Active Incident? 24/7 Response →
SleuthX

Read this first

Are you on a device or network the person can see?

  • If they might be able to see this device, use one they can’t access, such as a friend’s phone, a library or public computer, or a domestic-violence shelter’s safe device. If you continue here, your visit may be visible on a synced iCloud, Google account, or shared family plan.
  • If you think spyware or stalkerware is on this device, removing it can alert the person monitoring you and can destroy evidence. Before you remove anything, make a safety plan with a domestic-violence advocate if one is available to you, and use a device they can’t access in the meantime.
  • The Quick Exit button (top right) replaces this page with weather.com immediately, but it does not erase this visit from your history, and private/incognito mode doesn’t fully hide it either. To be safe, use a device the person can’t access.
  • If you’re in immediate danger, call 911. If you have a few quiet minutes, keep reading.

National Domestic Violence Hotline: 1-800-799-7233 · text START to 88788 · thehotline.org · 24/7, free, confidential.

988 Suicide & Crisis Lifeline: call or text 988 · 988lifeline.org · free, confidential crisis and emotional support, 24/7.

NNEDV Safety Net: techsafety.org · technology-safety help for survivors.

New service

Stalkerware Detection and Removal

Think spyware is on your phone? Forensic stalkerware detection for iPhone and Android, covering Pegasus, FlexiSPY and mSpy. Court-ready findings.

Updated July 2026 · Reviewed by Quinnlan Varcoe, digital forensics examiner. If this phone may be monitored, browse and sign up from a safer device, because activity here can be visible to monitoring software. The Quick Exit button above works on every page.

What this service does

Worried there is spyware on your phone? This is detection and removal: a forensic examiner checks your iPhone or Android for stalkerware, hidden tracking apps, rogue device-management profiles, and AirTags or GPS trackers, and if something is found, removes it on a timeline that keeps you safe. You get a plain-language answer backed by evidence rather than a guess, and a written record if you ever need one.

What makes forensic work different from an antivirus scan is the order it protects: preserve → attribute → report → recover. A scanner can sometimes find monitoring software; only preserved evidence can show who put it there, and the finding-out usually destroys the proof unless the preservation comes first. The sections below walk that order.

Before you remove anything, preserve it

If you think an abusive partner installed it, plan before you remove it. Pulling stalkerware can alert the person who put it there, so for intimate-partner situations the safest first step is often a call with a domestic-violence advocate. See domestic violence digital forensics. The Coalition Against Stalkerware puts it plainly: deleting stalkerware also deletes the evidence, and removal can be detected by the person who installed it. NNEDV’s Safety Net project adds the practical corollary. Proving mobile spyware usually takes a forensic professional, and it takes the device before anyone has cleaned it.

The costliest mistake we see is well-meaning: the factory reset. It is the advice most articles give, and it is the single most evidence-destructive act available. It erases when the software arrived, how it was configured, and where it reported. If there is any chance you will want a protective order, a police report, or a custody filing, the device (or a forensic image of it) needs to be preserved un-reset first. Preservation doesn’t commit you to anything; it keeps every later option open, including the option to simply move on.

When removal is the right call and the timing is safe, the step-by-step is its own guide: how to remove stalkerware, step by step, with per-OS instructions and the preserve-first sequencing built in. After removal, privacy hardening closes the exposure that let it in.

How we establish who installed it

“Who did this?” is usually the question that matters most, for a protective order, for a police report, or just to know. It is also the question no scanner and no removal guide answers. In an examination we work it as an attribution problem across three independent channels, and we corroborate across them rather than relying on any one:

The three-channel attribution check

  1. The vendor account. Consumer monitoring products are subscriptions: someone bought a license, and someone logs into a dashboard to read what it collects. We establish whose purchase and whose access that is. That trail exists off the device and can be formally requested or subpoenaed.
  2. Install evidence × physical access. We establish when the software arrived on the device and correlate that window with who had hands-on access to it. Opportunity plus timing, documented.
  3. Account-level access. Much “spyware” is really a person holding your iCloud or Google credentials, or a management profile. The installer is then whoever holds that access, and the account’s own records can show it.
Two honesty notes

First, we describe these channels at the category level on purpose. This page is for the person being watched, not a how-to for covering tracks. Second, attribution is evidence work, not magic: what we produce is a documented, court-ready basis for “this account, this access window, this person had the means”, and the court or investigator draws the conclusion.

Familiarity with the consumer products matters here in one specific way: knowing what mSpy, FlexiSpy, or TheTruthSpy installations look like in evidence. We read what a license receipt, a dashboard login, or an install footprint means for attribution. (That is the only sense in which product names belong on this page; we don’t compare their features, and we don’t link to them.)

