Practice areas
Each area answers a different legal question and calls for a different method. Under each you will find what can be established, how, and within what limits — because knowing in advance what cannot be proved is often worth as much as the examination itself.
Forensic acquisition
Making a copy of a disk, a phone or a mailbox that will still stand up when the other side attacks it.
Chat and messaging
What a WhatsApp screenshot actually proves, and what has to be done to make it hold.
Email and certified email
Reading SMTP headers, SPF, DKIM and certified-email receipts to establish who really sent what.
Mobile devices
Extraction from smartphones and tablets: what can be recovered, what cannot, and why.
Software and source code
Disputes over development contracts, ownership of code and software that does not do what was agreed.
Artificial intelligence systems
Model outputs, inference logs and training data: what can genuinely be established about an AI system.
Data breaches and log analysis
Reconstructing an intrusion from the logs and separating what was taken from what was merely reachable.
Where to start
If the matter turns on a conversation — messages, chats, exchanges between people — the starting point is chat and messaging, and the next step is almost always the device that conversation came from.
If it turns on a formal communication — a notice, a termination, an order, a service of process — look to email and certified email: the area where the technical evidence is strongest, because the message carries its own route inside it.
If it turns on a contractual relationship — a delivery that does not work, contested code, a system that caused loss — the area is software and source code or, where a generative model is involved, artificial intelligence systems.
If it turns on unauthorised access — an intrusion, a data leak, an employee who walked out with an archive — the area is data breaches and log analysis.
In every case, before any analysis, comes acquisition: the step at which most digital evidence is spoiled, and one that can almost never be repaired afterwards.
The method is the same across every area
Framing the fact to be proved, acquisition with integrity verification, repeatable analysis on a copy, and a report that separates what is established from what is an assessment and from what remains unknown. How a forensic examination runs →
And if you are not yet sure whether you need a party-appointed expert: what the role involves and when it pays →
Do you have a matter under way?
Tell me what happened and what you need to prove. In a first reply I will tell you whether there is a technical route, what data is needed and how long it takes — before any commitment.