Local AI · Trusted evidence · Sovereign control


Instant digital-forensics capability

For law-enforcement, government and institutional investigation units. Deploy rapidly. Detect earlier. Preserve trusted evidence.

The platform

One platform, from the device to the case file

ForensicsGuard is a single integrated system, not a collection of tools. Two kinds of sensor observe authorised activity; one analyst environment turns what they see into a documented, integrity-verified case.

Diagram of the ForensicsGuard platform. The Mobile Sensor, running on iOS and Android, and the Wi-Fi Sensor Appliance both connect to a central analysis engine, which feeds the Lab Station forensic analysis console.
Collection on the device and on the network; correlation, analysis and reporting on the Lab Station. Everything runs inside your own environment.

Why now

The investigative challenge

Important traces can disappear, appear intermittently, or activate only under specific conditions. A point-in-time examination may not reveal the complete operational behaviour of a device.

A forensic analyst's workbench: a laptop and monitor showing network analysis, alongside a microscope, a mobile handset and evidence bags
  • Point-in-time examinations may miss live behaviour Suspicious behaviour may appear only during real-world use.
  • Activity can resume after inspection A device may behave differently once it is returned to the field.
  • Investigators need rapid triage Case backlogs demand fast, defensible prioritisation.
  • Cases span devices and locations Evidence only makes sense when it is correlated.

Method

How ForensicsGuard works

The same four movements run through every deployment, whether the case is a single handset or a coordinated operation across several sites.

Observe Detect Correlate Preserve Report
  1. Observe mobile behaviour

    Applications, permissions, background activity and known indicators.

  2. Observe network activity

    The Guardian appliance observes authorised communications on a network under your control.

  3. Analyse and correlate

    The Lab Station prioritises findings and connects patterns across devices and sources.

  4. Preserve and report

    Integrity-verified findings, with audit and custody context.

Case study

Watch a case move through the platform

A synthetic investigation, recorded from the product interface: suspicious activity is observed on the network, identified as a departure from the device's own baseline, correlated against the handset's own record, placed on the map, sealed as evidence, and written up.

A synthetic case, recorded from the product interface. Every device, address, identity and case number shown was generated for this demonstration — no customer data, no real infrastructure. Silent; 1 minute 43 seconds.

What it shows

  1. Observe The Guardian records what the network carried — destinations, volume and the names each device asked for.
  2. Detect Regular low-volume contact while the handset is idle, departing from the baseline the device set for itself.
  3. Correlate The device-side and network observations of the same activity are matched and graded, with the basis shown.
  4. Map The correlated events placed geographically and stepped through in time, alongside the case timeline.
  5. Preserve Evidence hashed and sealed with its origin, time and engagement attached.
  6. Report Findings drafted locally and validated against the case record before an analyst sees them.

Positioning

Completing the missing picture

Established forensic platforms remain essential for acquisition and examination. ForensicsGuard complements them by observing authorised mobile and network behaviour over time — so you can understand what a device was doing, when it happened, and how often.

  • Application and permission activity
  • Background and intermittent behaviour
  • Network communications
  • Known indicators and triggered activity

The result

  • Document and preserve relevant suspicious activity as evidence
  • Prioritise devices and cases
  • Reduce unnecessary examinations
  • Keep evidence under your own control

Deployment

Local analysis. Fully isolated.

Detection, prioritisation, correlation and reporting run inside your own environment — inside existing laboratories, government facilities, or fully isolated networks. There is no dependency on a public cloud service, and no requirement to send evidence anywhere.

  • Evidence stays where you put it Cases, captures and exports live on systems you operate.
  • Designed to run offline Core collection and analysis do not require an internet connection.
  • Cryptographic identity Each Guardian carries its own hardware-bound identity.
  • Verifiable software Releases are distributed with signed integrity manifests.

Founder-led

Direct accountability, not a faceless vendor

ForensicsGuard was founded by Khireddine Garri, a digital-forensics practitioner with close to two decades of experience across digital forensics, security governance and cyber risk management. The company remains deliberately small and technically led — when you raise a question about the architecture, the answer comes from the people who built it.

ForensicsGuard is not a black-box product.

It is a transparent initiative built for lawful analysis, institutional capability-building, and the protection of high-risk professionals.

See it on your own network

A pilot puts a Guardian and a Lab Station into your environment, on a network you control, with your own team running the workflow.