It may not be an implant, but account-level access

The peer-reviewed finding most “spyware check” services skip: the Cornell Tech study of spyware in intimate partner violence found that most real-world “my phone is being monitored” cases involve no spyware app at all, especially on iPhone. They are account-level access. Someone who knows the Apple ID or Google password reads synced messages, photos, and location from their own device. Apple’s Safety Check exists precisely because the sharing surfaces are the exposure.

This changes both the check and the fix. No device scan, ours or anyone’s, can clear your accounts, which is why no honest examination ends with “you are safe”; it ends with what was found, what was checked, and what that does and doesn’t rule out. And if the access was account-level, the fix is credential rotation done in the safe order, not app removal. That order is walked through in what to do if someone has access to your phone.

What to hand police if you want this investigated

Officers see stalkerware rarely enough that the report often goes nowhere without preparation. What moves a case is handing over a package they can act on:

Two companion guides cover the handoff itself: how to report digital evidence to law enforcement (who to report to, in what order) and the court-readiness checklist for digital evidence (what your documentation needs so it holds up).

Not every monitored phone is the same case

Most of this page assumes an intimate partner and a safety risk. That is the hardest version and the one where wrong moves cost the most, and it is why the domestic-violence resources above lead. But the same forensic questions show up in calmer postures. If the monitoring belongs to a relationship dispute headed for attorneys rather than advocates, that path is infidelity investigation coordination. It covers evidence on your own devices and accounts, coordinated lawfully for a divorce or custody matter. And if what worries you is nation-state spyware such as Pegasus and its relatives, you are looking at a different threat class from consumer stalkerware, with different checks: what Pegasus and zero-click attacks actually are.

Engagements are confidential and structured to begin within 48 hours of the consultation. Some service tracks are offered at a fixed fee; complex investigations are billed hourly with a clear scope, milestone updates, and a cap agreed up front. Quinn (Founder and CEO) oversees every engagement and reviews every case before findings leave the practice; the practitioner team executes the technical work under her methodology.

What this means for you

How an engagement begins

  1. Confidential consultation. NDA-protected. 30-60 minutes. Direct conversation, no sales process.
  2. Scoped engagement. Written proposal with defined deliverables and pricing, fixed fee where it applies, hourly with milestone caps for open-ended investigations.
  3. Investigation and findings. Prepared to support admissibility under FRE 901/902. Written report you can act on.

Why this work matters

Stalkerware detection means finding spyware on an iPhone or Android and removing it without tipping off the installer. It is precision forensic work, not an antivirus scan. Quinn holds 9 active certifications across GIAC, a methodology trusted by Fortune 50 enterprises, defense contractors, and the attorneys who refer to us.

Meet Your Practitioner

Quinnlan Varcoe

Founder & CEO

GIAC-certified · 9 industry certifications

With operational experience across Fortune 50 security programs and the defense industrial base, Quinnlan founded SleuthX in 2022 to provide clients with the caliber of expertise typically reserved for the largest enterprises. Her work in threat intelligence and digital forensics has earned the trust of 26,000+ cybersecurity professionals who follow her analysis.

“26,000 professionals follow my work because I say what others won't — and I can back it up technically.”

Fortune 50 BackgroundDefense IndustryThreat IntelligenceDigital PrivacyIncident Response
Quinnlan Varcoe, Founder & CEO
iPhone & Android Forensics · How Acquisition Actually Works

Why iPhone forensics is hard, and what we ship to do it.

iPhone forensic acquisition is the most technically demanding work in consumer DFIR. Apple's Secure Enclave, hardware-backed encryption keys, signed-system volume, and aggressive iOS hardening between every minor release mean there is no "run a tool from the cloud and read the phone" option. Each iOS version requires updated forensic methods, and most of those methods only work with a specific physical-cable connection to a licensed acquisition platform such as Cellebrite UFED, Magnet AXIOM, MSAB XRY, the same tools used by federal law enforcement and major IR firms. When a matter calls for it, we engage these platforms through our licensed partner network.

Android is a different problem set with the same conclusion. Verified Boot, full-disk encryption, and OEM-specific lock states (Samsung Knox, Google's Titan M2, Xiaomi's mi-account lock) all gate what can be acquired and how. Every Android make and model is its own acquisition path.

Remote forensics works, but the device has to be in the lab.

We work with clients across the United States. For remote engagements, we ship you a tracked, insured, evidence-grade shipping kit with anti-static packaging, tamper-evident seals, and a chain-of-custody form. You package the device, drop it at the carrier, and we acquire it in our lab using the appropriate acquisition workflow for that device and OS version. Findings are written up and the device ships back to you under the same chain of custody.

Total turnaround from device-arrival to written report is typically 5 to 10 business days for a standard single-device case. Active-incident or court-deadline cases compress under surge. A screen-share, an email of screenshots, or a remote session with the user holding the phone is not a forensic acquisition. It does not preserve evidence, it does not produce a court-admissible report, and we will not represent it as such.

