About
Why ForensicsGuard exists
A small, founder-led company building one thing properly: a forensic platform that observes authorised activity over time, correlates it across sources, and preserves it as evidence that holds up.
The gap we set out to close
Established forensic platforms are very good at what they were designed for: acquiring a device and examining what is on it at a moment in time. That leaves a real gap. Important traces can disappear, appear intermittently, or activate only under specific conditions — and a bench examination structurally cannot see behaviour that only happens in the field.
Meanwhile, the organisations most exposed to advanced mobile threats are frequently the ones least equipped to investigate them: investigation units with case backlogs, laboratories building capability, missions operating under exposure, and organisations supporting people at elevated personal risk.
ForensicsGuard was built to close that gap — to observe authorised activity over time, correlate what the device says with what the network shows, and preserve the result in a form that survives scrutiny.
Local observation. Trusted evidence. Faster investigative decisions.
The three things that have to be true simultaneously, and the reason the platform is built the way it is.
Principles
How we build
These are not aspirations. They are the constraints the platform is actually designed against, and they explain most of the engineering decisions behind it.
Evidence-driven, not automated
The platform surfaces and correlates. The conclusion belongs to a qualified analyst, and the design supports that judgement rather than substituting for it.
Sovereign by default
Evidence stays on systems the customer operates. There is no route by which case material reaches us in normal operation.
Verifiable, not trusted
Integrity claims are backed by signatures a customer can check themselves, offline, against published keys.
Honest about limits
We publish what the platform cannot see — including where iOS and Android genuinely differ. An investigator who does not know the blind spots cannot reason about an absence of findings.
Offline is a supported case
Isolated deployment is a first-class configuration, not a degraded one. Connectivity improves updates; it is not a condition of operating.
Responsible about who we supply
We assess enquiries against our responsible-use position and decline those that do not fit.
Founder-led
Direct accountability, not a faceless vendor
ForensicsGuard was founded by Khireddine Garri, a digital-forensics practitioner with close to two decades of experience across digital forensics, security governance and cyber risk management.
The company was started to bridge the gap between advanced mobile threats and the practical investigative capability available to the institutions and people who need it most. It remains deliberately small and technically led — when you raise a question about the architecture, the answer comes from the people who built it.
ForensicsGuard is not a black-box product. It is a transparent initiative built for lawful analysis, institutional capability-building, and the protection of high-risk professionals.
Company details
- Based in
- Doha, Qatar
- Telephone
- +974 7471 8495
- Founder
- Khireddine Garri — LinkedIn profile
Procurement teams requiring full registered entity details, or documentation for a vendor-assessment process, should request them directly and we will provide them.
Sources
Where our threat intelligence comes from
Indicators of mercenary spyware activity are established by a small research community working in public. Our indicator sets draw on that published work — including the Mobile Verification Toolkit maintained by Amnesty International's Security Lab, and research published by The Citizen Lab at the University of Toronto.
We name them because attribution is the correct practice, and because an investigator weighing what an indicator means should know where it came from and who established it.
A citation, not a relationship
ForensicsGuard is not affiliated with, endorsed by, partnered with, or working alongside Amnesty International, The Citizen Lab, or any other research organisation named on this site. Their research is published; we use it as published, and we credit it. Nothing here should be read as implying anything further, and we would regard it as a misrepresentation if it were.
The limits
What we do not claim
For a company selling into procurement processes, what is absent from a website matters as much as what is on it. To be explicit:
- No certifications
- We hold no security certification or accreditation, and we claim none. The platform is designed against recognised evidence-handling principles, but no independent evaluation has been performed. If your process requires one, tell us early so we can be straight with you about it.
- No published customer list
- We do not publish customer names, logos, deployment counts or case studies. Nothing on this site should be read as implying a particular organisation uses the platform.
- No partnerships or integrations claimed
- Where we name other tools, it is to explain how our platform relates to them, not to assert a relationship with their makers.
- No performance figures
- Throughput and capacity depend heavily on the environment. We would rather establish real numbers with you during a pilot than publish a figure that will not hold on your network.
See it on your own network
A pilot puts a Guardian and a Lab Station into your environment, on a network you control, with your own team running the workflow.