Active Incident? 24/7 Response →
SleuthX

AI Investigator · Personal Cybersecurity

SleuthX
The forensic layer credit-monitoring services can’t reach.

The personal cybersecurity stack built around what monitoring services miss: an AI investigator that examines accounts and devices end-to-end, with a credentialed examiner signing off on findings that need to stand up in court, police filings, or insurance claims. It speaks plain language for non-technical users, so you describe what's happening and it walks you through. Investigator-grade depth on demand. Identity monitoring, dark-web monitoring, restoration concierge, and identity-theft coverage layer in as the suite ships.

How SleuthX Works

Input. Agent. Output.

SleuthX ingests data from your accounts and devices, analyzes it with an AI agent built on a working forensics methodology, and escalates to senior human examiners when the case demands it.

Input

Ingest data from accounts and devices

  • Account logs (email, cloud, banking, social)
  • Device artifacts and screenshots
  • Phone, computer, and forensic captures
Agent

Analyze with the AI agent

  • Classify what's a real compromise vs benign
  • Reconstruct the timeline of activity
  • Surface the root cause hypothesis
Output

Deliver a structured report

  • Compromise classification + severity
  • Clear next steps you can act on
  • Court-admissible report when needed

When a case needs human judgment, SleuthX escalates to the practitioner team of Quinn and Alex, who oversee every output before it leaves the system.

Explore the platform →See what's live on the roadmap →

Deliverables

What you get

Every SleuthX engagement produces the same five deliverables. No mystery, no scope creep.

  • Compromise classification

    Real vs benign, with severity. Tells you whether something actually happened or whether the alarm was noise.

  • Timeline of activity

    What happened, in what order, on which device or account. Reconstructed from logs, artifacts, and forensic captures.

  • Root cause hypothesis

    How the compromise started, whether phishing, SIM swap, reused password, OAuth grant, malicious app, or insider access. Evidence-backed.

  • Clear next steps

    What to do this hour, this week, and this quarter. Specific to your situation, not a generic checklist.

  • Structured report (legal-ready optional)

    Written for non-technical decision-makers. Court-admissible chain of custody when you need it for litigation, insurance, or law enforcement.

What SleuthX does

SleuthX brings enterprise and legal-grade methodology direct to consumers.

Same court-ready work the enterprise and law firms get from senior IR firms, Belkasoft, and Cellebrite-licensed shops.

Quality, not budget.

We are not competing with NordVPN, LifeLock, or basic antivirus tools.

We are bringing enterprise-grade digital forensics into a tier consumers can actually pay for.

Coverage spans stalkerware detection on iPhone and Android, hacked-account forensic audit and recovery, romance scam attribution and documentation, identity theft forensic investigation, deleted-text recovery for divorce, OSINT exposure mapping, and domestic-violence digital forensics under a safety plan.

Each engagement is structured to be evidentiary, not just felt.

Who builds SleuthX

Quinnlan Varcoe, Founder and CEO, sets the methodology, reviews edge cases, and is the named expert witness for litigation where the agent's output is challenged.

Alex Riffenburgh, Co-Founder, brings the offensive-security discipline and takes investigations, field operations, and the agency build-out going forward.

The agent itself absorbs the procedural analysis that previously required senior-analyst hours; the cases run through it serve as both production output and training data.

Three ways to work with SleuthX

Pick the one that matches what you need.

The agent is the throughline across all three. What changes is whether you run it yourself, hand it to our team, or run a whole team on it.

  1. The self-serve tool costs $995 once and unlocks every tool. It is a personal cybersecurity service that investigates, not just alerts. The one-time purchase includes $995 of usage credit; after that, usage draws down a prepaid account balance as tools run, so you top up anytime and pay only for what you use. SleuthX Enterprise at $20,000/mo is the team tier, adding frontier reasoning, a dedicated analyst escalation channel, and team billing.
  2. Done-for-you forensics comes in device packages from from $3,000. $3,000 for 1 device, $7,000 for 3 devices, and $12,000 for 5 devices, each including the $995 lifetime license. Scoped in writing on a free triage call before any retainer is collected. Hire an examiner and see done-for-you →
  3. $400/hr flat covers everything else. The same standardized rate for additional devices, divorce work, hacked-account recovery, OSINT, breach-counsel support, and every bracket of expert-witness work (case review, deposition prep, deposition, trial testimony). The largest complex and litigation cases run $15,000–$50,000, scoped per case. 4-hour-per-session minimum without a retainer.