If the device is in active use by a hostile actor (an abuser, an active attacker), we coordinate timing of the hand-off with you to protect the integrity of the evidence and your physical safety. Tell us this on the first call.

How We Work

A confidential, structured engagement.

01

Confidential Consultation

A direct conversation with Quinn, the founder and CEO who oversees every engagement. NDA-protected. No sales process.

02

Scoped Engagement

A clear written proposal with defined deliverables, timeline, and pricing. No hidden costs.

03

Investigation and Findings

Forensic work conducted to court-admissible standards, with regular communication and a written summary you can act on.

Certified Expertise

GIAC

Frequently asked about stalkerware

What is stalkerware and how is it different from a virus?
Stalkerware is software that someone with physical or account access installs on a device to secretly collect location, messages, photos, and activity and report them to the installer. Unlike a virus or generic malware, stalkerware is sold legally as 'parental monitoring' or 'employee monitoring' (mSpy, FlexiSpy, Cocospy, Eyezy, and dozens of consumer apps). It's typically installed by a current or former partner or family member with a specific surveillance objective. Because it markets as legitimate, antivirus tools often miss it; specialized forensic detection is required.
How do you detect stalkerware on a device?
On iPhones: configuration profile audit, MDM enrollment check, jailbreak detection, app-list reconciliation against installed-app indicators, iCloud account sharing audit, and behavioral indicators (battery, data usage, temperature anomalies). On Android: package-list audit including hidden packages, accessibility-service abuse check, device-admin abuse check, signed-app inspection, and known-stalkerware app database matching. Both platforms: review of trusted devices, sharing permissions, and account access logs.
Can you remove it without alerting the person who installed it?
Often yes, depending on the specific stalkerware and how it's configured. Some products send tamper alerts when removed; others don't. We review the product first, then plan removal in a way that either avoids the alert (where possible) or is timed for when the alert is least likely to escalate the situation. For survivors of domestic abuse, this planning step is critical to safety. We don't act until you're ready and have your safety plan in place. The first call is when we map this together.
What about AirTags, Tile trackers, and GPS tracking devices on cars or belongings?
Yes, physical tracking devices are within scope. AirTags can be detected via iOS Find My / Tracker Detect (Android), and the partial owner phone number can be retrieved via NFC scan. Tile and GPS trackers are detectable via Bluetooth scanning and physical search. We will sweep your vehicle, belongings, and home for known device classes, and document findings in a written report. If you find a tracker before we arrive, do not power it off. Leave it in place and call us; powering it off can be a tampering indicator.
How much does stalkerware detection cost?
You have two ways to work with us. Run the investigation yourself in the SleuthX tool for $995 once. That is lifetime access, with usage metered from a prepaid balance you top up anytime. Or have our team do it for you in a done-for-you device package: $3,000 for one device, $7,000 for three, $12,000 for five, each including the $995 lifetime license. A multi-device household sweep (phones, laptops, smart-home, vehicle tracker check) beyond a package is scoped per case at a flat $400/hour, with no multipliers. Sliding-scale pricing for survivors with limited resources is built into the practice and applied without paperwork on the first call. Pro-bono work is available case-by-case for advocate or attorney referrals. One safety note: if the device you would run the tool on may itself be monitored, sign up and work from a safer device, because activity on a monitored phone can be visible to the person who installed the software.
What do I do if you find stalkerware on my device?
We don't act unilaterally. We plan with you. Options include: (1) document and leave in place if the evidence is needed for legal proceedings before removal, (2) remove with timing aligned to your safety plan, (3) replace the device entirely with a clean one if removal is risky, (4) coordinate with attorney or advocate before any change. The written report is structured to support law enforcement reporting, civil litigation, or family-court filings depending on what your situation calls for.
Quinnlan Varcoe, Founder & CEO
Quinnlan Varcoe
GIAC-certified · Founder & CEO

Schedule Your Session

Schedule a confidential consultation

A direct conversation with Quinn, the founder and CEO who oversees every engagement. NDA-protected. No sales process. Most engagements begin within 48 hours.

Free, confidential · NDA-protected · no obligation.

  1. 1. Book a 30-minute call — we scope your situation, no charge.
  2. 2. You get a written scope — deliverables, timeline, and price — before any work begins.
  3. 3. Approve it and we start; most engagements begin within 48 hours.

Transparent pricing

Trusted by partners across the practice

DAS Health
Exhibit A Cyber
Ally Security
KIRO Group
Black Mirage
Kalles Group
Gridware
CQR
Archstone Security
Cyvergence
Sentinel Cyber
Cloud Underground
Seron Security
Hexen
Koru Risk Management
DAS Health
Exhibit A Cyber
Ally Security
KIRO Group
Black Mirage
Kalles Group
Gridware
CQR
Archstone Security
Cyvergence
Sentinel Cyber
Cloud Underground
Seron Security
Hexen
Koru Risk Management