Engagements are scoped to the standard the output needs to meet: internal review, regulatory disclosure, or litigation.
Acquisition and analysis of digital evidence from computers, mobile devices, servers, and cloud accounts, documented to a standard admissible in court.
Rapid-response engagement covering detection through recovery, with a 24/7 on-call desk for active breaches.
Static and dynamic reverse engineering of malicious code to determine behavior, capability, and likely origin.
Proactive hunting for undetected compromise, paired with vulnerability assessment and penetration testing to close the gaps found.
| Stage | What happens | Typical timeline |
|---|---|---|
| Intake | Scope confirmed, evidence sources identified, engagement letter signed | Same day |
| Acquisition | Evidence collected and hashed under documented chain of custody | 1–2 days |
| Analysis | Examination, reverse engineering, or hunt conducted by case lead | 3–15 days |
| Reporting | Findings delivered as a technical report and, where needed, an affidavit | 2–5 days |