01

Investigations & digital forensics

When a dispute, an incident or an allegation turns on what happened inside your systems, the answer has to be recoverable, explainable and able to survive challenge. We acquire and preserve evidence to a standard that holds up, analyse it properly, and report in language a court or a regulator can actually use.

Internal investigations, regulatory enquiries, fraud, employee misconduct, incident response. Examinations run in a controlled environment or on your premises, whichever the circumstances demand.

Our examiners have given expert testimony in court. That shapes how we work from the first image onwards — every step is documented on the assumption that someone hostile will one day read the file.

What you get

  • Forensically sound acquisition and preservation, with a documented chain of custody
  • Analysis of devices, cloud accounts, mail systems and server infrastructure
  • Expert reports written for legal audiences, not technical ones
  • Expert witness testimony where a matter reaches court
  • Findings you can act on before the report is finished, where time matters
02

eDiscovery & disclosure at scale

Disclosure exercises fail on volume far more often than they fail on law. The cost lands when counsel spends time and budget reading duplicates instead of analysing the documents that matter.

We run the whole pipeline — collection, processing, deduplication, culling, hosting, review management and production — and we size it to the matter rather than to whatever platform we happen to own.

Cross-border matters bring their own constraints: data that cannot leave a jurisdiction, languages that defeat throughput assumptions, review populations that need managing across time zones. We plan for those before they become a problem, not after.

What you get

  • Defensible collection across custodians, systems and jurisdictions
  • Processing, deduplication and culling that measurably reduces the review population
  • Review platform set-up, workflow design and managed review teams
  • Production in the formats the other side and the court will accept
  • A cost and timeline model you can take to your client or your board
03

Data governance & regulatory change

The UK and EU GDPR are no longer new. The problem now is drift — you hold data you have forgotten about, under policies nobody has tested, in systems that changed hands three reorganisations ago.

We inventory what you actually hold, map how it moves, and set it against what you are permitted to hold. That means interviewing the people who own the systems, not circulating a questionnaire and hoping.

Unlike most of the market, we do not stop at a risk report. We turn the findings into changes a business and its IT function can implement, and we stay involved while they are implemented.

What you get

  • A data inventory and records of processing grounded in how your systems really work
  • Data-flow mapping and classification, including third-party and cross-border transfers
  • Retention and deletion schedules that can actually be operated
  • Subject access and data subject request handling that does not consume a department
  • Prioritised, costed remediation — and help delivering it
04

Search orders & urgent execution

Search orders, dawn raids and regulatory visits are executed under time pressure, in front of people whose interests are not aligned with yours, and with little room to correct a mistake.

We have worked sites in both civil and criminal matters. Our teams give practical advice on the day and carry out the work on the ground — capture, imaging, logging and handover — while remaining answerable to the order and to supervising solicitors.

This is not something most consultancies can offer, and it is not something to attempt for the first time on the day.

What you get

  • Pre-execution planning and realistic resourcing
  • On-site capture and imaging under supervision, to evidential standard
  • Contemporaneous logging that stands up to later scrutiny
  • Coordination with supervising solicitors and opposing parties
  • Immediate secure handover and onward processing
05

Insolvency & asset tracing

By the time an office holder is appointed, the company's IT has often already gone — hardware sold or returned, cloud subscriptions lapsed, mailboxes cancelled, and the one person who knew the passwords no longer taking calls. Evidence has a short half-life in insolvency, and the clock starts before you are appointed.

We move quickly to preserve what is left, recover what looks lost, and reconstruct books and records where the accounting system is incomplete or has been interfered with. Then we follow the money — tracing assets, payments and connected parties across ledgers, banking data, correspondence and devices.

The output is written for the use you actually need to put it to: supporting a conduct report, an application under section 236, or a claim for a preference or a transaction at an undervalue.

What you get

  • Urgent preservation of devices, mailboxes and cloud accounts before access is lost
  • Recovery from failed, wiped or abandoned systems, including deleted and orphaned data
  • Reconstruction of books and records where the accounting system is incomplete
  • Asset and payment tracing across ledgers, banking data, correspondence and devices
  • Evidence packaged for director conduct reporting, section 236 applications and antecedent transaction claims
06

Building your own capability

Sometimes the right answer is to stop buying the service and own it. But what do you actually need, where does it come from, and what does it cost to keep running?

We design, cost and implement in-house forensic, eDiscovery and compliance capability — tooling, workflows, facilities and the people to run them — then build the support structure so the investment holds its value as you grow.

Training comes with it, or on its own: your data, your workflows, your industry, hands-on with a machine per delegate. Certification and testing where it is useful.

What you get

  • Capability assessment and a costed target operating model
  • Tool selection fitted to your workflows, rather than the reverse
  • Facility, process and evidence-handling design
  • Hands-on training on your own data and workflows, with certification where useful
  • Ongoing support so the capability survives the people who built it

How an engagement runs

Scope, mobilise, execute, hand back

01

Scope

We establish what the question actually is, what data exists, and what the deadline and budget will bear. If we are not the right team, we say so here.

02

Mobilise

We assemble the team the matter needs — examiners, data engineers, review leads, project managers — and stand up the infrastructure to run it.

03

Execute

We run the work under one accountable lead, reporting against the plan, and flag problems early rather than at the point they become unrecoverable.

04

Hand back

You get the findings, the evidence trail and the documentation. Where we built capability, your people are trained to keep operating it.

Engagements that need a team

Tell us the problem, the volume and the deadline. We will tell you honestly whether we are the right team for it.

Start a conversation