
Every examination is carried out in house by the people below. We do not outsource forensic work.


When you suspect misconduct, the evidence is usually on a device: a work laptop, a phone, an email account. We preserve that evidence before it can be altered or deleted, then establish what actually happened. You receive findings you can rely on in a disciplinary process or an employment tribunal.
In employee investigations, activity during the weeks before a resignation is often particularly relevant. We examine USB activity, cloud synchronisation, personal email and file transfers to establish what was taken, when, and where it went. The evidence is preserved in a form your solicitors can act on.
We support solicitors, insolvency practitioners and internal teams by tracing communications, documents and financial records across devices and accounts, and by recovering material that someone hoped was gone.
Deleting a file does not always make its contents irrecoverable. We recover deleted files, messages and activity records from computers, servers and mobile phones, and we tell you honestly at the outset whether recovery is likely in your case before you commit to a full investigation.
Where a matter is heading to court, we prepare expert reports and, where required, give evidence. Findings are written in plain English so that a judge, a tribunal panel or an opposing expert can follow exactly what was done and why.
If you hold a forensic report you are not confident in, we review how the evidence was identified, preserved and examined, and whether the conclusions are supported. We then advise, candidly, whether a fresh examination is justified or whether the original work is sound. We run a conflict check before accepting any review instruction.
A confidential conversation to understand the situation, agree the questions the investigation must answer, and give you a realistic view of cost and timescale before anything begins.
We begin preservation as soon as is practically possible, because evidence degrades with use. We take forensic images of the devices and accounts involved. Wherever possible, examination is carried out on forensic copies. Any necessary interaction with an original device is minimised and documented. Every item is logged in a chain of custody from the moment we receive it.
Examination of the preserved data against the agreed questions: what happened, when, by whom, and what it means.
Findings in plain English, with the technical detail behind them documented and repeatable.
We carry out investigations for organisations across the UK. Initial conversations are confidential and without obligation, and we begin work as soon as is practically possible.