All engagements conducted under NDA·Evidence preserved to technical chain-of-custody standards·Engagements limited to qualified organizations

Free scanThe studyForensic TriageForensic AuditAI VendorsResearch
Free scan · no install
From $5,000, Scoped

What a Forensic Audit Examines, and How

The free read-out and the Forensic Triage work at the machine level. A Forensic Audit is the same kind of examination at organizational scope — collection under a written scope, and a chain of custody that holds up if the findings are ever challenged. From $5,000, scoped. Available after a Forensic Triage.

Free Read-Out, Forensic Triage, or Forensic Audit

Free read-outForensic TriageForensic Audit
PriceFree, one laptop$2,500 (first three clients $1,500)From $5,000, scoped
CoversOne laptopUp to 5 laptopsScoped in writing
Who collectsYou, with our open-source scannerYou, with a collection script we send youCollection under a written scope
What we receiveThe scanner's output (folder names and dates)The files the script collects, after you preview and remove anything you chooseArtifacts defined in writing beforehand
What it answersWhich AI tools are present, when each was last active, what evidence expires and whenWhen AI was used, which documents were open at the time, what the vendor's terms said that day, graded 1 to 5 with limitations firstThe same, across more machines, with chain of custody
DeliveryWithin 2 working days5 working days after we receive the fileAgreed in the scope
We access your machinesNeverNeverOnly within written scope
Your dataStays with you except the output you sendEncrypted transfer, analysed on an offline machine, deleted within 30 days with a certificateSame

For IT providers: you can resell the Forensic Triage at your own price. Ask us for the terms.

01

Browser records

Chrome and Edge keep browsing history (about 90 days) and one storage folder per website. Together they show which AI services were reached, and when.

02

Document activity

Windows records which files were recently opened. Matched against AI visits, this is how we assess whether a business document was likely involved.

03

Application records

Locally installed AI applications write files recording installation and use. What each one keeps varies by product and version, so we establish it per engagement rather than assuming it.

Scope and Limits

We report what the evidence supports, and nothing beyond it. We do not reconstruct what anyone typed. Every finding carries a 1 to 5 confidence grade, and its limitations come before its conclusion.

Scope is agreed in writing before collection begins, and nothing outside it is examined.

From "we don't know" to a decision

A triage narrows the question from every laptop, every file and every month to the specific people, documents and hours that matter, and tells you what to do about each.

GradeWhat we foundWhat you do next
1. PresentAn AI tool is on the machine, with no dated useNothing urgent. Cover it in your AI policy
2. UsedThe dates and times the tool was usedCheck whether that use was allowed under your policy
3. OverlapA business document was open within 15 minutes of AI useReview that document's sensitivity
4. Close matchThe document was opened within 5 minutes before AI use, confirmed by two independent recordsWith your counsel's guidance, ask that person for their own data export from the AI vendor. We analyse it and confirm or rule out the finding
5. ConfirmedThe export shows what was submittedYour counsel has the record needed to decide what comes next

We grade strictly. A grade rises only when an independent record confirms it, and anything that contradicts a finding is reported with it. If chats were deleted before the export, they won't appear in it, and we say so.

Chain of custody. Evidence destroyed on schedule.

A

Chain of custody

Every artifact is logged from the moment it's collected — what it is, where it came from, who handled it, and when — following SWGDE and NIST documentation standards. If a finding is ever challenged, the custody record is what makes it defensible.

B

Thirty-day evidence destruction

Collected artifacts are destroyed 30 days after final delivery unless you request otherwise in writing. You receive a certificate of destruction confirming it happened — your sensitive forensic data doesn't sit on our systems indefinitely by default.

Six parts. Every engagement.

Executive

Board-Ready Executive Summary

2–4 pages written for non-technical readers. Findings, risk level, regulatory exposure, and recommended immediate actions.

Technical

Full Findings Report

Complete documentation of every finding with evidence citations, artifact source, timestamp, a 1-to-5 grading, and its stated limitations. Written for General Counsel and CISO review. Structured for attorney work product delivery on request.

Visual

Risk Map by Department

A visual map of AI exposure by department and tool. Communicates where risk is concentrated and which teams need policy attention.

Regulatory

Regulatory Gap Analysis

Finding-by-finding mapping to HIPAA, SOX, GDPR, and EU AI Act obligations. Where a gap is present, we document the specific provision, the finding that triggers it, and the disclosure risk.

Action

Remediation Roadmap

Prioritised list of recommended actions ranked by risk severity and implementation complexity, with 30/60/90-day suggested milestones.

Forensic

Methodology & Chain of Custody Record

The collection method, the custody log, and the destruction certificate once evidence is destroyed. Required for any subsequent regulatory filing or litigation use of the findings.

We run Forensic Audits for organisations we've already run a Forensic Triage for.

It requires collection under a written scope, and we think that should be earned rather than sold. If you haven't run the free read-out or a Forensic Triage yet, that's where to start.