Data Guard
Digital forensics

Specialised evidence recovery in New York City

When security breaks down, recovery is not enough — you need to know what actually happened.

Data Guard extracts and analyses data from Apple, Windows, Linux and mobile devices for corporate reviews, civil litigation support and urgent personal matters. We use the same tools relied on by law enforcement and government agencies to reach data that is otherwise out of reach.

The tools we work with

Elcomsoft iOS Forensic Toolkit

Used for access to locked or encrypted Apple devices. It performs full file system extraction from both legacy and current iPhone, iPad and Apple Watch models, recovering deleted messages, app data, credentials and files protected by the strongest layers of iOS security.

Due to Apple's evolving security architecture, full access — file system extraction or keychain decryption — cannot be guaranteed for every device or iOS version. Each case is assessed individually against the specific hardware and software provided.

Sumuri RECON ITR and RECON LAB

RECON ITR handles forensically sound acquisition of Mac computers, including Apple Silicon. RECON LAB is our cross-platform analysis engine: it recovers Apple Extended Metadata and correlates evidence drawn from Mac, Windows and cloud sources.

CRU WiebeTech write blockers and PALADIN

Certified hardware write blockers physically prevent any alteration of the source media during acquisition. We pair them with PALADIN, a forensic platform with a long track record in casework.

Every acquisition is documented from the first minute, so that the handling of the media can be reconstructed and reviewed later.

How an engagement starts

Every case begins with a call. We establish what devices are involved, who owns them, what question you actually need answered, and whether we are the right people to answer it. If we are not, we say so on that first call.

See how this works in practice — four engagements described in detail, including one where the logs did not survive and we could not identify the attacker.