Why these prices

Premium positioning is deliberate.

The pricing funds the senior-practitioner time required to keep methodology current with the threat landscape and is comparable to enterprise retainer pricing per device covered.

The methodology is the same one the enterprise gets from senior IR firms for $50,000 to $500,000 minimums.

If you want to run it yourself, the self-serve tool is a one-time $995 purchase.

If you want us to do the work, done-for-you device packages start at $3,000.

If you need open-ended senior time, hourly is $400/hr across the board.

What this means for you

How it works

  1. Confidential consultation. NDA-protected. 30 to 60 minutes. Direct conversation with Quinn. No sales process.
  2. Scoped engagement. Written proposal with defined deliverables, pricing, and timeline. Triage, subscription, or forensic case engagement depending on what fits.
  3. Investigation, review, and findings. The agent runs the procedural forensic work. Quinn reviews every output. You receive a written report you can act on, structured for police, court, counsel, or your own decision-making.

What separates SleuthX from antivirus and identity-protection apps

Monitoring tells you that you might be at risk.

SleuthX tells you what actually happened — investigated end-to-end and reviewed by a credentialed examiner.

Antivirus scans for known malware signatures; identity-protection monitors public breach databases.

Neither one investigates a specific incident on your devices or accounts, produces a court-ready report, or is reviewed by a certified forensic practitioner.

SleuthX is forensic methodology, not signature matching.

The comp set is enterprise IR firms and Cellebrite-licensed shops, not NordVPN or LifeLock.

It is not a substitute for a full forensic examination of every device in a matter, or for contested-litigation expert testimony, which we arrange separately.

Why enterprise and legal-grade methodology matters

Enterprise IR firms and Cellebrite-licensed shops charge $50,000 to $500,000 for enterprise incident response and $5,000 to $15,000 per consumer case.

That quality of work was previously out of reach for individuals.

SleuthX keeps the methodological rigor and brings it inside a tier a consumer can actually pay for, because the agent absorbs the procedural analyst time.

Quinn still owns case judgment.

How SleuthX handles each of the consumer practices

Why this work matters

Built for personal cybersecurity at evidentiary grade.

Quinn holds 9 active certifications across GIAC.

Methodology trusted by Fortune 50 enterprises, defense contractors, and the attorneys who refer to us.

The agent extends that methodology to people who could not previously afford it.

Meet Your Practitioner

Quinnlan Varcoe

Founder & CEO

GIAC-certified · 9 industry certifications

With operational experience across Fortune 50 security programs and the defense industrial base, Quinnlan founded SleuthX in 2022 to provide clients with the caliber of expertise typically reserved for the largest enterprises. Her work in threat intelligence and digital forensics has earned the trust of 26,000+ cybersecurity professionals who follow her analysis.

“26,000 professionals follow my work because I say what others won't — and I can back it up technically.”

Fortune 50 BackgroundDefense IndustryThreat IntelligenceDigital PrivacyIncident Response
Quinnlan Varcoe, Founder & CEO

How We Work

A confidential, structured engagement.

01

Confidential Consultation

A direct conversation with Quinn, the founder and CEO who oversees every engagement. NDA-protected. No sales process.

02

Scoped Engagement

A clear written proposal with defined deliverables, timeline, and pricing. No hidden costs.

03

Investigation and Findings

Forensic work conducted to court-admissible standards, with regular communication and a written summary you can act on.

