WhatsApp
London, UK · Established 2007

Finding digital truth is our mission.

A London digital forensics laboratory instructed by solicitors, barristers, local authorities, government agencies and corporate investigators. We recover, examine and report digital evidence from phones, computers and cloud accounts, to a standard that survives challenge in UK courts and tribunals.

Practising since
2007
Standards
NPCC · ISO 17025
Response
8am–8pm Mon–Fri
Mobile phone forensics infographic: identify, preserve, acquire and report from smartphones with Cellebrite, GrayKey and XRY.
§ 01 · Mobile phone forensics
Criminal defenceCorporate forensicsFamily lawMobile phone expertsFor e-discovery · e-discovery.uk
§ 01 · Expertise

Digital forensic experts help you see beyond what meets the naked eye.

Every device holds a record its user never sees: activity logs, metadata, deleted fragments, synchronisation trails. Our examiners surface that record and translate it into findings a court can weigh, whether you are defending a client, disclosing in civil proceedings, or investigating misconduct inside an organisation.

We work as independent experts. Every examination is peer-reviewed, custody-logged and reported in line with NPCC guidance and ISO 17025, and our examiners attend court to defend their methodology when instructed.

§ 02 · Mobile phone forensics

London mobile phone forensics for law firms, businesses & individuals.

The phone is now the single richest evidence source in most criminal, family and employment matters. Our forensic process follows five controlled stages: Identification, Preservation, Acquisition, Examination and Reporting. Each stage is documented, hash-verified and designed to preserve evidential integrity from the moment the device enters the laboratory.

We acquire data using the same specialist tools relied on by law enforcement and government agencies, including Cellebrite UFED, Magnet Forensics GrayKey, FTK Imager Pro, MobilEdit Ultra and XRY. Depending on the device and lawful authority, we perform logical, file-system, physical and chip-off extractions to retrieve messages, call records, chat histories, media, app activity and location trails, including material the user deleted, and preserve it so it withstands scrutiny.

Mobile device forensics stages: Identification, Preservation, Acquisition, Examination, Reporting
01

Physical data extraction

Forensic recovery from dead, damaged, PIN-protected, encrypted or password-protected phones, tablets, MacBooks and Surface Pros.

02

Deleted data recovery

Deleted messages, conversations and media from WhatsApp, iMessage, Facebook, Instagram, Telegram, Snapchat and more.

03

Cell-site analysis

Location data, movement patterns and expert witness support to verify timelines, challenge statements or support alibis.

§ 03 · As featured

Featured in 999 Murderer Calling on Discovery+.

Our lead examiner Joseph Naghdi contributed the digital forensic analysis featured in 999 Murderer Calling, the Discovery+ crime series exploring how criminals dial 999 to escape justice and mislead investigators, only to be damned by their own words.

Across the series, Joseph explains how digital forensics helps detectives separate genuine distress calls from staged performances. He examines the acoustic detail of the calls themselves, the timelines they sit inside, and the digital footprints left on the suspects' phones, laptops and cloud accounts in the hours and days around each killing.

Episodes cover the Fentanyl Killer Luke D'Wit, pharmacist Mitesh Patel's staged burglary, Andrew Pearson's cover-up in the woods, Collin Reeves' fatal parking dispute and the seven-year mystery cracked by a single late-night 999 call. In each case, recovered messages, deleted media, location data, browser history and app activity turn a performance into a confession, giving investigators the evidence to charge, prosecute and secure a conviction.

Joseph's contribution reflects the same laboratory work we deliver every day for UK solicitors, police forces and corporate clients: rigorous acquisition, hash-verified preservation and evidence that stands up in court. Streaming now on Discovery+ and Amazon Prime Video.

999 Murderer Calling on Discovery+ — episodes page featuring Joseph Naghdi, contributing digital forensics expert
Joseph Naghdi · contributing digital forensics expert
§ 04 · Method

Challenges in data extraction from Modern Mobile phones

Modern extraction challenges

How acquisition from modern mobile phones is becoming increasingly difficult

Full-disk encryption, secure enclaves, stronger passcodes and factory-reset protection have made logical and file-system extraction from modern iPhones and Android devices far harder than it was a decade ago. When a device is locked or damaged, standard software tools often cannot reach the evidence held inside.

