Active Incident? 24/7 Response →
SleuthX

Read this first

Are you on a device or network the person can see?

  • If they might be able to see this device, use one they can’t access, such as a friend’s phone, a library or public computer, or a domestic-violence shelter’s safe device. If you continue here, your visit may be visible on a synced iCloud, Google account, or shared family plan.
  • The Quick Exit button (top right) replaces this page with weather.com immediately, but it does not erase this visit from your history, and private/incognito mode doesn’t fully hide it either. To be safe, use a device the person can’t access.
  • If you’re in immediate danger, call 911. If you have a few quiet minutes, keep reading.

National Domestic Violence Hotline: 1-800-799-7233 · text START to 88788 · thehotline.org · 24/7, free, confidential.

988 Suicide & Crisis Lifeline: call or text 988 · 988lifeline.org · free, confidential crisis and emotional support, 24/7.

NNEDV Safety Net: techsafety.org · technology-safety help for survivors.

New service

Domestic Violence Digital Forensics

Forensic investigation for domestic violence survivors. Stalkerware detection, account recovery, evidence for protective orders. Discreet, court-ready.

What this service does

If someone is using technology to track, monitor, or control you, that is not your fault and you are not imagining it.

This is forensic help for tech-enabled abuse:

Plan before you act.

Removing a tracking app or changing a password can alert the person monitoring you, so the safest first step is often a call with a domestic-violence advocate and, where possible, your attorney, before any technical change, so we can time the work around your safety plan.

If a free or simpler step is the right move first, we will tell you.

This work pairs with stalkerware detection and removal when a device is suspect, and with privacy hardening after separation once the immediate danger is documented.

Engagements are confidential and structured to begin within 48 hours of the consultation.

Some service tracks are offered at a fixed fee; complex investigations are billed hourly with a clear scope, milestone updates, and a cap agreed up front.

Quinn (Founder and CEO) oversees every engagement and reviews every case before findings leave the practice; the practitioner team executes the technical work under her methodology.

What this means for you

How an engagement begins

  1. Confidential consultation. NDA-protected. 30-60 minutes. Direct conversation, no sales process.
  2. Scoped engagement. Written proposal with defined deliverables and pricing, fixed fee where it applies, hourly with milestone caps for open-ended investigations.
  3. Investigation and findings. Prepared to support admissibility under FRE 901/902. Written report you can act on.

Why this work matters

Domestic violence digital forensics is safety-critical work: every examination is planned around the survivor's safety plan first, and stalking and abuse evidence is preserved to a standard prepared to support admissibility under FRE 901/902 for protective-order hearings.

Quinn holds 9 active certifications across GIAC, a methodology trusted by Fortune 50 enterprises, defense contractors, and the attorneys who refer to us.

Meet Your Practitioner

Quinnlan Varcoe

Founder & CEO

GIAC-certified · 9 industry certifications

With operational experience across Fortune 50 security programs and the defense industrial base, Quinnlan founded SleuthX in 2022 to provide clients with the caliber of expertise typically reserved for the largest enterprises. Her work in threat intelligence and digital forensics has earned the trust of 26,000+ cybersecurity professionals who follow her analysis.

“26,000 professionals follow my work because I say what others won't — and I can back it up technically.”

Fortune 50 BackgroundDefense IndustryThreat IntelligenceDigital PrivacyIncident Response
Quinnlan Varcoe, Founder & CEO
iPhone & Android Forensics · How Acquisition Actually Works

Why iPhone forensics is hard, and what we ship to do it.

iPhone forensic acquisition is the most technically demanding work in consumer DFIR. Apple's Secure Enclave, hardware-backed encryption keys, signed-system volume, and aggressive iOS hardening between every minor release mean there is no "run a tool from the cloud and read the phone" option. Each iOS version requires updated forensic methods, and most of those methods only work with a specific physical-cable connection to a licensed acquisition platform such as Cellebrite UFED, Magnet AXIOM, MSAB XRY, the same tools used by federal law enforcement and major IR firms. When a matter calls for it, we engage these platforms through our licensed partner network.

Android is a different problem set with the same conclusion. Verified Boot, full-disk encryption, and OEM-specific lock states (Samsung Knox, Google's Titan M2, Xiaomi's mi-account lock) all gate what can be acquired and how. Every Android make and model is its own acquisition path.

Remote forensics works, but the device has to be in the lab.

We work with clients across the United States. For remote engagements, we ship you a tracked, insured, evidence-grade shipping kit with anti-static packaging, tamper-evident seals, and a chain-of-custody form. You package the device, drop it at the carrier, and we acquire it in our lab using the appropriate acquisition workflow for that device and OS version. Findings are written up and the device ships back to you under the same chain of custody.

Total turnaround from device-arrival to written report is typically 5 to 10 business days for a standard single-device case. Active-incident or court-deadline cases compress under surge. A screen-share, an email of screenshots, or a remote session with the user holding the phone is not a forensic acquisition. It does not preserve evidence, it does not produce a court-admissible report, and we will not represent it as such.

