Active Incident? 24/7 Response →
SleuthX

For Attorneys

Digital forensics for attorneys, when your case turns on a device

Digital forensics for attorneys: computer and mobile forensics, deleted data recovery, expert witness testimony. FRE 901/902 chain of custody. 48-hour start.

When your case turns on what is on a phone, a laptop, or in an account

Litigators retain us when the evidence is digital and the other side will fight over it.

We acquire it with write-blocked imaging and hash verification, document the chain of custody, and authenticate it under FRE 901 and the self-authentication provisions of FRE 902(13)/(14). We build every engagement to survive a Daubert challenge, with methodology a court can test and a deposition and trial record behind it.

Whether a given exhibit is ultimately admitted is the court’s call; our job is to give you findings that hold up when they are challenged.

This is the litigation-support spoke of our forensic services for law firms hub.

Related attorney work runs through forensic phone extraction, cybersecurity expert witness testimony, e-discovery and ESI collection, and digital forensics for divorce. See also spoliation in family-law digital evidence.

Engagements are confidential and structured to begin within 48 hours of the consultation.

Some service tracks are offered at a fixed fee; complex investigations are billed at a flat $400/hr against a $5,000 refundable retainer, with a clear scope, milestone updates, and a cap agreed up front.

Quinn (Founder and CEO) oversees every engagement and reviews every case before findings leave the practice; the practitioner team executes the technical work under her methodology.

What this means for you

The process, end to end

Most forensic vendors describe their process in a sentence.

Opposing counsel will examine yours for an hour.

This is the workflow every engagement runs, stage by stage, so you know what the record will show before you retain us.

  1. Identification and scoping. Which devices, accounts, and data sources plausibly hold the evidence; what the preservation obligations already are; what can be acquired lawfully and with whose authorization. You get a written scope before any acquisition begins.
  2. Preservation and intake. Chain-of-custody documentation starts at intake, with tamper-evident packaging for shipped devices, a custody form signed at every handoff, and a preservation letter template for custodians when counsel wants one.
  3. Write-blocked acquisition with two-hash verification. Devices are imaged behind a write blocker; an acquisition hash is computed when the image is taken and a verification hash is computed on the working copy before analysis, so the record shows the copy analyzed is the copy acquired. The methodology follows NIST SP 800-86 and SWGDE practice. Where a matter requires Cellebrite, Magnet AXIOM, or a similar extraction platform, we engage those platforms through our partner network.
  4. Analysis at the artifact level. Findings are tied to named file-system metadata, application databases, and account and sync logs, documented precisely enough that another examiner could retrace the path. That reproducibility is what a reliability challenge actually tests.
  5. Report. Written to the structure Rule 702 examinations follow: data relied on, method applied, how the method was applied to the data, and conclusions stated with method-bounded confidence that go no further than what the artifacts support. See what goes into a court-ready forensic report.
  6. Testimony support. Declarations, FRE 902 certifications, deposition preparation, and trial support. Quinn is prepared to testify on any report the practice issues.

Authentication under FRE 901, and self-authentication under 902(13)/(14)

Digital evidence gets admitted the same way everything else does: a foundation.

FRE 901(b) lists the routes of witness testimony, distinctive characteristics, and process-or-system evidence.

For electronic records there is a faster path: under FRE 902(13) a certification of a qualified person can authenticate records generated by a process or system, and under FRE 902(14) the same mechanism covers data copied from a device, storage medium, or file, and the committee note names hash-value comparison as the canonical digital-identification process.

That is not paperwork we bolt on afterward.

Our workflow captures the acquisition and verification hashes a Rule 902(14) certification requires, and our examiner prepares those certifications for counsel.

Notice matters: the rule’s advance-notice procedure means the certification should be planned with your disclosure calendar, not the week before trial.

For the foundations themselves, start with authenticating text messages under FRE 901/902 and chain of custody for litigators.

What 902(13) and 902(14) do not do

Honesty about the limits is part of the foundation.

A 902(13)/(14) certification settles authenticity of the copy or the process, establishing that the data is what it purports to be and the copy matches the original.

It does not resolve hearsay, relevance, or authorship: a certified extraction proves the messages came off that phone intact, not who typed them.

And whether a given examiner is a “qualified person” is decided by the court on the record before it, matter by matter.

Any vendor who tells you 902(14) makes evidence “automatically admissible” is overselling the rule.

