Evidence that holds up when it is questioned.
I recover, examine and explain digital artefacts on their way to becoming evidence — for lawyers, companies and investigators, from the first image of a device to the last question in a hearing.
What emerges is one reconstruction of what happened, drawn from file systems, message databases, deleted data, access logs and statements, with every finding supported by more than one source and graded proven, probable or unsupported. It is written for the people who have to decide — counsel, boards, management — with method and limits stated, so the decision survives when it is questioned in a hearing, a court or a negotiation.
Chain of custody, start to finish
-
Stage 1Acquire
Preserve first
Forensic imaging of phones, laptops, servers and cloud accounts, with hashes and a log that starts the moment the device is handed over.
- Write-blocked imaging
- SHA-256 verification
- On-site or remote seizure
-
Stage 2Analyse
Reconstruct what happened
Timelines, deleted data, messaging, e-mail and access logs — cross-checked across sources so a finding rests on more than one artefact.
- Incident & intrusion analysis
- Fraud and data-theft cases
- Mobile, endpoint, cloud
-
Stage 3Testify
Say it plainly
Reports written for the reader who has to decide, and expert testimony that survives cross-examination.
- Expert reports (DE / FR / EN)
- Court & arbitration testimony
- Second opinions on existing reports
Based in Zürich. Working wherever the evidence is.
Engagements across Switzerland and abroad, based in Zürich. Clear findings for people who have to decide. Devices, logs and accounts turned into what is proven, what is likely and what is not — so counsel, boards and management can act.
Start with a confidential conversation.
No engagement letter needed for a first call. Describe the situation; I will tell you what can be preserved and what can be proven.