Certified Expertise

GIAC

Frequently asked about SleuthX

What is SleuthX, in one sentence?
SleuthX brings enterprise and legal-grade methodology direct to consumers. Same court-ready work the enterprise gets from enterprise IR firms, BelkaSoft, and Cellebrite-licensed shops, delivered in a tier individuals can actually pay for.
How is this different from antivirus or identity-protection apps?
SleuthX is not competing with NordVPN, LifeLock, or basic antivirus tools. Antivirus scans for known malware signatures. Identity-protection monitors public databases for breach exposure. Neither one runs forensic methodology, neither one produces a court-ready report, and neither one investigates a specific incident on your devices or accounts. SleuthX does. The agent scales the procedural work that previously required senior-analyst hours, and Quinn (Founder and CEO) reviews every output before it leaves the practice.
Do I need to be technical to use it?
No. The default flow is plain language: describe what's happening ("my email got hacked," "someone's tracking my phone," "I keep getting messages from numbers I don't recognize") and the agent walks you through. It asks the next right question, tells you which device or account to grant access to, and explains what it found in plain English. Most users finish triage without ever touching a forensic term. If you want to go deeper, the agent supports that too. You can pick a specific investigation, drill into device/account/timeline/artifact-level analysis, run targeted forensic tasks, and export evidence in a specific format. The same tool works for someone who's never heard of DFIR and for a senior investigator running a multi-device case. Easy floor, deep ceiling.
How is SleuthX priced?
Three ways to work with SleuthX. (1) The self-serve tool is a one-time $995 purchase with lifetime access and every tool unlocked. It includes $995 of usage credit; after that, usage is metered from a prepaid account balance deducted as tools run, so you only pay for what the investigation actually uses. Teams that need frontier reasoning, dedicated analyst escalation, and team billing subscribe to SleuthX Enterprise at $20,000/mo. (2) Done-for-you forensics comes in three device packages, $3,000 (1 device), $7,000 (3 devices), and $12,000 (5 devices), each including the $995 lifetime license. (3) $400/hour flat covers anything beyond that, including additional devices, complex multi-actor cases, litigation, and expert-witness work; complex and litigation cases run $15,000 to $50,000, scoped per case. All standard payment methods are accepted via Stripe, with bank transfer (ACH or wire) preferred for larger engagements.
What does the one-time purchase include?
Everything. The $995 one-time purchase unlocks AI triage, link analysis, the evidence vault, court-ready reporting, and every forensic tool for life, and comes with $995 of usage credit. Usage draws down a prepaid balance as tools run; top it up whenever you need more, and the balance never expires. There is no recurring charge for individual users. SleuthX Enterprise is the team offering, a $20,000/mo subscription that adds frontier reasoning, a dedicated analyst escalation channel, and team billing.
Who reviews the work? Is this just an AI?
Quinnlan Varcoe (Founder and CEO, BS cybersecurity from SANS Technology Institute, 9 active GIAC certifications, court-ready methodology, named expert witness for litigation) designed the methodology SleuthX is built on. Alex Riffenburgh, Co-Founder, brings the offensive-security discipline and takes investigations and field operations going forward. The agent scales the procedural work that used to require senior-analyst hours; the judgment, methodology, and final report carry Quinn's name.
Will the report hold up in court?
We build the work to support admissibility through a methodology designed to support the Federal Rules of Evidence, a documented chain of custody, and forensically sound (NIST/SWGDE-aligned) handling. Admissibility itself is always the court's decision, case by case; no examiner can promise a specific ruling in advance. Quinn is a named expert witness and can testify to the methodology, and expert testimony is arranged separately for your matter rather than bundled into the package. If a case has a legal dimension and you have an attorney, we structure the engagement under privilege at your attorney's request.
What kinds of cases does SleuthX handle?
Stalkerware detection on iPhone and Android. Recovery and forensic audit after an account compromise (email, social, banking, iCloud). Romance-scam attribution and documentation. Identity-theft forensic investigation. Deleted-text and chat-history recovery for divorce. OSINT exposure mapping. Domestic-violence digital forensics under a safety plan. Each of these has a dedicated practice page with the methodology detail.
Quinnlan Varcoe, Founder & CEO
Quinnlan Varcoe
GIAC-certified · Founder & CEO

Schedule Your Session

Schedule a confidential consultation

A direct conversation with Quinn, the founder and CEO who oversees every engagement. NDA-protected. No sales process. Most engagements begin within 48 hours.

Free, confidential · NDA-protected · no obligation.

  1. 1. Book a 30-minute call — we scope your situation, no charge.
  2. 2. You get a written scope — deliverables, timeline, and price — before any work begins.
  3. 3. Approve it and we start; most engagements begin within 48 hours.

Transparent pricing

Trusted by partners across the practice

DAS Health
Exhibit A Cyber
Ally Security
KIRO Group
Black Mirage
Kalles Group
Gridware
CQR
Archstone Security
Cyvergence
Sentinel Cyber
Cloud Underground
Seron Security
Hexen
Koru Risk Management
DAS Health
Exhibit A Cyber
Ally Security
KIRO Group
Black Mirage
Kalles Group
Gridware
CQR
Archstone Security
Cyvergence
Sentinel Cyber
Cloud Underground
Seron Security
Hexen
Koru Risk Management