The December 2023 amendment to Rule 702

Rule 702 was amended effective December 1, 2023: the proponent must now show it is more likely than not that each admissibility requirement is met, and subsection (d) was reworded to require that the opinion reflect a reliable application of the method to the facts.

The committee note speaks directly to this field, saying forensic experts should avoid assertions of absolute or one hundred percent certainty.

That is how our reports were already written: conclusions carry the confidence the method supports, stated so the court can see where the data ends and the inference begins.

If the expert you are vetting states conclusions without bounds, the 2023 note is now the cross-examination script against them.

Background: how to vet and qualify a forensic expert.

Spoliation and preservation

When the question is whether the other side deleted evidence, the analysis changes shape: wiping and deletion timestamps, wiping-tool traces, and mass-deletion patterns in file-system metadata are identifiable where present, and FRCP 37(e) frames what a court can do about ESI that should have been preserved and was lost.

That work has its own service page: spoliation forensic analysis.

For the preservation side, send custodians a litigation-hold template that actually covers a phone.

How an engagement begins

  1. Confidential consultation. NDA-protected. 30-60 minutes. Direct conversation, no sales process.
  2. Scoped engagement. Written proposal with defined deliverables and pricing, a fixed fee where it applies and hourly with milestone caps for open-ended investigations.
  3. Investigation and findings. Court-ready standards. Written report you can act on.

Why this work matters

In litigation the methodology behind a finding gets tested as hard as the finding itself, so it has to hold up under cross-examination and a Daubert challenge.

Quinn holds 9 active certifications across GIAC, a methodology trusted by Fortune 50 enterprises, defense contractors, and the attorneys who refer to us.

This page is general information for attorneys and their clients, not legal advice, and reading it does not create an attorney-client or expert-engagement relationship. SleuthX is a digital-forensics firm, not a law firm. Admissibility decisions belong to the court; litigation strategy belongs to your attorney. Rules and case law summarized here can change, so verify current authority before relying on it. © 2026 SleuthX, Inc.

Meet Your Practitioner

Quinnlan Varcoe

Founder & CEO

GIAC-certified · 9 industry certifications

With operational experience across Fortune 50 security programs and the defense industrial base, Quinnlan founded SleuthX in 2022 to provide clients with the caliber of expertise typically reserved for the largest enterprises. Her work in threat intelligence and digital forensics has earned the trust of 26,000+ cybersecurity professionals who follow her analysis.

“26,000 professionals follow my work because I say what others won't — and I can back it up technically.”

Fortune 50 BackgroundDefense IndustryThreat IntelligenceDigital PrivacyIncident Response
Quinnlan Varcoe, Founder & CEO
iPhone & Android Forensics · How Acquisition Actually Works

Why iPhone forensics is hard, and what we ship to do it.

iPhone forensic acquisition is the most technically demanding work in consumer DFIR. Apple's Secure Enclave, hardware-backed encryption keys, signed-system volume, and aggressive iOS hardening between every minor release mean there is no "run a tool from the cloud and read the phone" option. Each iOS version requires updated forensic methods, and most of those methods only work with a specific physical-cable connection to a licensed acquisition platform such as Cellebrite UFED, Magnet AXIOM, MSAB XRY, the same tools used by federal law enforcement and major IR firms. When a matter calls for it, we engage these platforms through our licensed partner network.

Android is a different problem set with the same conclusion. Verified Boot, full-disk encryption, and OEM-specific lock states (Samsung Knox, Google's Titan M2, Xiaomi's mi-account lock) all gate what can be acquired and how. Every Android make and model is its own acquisition path.

Remote forensics works, but the device has to be in the lab.

We work with clients across the United States. For remote engagements, we ship you a tracked, insured, evidence-grade shipping kit with anti-static packaging, tamper-evident seals, and a chain-of-custody form. You package the device, drop it at the carrier, and we acquire it in our lab using the appropriate acquisition workflow for that device and OS version. Findings are written up and the device ships back to you under the same chain of custody.

Total turnaround from device-arrival to written report is typically 5 to 10 business days for a standard single-device case. Active-incident or court-deadline cases compress under surge. A screen-share, an email of screenshots, or a remote session with the user holding the phone is not a forensic acquisition. It does not preserve evidence, it does not produce a court-admissible report, and we will not represent it as such.

If the device is in active use by a hostile actor (an abuser, an active attacker), we coordinate timing of the hand-off with you to protect the integrity of the evidence and your physical safety. Tell us this on the first call.

