expert witness & court reports
Independent opinion under Order 38, with oral evidence where instructed. Full detail →
Independent opinion under Order 38, with oral evidence where instructed. Full detail →
Incident response & breach investigation
Intrusion, ransomware and data loss: scope, cause and impact, evidenced. Full detail →
Intrusion, ransomware and data loss: scope, cause and impact, evidenced. Full detail →
Employee misconduct & insider risk
Data exfiltration and IP theft investigated across devices and accounts. Full detail →
Data exfiltration and IP theft investigated across devices and accounts. Full detail →
Data recovery & deleted file analysis
Deleted, hidden and fragmented data recovered and interpreted. Full detail →
Deleted, hidden and fragmented data recovered and interpreted. Full detail →
Forensic imaging & chain of custody
Hash-verified acquisition with an unbroken custody record. Full detail →
Hash-verified acquisition with an unbroken custody record. Full detail →
OSINT & online investigation
Lawful open-source intelligence with documented provenance. Full detail →
Lawful open-source intelligence with documented provenance. Full detail →
Electronic privacy audit (TSCM)
Spyware assessment and, with Risk3 Consulting, physical counter-surveillance. Full detail →
Spyware assessment and, with Risk3 Consulting, physical counter-surveillance. Full detail →
Not sure which applies? Describe the situation in a confidential case review and we will tell you what the evidence can and cannot answer, before any fee.
Before you instruct anyone: how to choose a firm · how fees work · straight answers about digital evidence.