Computer Forensics Lab works in partnership with Magnet Forensics Axiom to overcome this limitation. Through our technology partnership with Magnet Forensics, we deploy Magnet Forensics GrayKey — one of the most advanced mobile phone extraction tools available — to lawfully access data that would otherwise remain inaccessible.

How we lawfully overcome modern encryption barriers

Our London laboratory is equipped to handle the full range of mobile encryption scenarios. When a device is locked or damaged, we first establish the lawful authority to examine it, then select the least intrusive method capable of retrieving the evidence. This may include advanced logical extraction, file-system parsing, bootloader-level access or, where proportionate, the use of Magnet Forensics GrayKey to unlock supported iOS and Android devices.

Each technique is documented in the case record, together with the device state, tool version and any limitations. Where full physical extraction is not possible, we target specific data categories—messages, call logs, location history, app data and deleted fragments—so the instruction is answered without unnecessary intrusion.

Latest from the lab

Watch an introduction to Computer Forensics Lab and how our digital forensic services support law firms, law enforcement and businesses.

Authenticity, hashes and verification

Every exhibit we acquire is fingerprinted with cryptographic hashes (SHA-256 and MD5) at the moment of capture and re-verified at each stage of examination. Those hashes travel with the evidence in a signed, timestamped custody log, so any alteration, however small, is instantly detectable. When we hand a report to court, the numbers on the page match the numbers on the original device, and any party can independently reproduce the check.

01

Acquisition

Hash-verified imaging, logged.

02

Preservation

Evidence integrity protected.

03

Access control

Documented, role-based, audited.

04

Reporting

Court-admissible, peer-reviewed.

§ 05 · Specialist services

Cyber security, OSINT & data recovery solutions.

01

Hacking & cybercrime investigation

When a system is compromised or data walks out the door, we establish what happened, how, and who was behind it, then produce a report fit for prosecution, litigation or regulatory disclosure, and close the route the intruder used.
02

Forensic data recovery

Failed drives, water-damaged phones, formatted media, corrupt RAID arrays, laboratory recovery that keeps the salvaged data evidentially intact, not just readable.
03

OSINT & data breach investigation

Open-source intelligence for due-diligence and litigation support, breach investigations that satisfy ICO reporting duties, and security audits for firms that handle privileged material.
04

Employee data theft examination for companies

A departing employee who copies a client list, a manager feeding a competitor, a contractor with a USB stick, most insider cases leave a clear digital trail across cloud accounts, work devices and personal phones. We find it, preserve it lawfully, and package it for tribunal, injunction or prosecution. Our examinations have supported UK insider-theft proceedings continuously since 2007.
CoversIP theftIndustrial espionageData exfiltrationComputer misuseEx-employee devices
§ 06 · Clients

Typical clients using our computer forensics services.

  • Solicitors & law firms
  • UK police & law enforcement
  • Local councils & government
  • Employment tribunals
  • Insurance companies & brokers
  • Banks & regulators
  • Auditors & accounting firms
  • Small & medium businesses
  • Divorce & family lawyers
  • Fact-finding & adjudicating bodies
  • Criminal & civil litigators
  • Private individuals
§ 07 · Credentials

Professional certifications & technology partners.

Approved UK Government Digital Marketplace supplier. Registered with the ICO (ZB395023). Certified examiners working with industry-standard forensic platforms.

Examiner certifications
  • EnCE
    EnCase Certified Examiner
    Guidance Software
  • CFIP
    Certified Forensic Investigation Practitioner
    Digital Forensics
  • CMFS
    Certified Mac Forensics Specialist
    Digital Forensics
  • CCE
    Certified Computer Examiner
    ISFCE
  • IACIS
    Certified Forensic Computer Examiner
    IACIS
  • ISFCE
    International Society of Forensic Computer Examiners
    ISFCE
Technology partners
  • AccessData
  • Guidance / EnCase
  • Cellebrite
  • Magnet Forensics
  • Passware
  • F-Response
  • Oxygen Forensics
Instruct the lab

Speak to a computer forensic expert today.

Solicitors, counsel, local government officers, investigators and company directors: describe your matter in confidence and an examiner, not a salesperson, will respond the same working day.