How We Work

A confidential, structured engagement.

01

Confidential Consultation

A direct conversation with Quinn, the founder and CEO who oversees every engagement. NDA-protected. No sales process.

02

Scoped Engagement

A clear written proposal with defined deliverables, timeline, and pricing. No hidden costs.

03

Investigation and Findings

Forensic work conducted to court-admissible standards, with regular communication and a written summary you can act on.

Certified Expertise

GIAC

Frequently asked by attorneys

What forensic services do you provide for attorneys?
Digital forensics, e-discovery and ESI handling, expert witness testimony, breach causation analysis, spoliation evaluation, forensic phone extraction, e-mail and account compromise investigation, social-media and messaging-app preservation, GPS and location data analysis, and litigation-support consulting. Engagements are accepted as testifying expert, consulting expert (FRCP 26(b)(4)(D) non-disclosed), and as a forensic vendor working under the supervision of trial counsel.
How does engagement under attorney privilege work?
Standard practice. The engagement letter names you (or your firm) as the directing client, with the underlying party as the beneficiary. Forensic findings, interim communications, and work product are protected under attorney work-product doctrine and attorney-client privilege. Reports are not produced to the underlying party until you authorize release. This structure preserves admissibility while protecting strategic flexibility for your case.
What does a typical attorney engagement look like end-to-end?
Conflicts check (same-day) → engagement letter and retainer (24–48 hours) → device or evidence intake (chain of custody documented) → forensic acquisition and analysis (1–4 weeks depending on scope) → preliminary findings call with trial counsel → written report formatted to FRE 702 and Daubert standards → expert disclosure if needed → deposition and trial support. Throughout, you have a direct line to Quinn, with no account managers and no junior intermediaries.
Do you handle both plaintiff and defense work?
Yes. The practice is independent and accepts work on either side of the v. The technical methodology is the same regardless of which party retained us, which is what makes findings defensible under cross-examination. We've been retained both to provide affirmative findings and to evaluate the methodology of opposing experts (a defense-side rebuttal engagement).
What is your conflict-check process?
Provide the parties (full legal names), counsel of record, and case caption in the initial inquiry. Conflicts checks are completed same-day. We maintain an internal client list and screen against it; if a conflict exists, we will tell you immediately. The practice does not accept matters where Quinn or a senior team member has prior involvement that creates a conflict, including expert work for the opposing party in a related matter.
Do you work with both major-firm and solo / small-firm attorneys?
Both. Engagements range from solo family-law practitioners with a single divorce-forensics question to large-firm litigation teams in IP and breach-causation matters. Pricing and scope flex accordingly, so single-issue forensic extractions can be fixed-fee and accessible to small-firm budgets, while complex multi-device investigations are scoped hourly with milestone caps.
How do you handle e-discovery and spoliation issues?
We are retained both for affirmative ESI handling (preservation, collection, production) and for spoliation evaluation when the question is whether the opposing party preserved properly. Forensic acquisition uses write-blocked imaging and hash verification, which is the methodology required for defensible production. For spoliation analysis, we examine artifact patterns in file system metadata, application logs, and recovery artifacts to assess whether deletion was intentional, when it occurred, and what was lost.
Quinnlan Varcoe, Founder & CEO
Quinnlan Varcoe
GIAC-certified · Founder & CEO

Schedule Your Session

Schedule a confidential consultation

A direct conversation with Quinn, the founder and CEO who oversees every engagement. NDA-protected. No sales process. Most engagements begin within 48 hours.

Free, confidential · NDA-protected · no obligation.

  1. 1. Book a 30-minute call — we scope your situation, no charge.
  2. 2. You get a written scope — deliverables, timeline, and price — before any work begins.
  3. 3. Approve it and we start; most engagements begin within 48 hours.

Transparent pricing

Trusted by partners across the practice

DAS Health
Exhibit A Cyber
Ally Security
KIRO Group
Black Mirage
Kalles Group
Gridware
CQR
Archstone Security
Cyvergence
Sentinel Cyber
Cloud Underground
Seron Security
Hexen
Koru Risk Management
DAS Health
Exhibit A Cyber
Ally Security
KIRO Group
Black Mirage
Kalles Group
Gridware
CQR
Archstone Security
Cyvergence
Sentinel Cyber
Cloud Underground
Seron Security
Hexen
Koru Risk Management