If the device is in active use by a hostile actor (an abuser, an active attacker), we coordinate timing of the hand-off with you to protect the integrity of the evidence and your physical safety. Tell us this on the first call.

How We Work

A confidential, structured engagement.

01

Confidential Consultation

A direct conversation with Quinn, the founder and CEO who oversees every engagement. NDA-protected. No sales process.

02

Scoped Engagement

A clear written proposal with defined deliverables, timeline, and pricing. No hidden costs.

03

Investigation and Findings

Forensic work conducted to court-admissible standards, with regular communication and a written summary you can act on.

Certified Expertise

GIAC

Frequently asked about tech-enabled abuse cases

What does forensic help look like for tech-enabled abuse?
Tech-enabled abuse (TEA) covers stalkerware on phones, location tracking through shared accounts and AirTags, financial control through shared banking and credit accounts, social-media monitoring, smart-home device weaponization (cameras, locks, thermostats), and digital harassment patterns. Forensic help means: documenting what's happening (so it's evidentiary, not just felt), identifying and removing the technical mechanism, hardening accounts and devices going forward, and coordinating with the people who matter (advocate, attorney, court, sometimes police). The deliverable is both safety improvement and a written record that holds in court.
Will the abuser know I had my devices examined?
We design every engagement to avoid alerting the abuser when that matters for safety. That means: examining cloned device images rather than the live device when possible, using protocols that don't trigger remote-management alerts (e.g., MDM removal patterns), staging account changes to look like normal user activity, and timing changes when discovery is least likely. The first call is when we plan this together. There is no one-size-fits-all answer because tech-enabled abuse situations vary widely.
What if I don't have access to the device that's being used against me?
If the device belongs to the abuser and you don't have legal access, forensic examination of that device is not work we will take, because that crosses a federal Computer Fraud and Abuse Act line that can also compromise your legal case. But we have other paths: forensic examination of YOUR devices to identify what's been installed on them or what's being shared from them, account-side analysis (login logs, device-list audits, sharing-permission review on iCloud/Google), and coordination with your attorney for subpoena-based access to the abuser's devices or records when that's an option.
What does a forensic exam cost?
Done-for-you forensics in three device packages at $3,000 (1 device), $7,000 (3 devices), $12,000 (5 devices), each including the $995 lifetime tool license. $400/hr flat for anything beyond that, such as additional devices, complex or multi-actor cases, litigation, and expert-witness work. Final scope is set on a free triage call. Sliding-scale and pro-bono options for survivors are described below. No one is turned away on the first call over money.
How do you handle pricing for survivors with limited resources?
Sliding-scale pricing is built into the practice and is offered without paperwork drama on the first call. Pro-bono work is available for survivors with no resources, on a case-by-case basis tied to advocate or attorney referrals. We partner with local domestic-violence agencies and shelter networks. No one is turned away on the first consultation over money, and we don't bill for the consultation itself.
Can you coordinate with my advocate, attorney, or shelter?
Yes, and we strongly prefer to. Advocates and attorneys are the right hub for survivor cases because they understand the broader safety plan and the legal context the forensic work supports. Engagements are commonly retained by the attorney under privilege; advocates are kept informed within the boundaries the survivor sets. We sign confidentiality agreements with shelters and DV agencies as needed.
Will the report be safe to share with police, court, or my attorney?
The report is prepared to support admissibility under FRE 901/902 and structured for safe disclosure: technical findings are factual and verifiable, contextual narrative is clinical (no characterization of intent), and survivor-identifying detail is constrained to what's necessary for the case. We can produce two versions, a full report for attorney-eyes-only and a redacted version safe for filing or sharing with law enforcement, depending on what your safety plan calls for.
Quinnlan Varcoe, Founder & CEO
Quinnlan Varcoe
GIAC-certified · Founder & CEO

Schedule Your Session

Schedule a confidential consultation

A direct conversation with Quinn, the founder and CEO who oversees every engagement. NDA-protected. No sales process. Most engagements begin within 48 hours.

Free, confidential · NDA-protected · no obligation.

  1. 1. Book a 30-minute call — we scope your situation, no charge.
  2. 2. You get a written scope — deliverables, timeline, and price — before any work begins.
  3. 3. Approve it and we start; most engagements begin within 48 hours.

Transparent pricing

Trusted by partners across the practice

DAS Health
Exhibit A Cyber
Ally Security
KIRO Group
Black Mirage
Kalles Group
Gridware
CQR
Archstone Security
Cyvergence
Sentinel Cyber
Cloud Underground
Seron Security
Hexen
Koru Risk Management
DAS Health
Exhibit A Cyber
Ally Security
KIRO Group
Black Mirage
Kalles Group
Gridware
CQR
Archstone Security
Cyvergence
Sentinel Cyber
Cloud Underground
Seron Security
Hexen
Koru Risk Management