Active Incident? 24/7 Response →
SleuthX

About & Contact

Talk to Quinn,
not a sales pipeline.

Confidential consultations are 30-60 minutes, NDA-protected, and free. If your case is a good fit, we'll scope an engagement. If a simpler step would resolve it, we'll tell you that and decline. We'd rather lose the case than waste your money.

About Quinnlan Varcoe

The investigator on the other end of the call.

I'm Quinnlan Varcoe. I founded SleuthX in 2022 after a decade of incident response and threat intelligence work for Fortune 50 enterprises and the defense industrial base. I hold 9 active certifications across GIAC, the same credentials that get forensic findings admitted in federal court.

I started this practice because the people who actually need DFIR work, individuals being stalked, attorneys preparing for trial, family offices recovering from wire fraud, and small businesses hit by ransomware, were getting the worst of an industry built for billion-dollar enterprise contracts. Either they were priced out, or they were sold automated scans dressed up as investigations, or they were handed off to junior staff after the sales call. None of those outcomes are acceptable.

I scope every engagement and oversee the practitioner team executing the work. Alex Riffenburgh, our Co-Founder, brings the offensive-security discipline and takes investigations and field operations going forward. I review every case before findings leave the practice. If we are not the right fit for your case, I'll tell you, and where possible I'll refer you to someone who is.

  • A direct line to Quinn, the founder, not a sales pipeline.
  • Worked in-house by the examiner who scoped it.
  • Explainable findings you can verify, with the methodology shown.

Who we work with

  • Individuals and families facing stalkerware, account compromise, identity theft, romance scams, or domestic-violence situations involving digital evidence.
  • Attorneys who need court-admissible forensic phone extraction, e-discovery support, expert-witness testimony, or spoliation analysis, primarily in family law and commercial litigation.
  • Family offices and HNW principals who need discreet investigative support, privacy services, and a security program ownership layer their wealth manager cannot provide.
  • Investigative journalists and newsrooms facing device compromise or source-protection questions. See our work with journalists.
  • Small and mid-sized businesses that need real cybersecurity without the enterprise pricetag, through managed services, vCISO, and incident response.
  • Other security firms, MSPs, and law firms who refer cases to us or sub-contract us as a white-label partner. See enterprise services for partnership terms.

What this means for you

  • Written scope before any work. You see a written scope covering deliverables, timeline, and price, and you approve it before we begin. You are never billed for work you did not authorize.
  • We commit to findings, not outcomes. We tell you up front what the evidence can and cannot establish. Recovery, attribution, and prosecution are decided by banks, platforms, insurers, and courts. We produce the record they act on, and we put that distinction in writing.
  • Every case is investigated, not just scanned. A credentialed examiner reviews every case before findings leave the practice. You get a documented investigation to court-admissible standards, not a single automated scan and a one-line answer.
  • We will tell you if you do not need us. If a free or simpler step would resolve your situation, whether a police report, an IC3 filing, or a platform's own recovery flow, we point you there first.

How an engagement begins

  1. Confidential consultation. NDA-protected. 30-60 minutes. Direct conversation, no sales process.
  2. Scoped engagement. A written proposal with a fixed fee where it applies and hourly with milestone caps for open-ended investigations.
  3. Investigation and findings. Court-admissible standards. Written report you can act on.

Certified Expertise

GIAC

Frequently asked about getting in touch

What happens after I send a message?
If you submit through the form or by email, you will get a personal response from Quinn or someone on her direct team, usually within one business day. The next step is a confidential consultation, scheduled through Calendly or by phone, NDA-protected, 30 to 60 minutes, free. The consultation is a real conversation about the case, not a sales call. If we are a fit, we follow up with a written scope. If a simpler step would resolve the situation, we tell you that and decline the engagement.
How fast do you respond to incident-response inquiries?
For active incidents (active ransomware, ongoing account takeover, in-progress data exfiltration, suspected stalkerware on a phone you still need to use), call (239) 241-8095 directly rather than emailing. Phone-based triage and immediate guidance start within 60 minutes for declared incidents on a retainer, and on a best-effort basis without one. For non-active matters such as litigation prep, scoping a forensic extraction, or planning an engagement, the standard response time is one business day.
Do you sign NDAs before the consultation?
Yes. Initial consultations are NDA-protected before any substantive discussion of the case. We can sign your NDA, ours, or a mutual one drafted at the start. For attorneys with pending or active litigation, we recommend that your firm engage us directly so the work product falls under attorney-client privilege and attorney-work-product doctrine from the first call.
What information should I have ready?
A short written summary of what is happening (one paragraph is fine), the rough timeline, the devices and accounts involved, and any relevant deadlines (a hearing, a regulatory notification window, a closing date). For active incidents, do not factory-reset, do not clean up affected systems, and do not change passwords on the compromised device before the call. Each of those steps destroys forensic evidence you may need later. If you have already taken any of those actions, just tell us; we work with what is available.
Do you take cases nationwide?
Yes. The practice is headquartered in Naples, Florida, and engagements are taken across the United States. Most forensic and consulting work is performed remotely with documented chain of custody for shipped or imaged devices. On-site work is available for active incidents, expert-witness depositions and trial, and enterprise engagements that require physical presence. International engagements are considered case by case, subject to export-control rules.

Transparent pricing

Trusted by partners across the practice

DAS Health
Exhibit A Cyber
Ally Security
KIRO Group
Black Mirage
Kalles Group
Gridware
CQR
Archstone Security
Cyvergence
Sentinel Cyber
Cloud Underground
Seron Security
Hexen
Koru Risk Management
DAS Health
Exhibit A Cyber
Ally Security
KIRO Group
Black Mirage
Kalles Group
Gridware
CQR
Archstone Security
Cyvergence
Sentinel Cyber
Cloud Underground
Seron Security
Hexen
Koru Risk Management