Investigations & Digital Evidence

Digital & Mobile Forensics

Digital and mobile forensics for legal, investigation and privacy teams that need to know what a device, account or cloud source can show, and where its limits lie. Scope, authority, method and deliverables are agreed for each engagement.

AploIQ provides digital and mobile forensics for devices, accounts, cloud services and systems: logical or physical acquisition, imaging, collection, recovery where technically feasible, examination and analysis, within the authority, method, source scope and limitations agreed for the engagement.

  • We acquire and examine only with proper authority, an agreed access and handling route, and any ownership or third-party constraints identified first.
  • Devices, accounts, cloud services and systems are selected against the questions in the engagement, and we record which sources were covered.
  • Logical or physical acquisition, imaging or collection is chosen to suit the source, the access conditions and the evidential need.
  • What can be recovered depends on the source's condition, access, platform behaviour and encryption.

When forensic work helps

  • The activity that matters is spread across a phone, a laptop, an account, a cloud service or a system log.
  • The sequence of events cannot be established from one source alone.
  • A source is volatile, changing or access-controlled, and needs a preservation plan before it is lost.

What we do

Source identification

Identify the devices, accounts, cloud services and system records that matter, who holds them, and what limits access.

Acquisition, imaging and collection

Carry out logical or physical acquisition, forensic imaging or targeted collection by an agreed method.

Technically feasible recovery

Assess and perform recovery where it is technically feasible and relevant to the question.

Examination and analysis

Examine artefacts, correlate activity across sources and test explanations against the technical record.

Method and limitations

Document the method, the analysis steps, the evidence gaps and every material limitation.

What you receive

  • Source, authority and method record
  • Acquisition, imaging or collection record
  • Correlated activity timeline
  • Technical findings with stated limitations

How we work

  1. Start with the questions

    Define what has to be tested before choosing sources or methods.

  2. Protect the sources

    Agree access, handling and preservation before data changes or disappears.

  3. Examine and correlate

    Analyse artefacts across sources, keeping observed facts separate from inference.

  4. Report with limits

    Set out the findings, the missing evidence, the alternative readings and the effect of technical constraints.

How to start

Send a short, non-sensitive note naming the source types, the event or question, the current access position and any preservation deadline. Do not send device images, credentials or evidence.

Discuss a forensic matter

Source and method questions

  • When is physical acquisition used for a mobile device?

    No single method fits every source. The acquisition route is selected after the source, authority, available access, source condition and analysis questions have been assessed.

  • When is recovery work included?

    Where it is relevant to the agreed questions. What can be recovered depends on the source, its condition, access and how the platform behaves.