Product line 01

The investigation platform, with the ledger underneath it.

Most digital forensics suites are good at extraction and weak at custody. Ours treats the two as one problem: every acquisition, every derived artefact and every analyst action is sealed into a hash chain at the moment it happens, so the integrity story is written by the tool rather than reconstructed afterwards from a logbook.

Capability map

Eight wings, one case file.

The platform is organised the way an investigation actually runs — from intake and triage, through analysis and legal preparation, to review, reporting and hand-off. Nothing crosses a boundary without leaving a record.

WING 01

Workspace

Case and evidence registers, scan centre, analysis history, findings, chain of custody, verification and a media manager — the daily surface an examiner works from.

CasesEvidenceFindingsCustody

WING 02

Investigate

Disk image analysis, memory forensics, e-mail forensics, volatile data capture, an evidence processor for bulk intake, and media authentication.

Disk imageMemoryE-mailVolatile

WING 03

Evidence & ledger

Ledger explorer, transaction timeline, Merkle inclusion proofs, and the network view over the permissioned ledger the custody chain is anchored to.

Ledger explorerMerkle proofTX timeline

WING 04

Legal & court

Warrant compliance enforcement, court-package assembly, electronic-record certificates, fabrication detection, media provenance verification and the evidence QR chain.

WarrantsCourt packagesCertificates

WING 05

Intelligence

Assisted evidence analysis and case assistance, digital forensics toolkit, network and log analysis, signature scanning, image forensics, synthetic-media detection and transcription.

Log analysisSignature scanImage forensics

WING 06

Collaborate

Shared boards and editors, cross-organisation evidence sharing with scoped access, and a live activity feed so a distributed team sees the same case state.

Cross-org shareCollab boardLive feed

WING 07

Reports & learning

Report generation, review and approval workflow, executive dashboards, full audit trail, methodology reference, artefact reference and structured training material.

Review & approvalAudit trailTraining

WING 08

Platform & administration

Import and export, cloud intake, methodology configuration, backup and disaster recovery, organisation and role administration, and the integration API.

Cloud intakeBackup & DRAPI

INDEX

77 workspaces and tools

The capability index above is generated from the portal’s own navigation — so what is advertised is what ships.

Built for the courtroom

Integrity that can’t be presented is integrity wasted.

These instruments turn a cryptographic record into paperwork a judge, a clerk or opposing counsel can act on — and check.

Evidence QR chain

Printable stickers carrying signed, revocable, scan-audited tokens. Anyone can scan one and confirm an item’s integrity and custody timeline on the public verification page — no account required.

Court package builder

Assembles a complete submission in one action: cover page, table of contents, statutory electronic-record certificate, examiner affidavit, chain of custody and Bates-numbered exhibits, under jurisdiction-specific rules.

Electronic-record certificates

Court-ready certificates issued as real, hashable documents whose digital signature is bound to the evidence digests, the examiner’s details and the ledger anchor — re-verifiable at any later date.

Warrant compliance

Scope enforced in code rather than policy. Every access to an item is checked against the live warrant’s status, expiry and scope; violations are blocked, logged, anchored and reported.

Fabrication detection

Six independent detectors — timestamp coherence, metadata inconsistency, generated-text perplexity, zone identifiers, synthetic log patterns and cross-source consistency — screen incoming material before it becomes an exhibit.

Media provenance verification

Provenance parsed at the byte level: a real container parser extracts embedded manifests and validates the signing chain, so an origin claim is checked rather than taken at face value.

Acquisition & analysis

What the examiner actually touches.

The analytical surface is deliberately conventional — examiners should not have to learn a new discipline to use it. What differs is that every operation below emits a custody event, and every derived artefact inherits a provable relationship to the sealed original.

  • Disk image analysis. Partition and file-system reconstruction, deleted-file recovery, timeline building and keyword indexing across acquired images.
  • Memory forensics. Process, handle, network-socket and injected-code analysis from volatile captures.
  • E-mail forensics. Mailbox and archive parsing, header and routing analysis, attachment extraction and thread reconstruction.
  • Network and log analysis. Session reconstruction from capture files, protocol breakdown, and log correlation with technique mapping.
  • Media authentication. Image forensics, synthetic-media screening, transcription, and provenance manifest validation.
  • Signature scanning. Rule-based artefact matching across acquired sets, with findings written straight into the case register.
DISKMEMORY MAILNETWORK SEALED MASTER 4 digests · encrypted WORKING COPYFINDINGSEXHIBIT SET CUSTODY CHAIN every operation above emits an append-only, anchored record CONTINUOUS RE-VERIFICATION stored bytes pulled back and re-hashed; mismatches quarantined

Fig. 03 — acquisition to exhibit

Deployment

Built for the way digital forensics units are actually run.

Multi-organisation by design

Separate organisations, roles and channels are first-class. Evidence can be shared across an organisational boundary with a scoped, revocable grant — and the grant itself is a custody event.

Default-deny interfaces

Every route and resolver is authenticated unless it is explicitly declared public. The public verification page is the deliberate exception, and it exposes integrity without exposing case-internal data.

Sovereign and air-gap aware

The custody hash chain is offline-capable: it continues to chain and verify without ledger connectivity, and anchors in batch when a connection is available. Storage is region-routed.

See it recompute in front of you.

The most useful demonstration is the least theatrical one: take a file, seal it, alter a byte, and watch the platform refuse to agree with itself.