Frequently asked

Questions we get before the first call.

Straight answers on preservation, process, admissibility, and how an engagement actually works — written for counsel and in-house teams weighing whether to bring in a forensic examiner.


Getting started

Getting started

A digital forensics firm recovers, preserves, and analyzes electronic evidence, then explains what that evidence shows to people who have to make decisions about it — counsel, a board, a regulator, or a court. In practice that means imaging devices and cloud accounts without altering them, reconstructing activity from logs and artifacts, and producing a written record of the methodology that can be tested by the other side.

Digital forensics answers questions about what happened — who accessed a file, whether data was taken, when a device was wiped. eDiscovery is about producing electronically stored information in a matter where the facts are largely known and the volume is the problem. Many matters need both, and they overlap most at the collection stage, which is why it is worth deciding early rather than collecting twice.

Before evidence is handled, if that is still possible. The most common irreversible damage happens in the first days: a laptop is reimaged and reissued, a departing employee's account is deleted, IT searches a device and overwrites the artifacts that would have shown what was on it. An examiner brought in early shapes what gets preserved; one brought in late is often limited to documenting what was lost.

It depends on the number of devices and data sources, the volume of data, how quickly the work must happen, and whether the matter will require expert testimony. We scope the work before it starts and tell you what is driving the estimate, so the cost is a decision you make rather than a number that arrives later. Preservation is usually a small, fast piece that can be scoped separately from full analysis.

Preservation can generally begin quickly, and our New York office means devices in the metropolitan area can often be handled without shipping them anywhere. Because the evidence is decaying while the engagement is being negotiated — retention policies keep running, devices keep getting used — we treat time-critical preservation as a step that can be scoped and started ahead of the broader engagement.

Evidence and process

Evidence and process

Anything that a system will delete on its own schedule, and anything in the hands of a person whose conduct is in question. That typically means the individual's laptop and phone, their email and cloud accounts, relevant server and application logs with short retention windows, and any backup that is about to roll off. Issue a legal hold that actually reaches the systems doing the deleting — a hold that only reaches people is not a hold.

Chain of custody is the documented record of who had the evidence, when, and what they did to it, from acquisition through analysis. It matters because it is the first thing an opponent attacks: if there is a gap in the record, the argument shifts from what the evidence shows to whether the evidence can be trusted at all. A clean chain of custody makes that attack unavailable.

Both are possible and the right choice depends on the source. Computers and mobile devices generally yield the most complete evidence when imaged directly, and physical possession also produces the cleanest custody record. Cloud accounts, email tenancies, messaging platforms, and many server environments can be collected remotely given the right credentials and proper authorization.

Sometimes. It depends on the device, the file system, whether the storage is encrypted, how much time has passed, and how heavily the device has been used since. Even where the file contents are gone for good, the surrounding artifacts — logs, timestamps, registry and system entries, metadata — frequently establish that a deletion happened, roughly when, and by which account.

Tell us, in detail, before we start. Well-intentioned IT review is one of the most common sources of evidence damage: opening files changes access timestamps, running a scan writes to the disk, and reimaging destroys the artifacts entirely. It is usually still workable, but we need to know what was done so the report can account for it rather than being surprised by it in deposition.

Yes. Mobile extraction covers messages, call and location data, and application activity, and messaging content is frequently the decisive evidence in employment, trade-secret, and internal misconduct matters. What is recoverable varies significantly by device, operating system version, and whether the application stores data locally or only in the cloud.

Testimony and admissibility

Testimony and admissibility

It depends on the forum. New York state courts have historically applied the Frye general-acceptance standard to expert proof, while the federal courts sitting here — the Southern and Eastern Districts of New York — assess expert testimony under Federal Rule of Evidence 702. Arbitral forums such as AAA and JAMS apply their own rules. The practical consequence is the same in each: the methodology has to be defensible and clearly documented.

Yes. Our forensic professionals write their own reports and defend them in deposition and at trial. Splitting the analysis from the testimony creates an obvious vulnerability on cross-examination, so we avoid it.

Yes. Law & Forensics professionals hold 200+ special-master and neutral appointments and have worked in 100+ courts and arbitral forums. Neutral appointments are conflict-screened separately from party engagements, and the firm has been recognized for that work, including a Distinguished Neutral designation from the Academy of Court Appointed Masters.

Yes. Rebuttal work means reviewing the opposing methodology and the data underneath it, identifying where the conclusions go further than the evidence supports, and where appropriate reproducing the analysis independently to see whether the results actually hold up.

Working with us

Working with us

Yes, before any substantive discussion. Identifying the parties early lets us clear conflicts quickly and tell you promptly whether we are able to assist, which matters most when the timeline is short.

We treat inquiry details as confidential and limit access to the team reviewing the request. Contacting us does not by itself create an attorney-client relationship, and nothing on this site is legal advice, so please avoid sending privileged or highly sensitive specifics before an engagement is in place.

Yes. This practice is the New York presence of Law & Forensics LLC, whose professionals have worked across 100+ courts and arbitral forums. The New York office exists because so many significant digital-evidence matters are venued here, not because the work stops at the state line.

Go deeper

Questions specific to one discipline

Still have a question? Ask us directly.

Request a consultation