About

Why ForensicsGuard exists

A small, founder-led company building one thing properly: a forensic platform that observes authorised activity over time, correlates it across sources, and preserves it as evidence that holds up.

The gap we set out to close

Established forensic platforms are very good at what they were designed for: acquiring a device and examining what is on it at a moment in time. That leaves a real gap. Important traces can disappear, appear intermittently, or activate only under specific conditions — and a bench examination structurally cannot see behaviour that only happens in the field.

Meanwhile, the organisations most exposed to advanced mobile threats are frequently the ones least equipped to investigate them: investigation units with case backlogs, laboratories building capability, missions operating under exposure, and organisations supporting people at elevated personal risk.

ForensicsGuard was built to close that gap — to observe authorised activity over time, correlate what the device says with what the network shows, and preserve the result in a form that survives scrutiny.

Local observation. Trusted evidence. Faster investigative decisions.

The three things that have to be true simultaneously, and the reason the platform is built the way it is.

Principles

How we build

These are not aspirations. They are the constraints the platform is actually designed against, and they explain most of the engineering decisions behind it.

Evidence-driven, not automated

The platform surfaces and correlates. The conclusion belongs to a qualified analyst, and the design supports that judgement rather than substituting for it.

Sovereign by default

Evidence stays on systems the customer operates. There is no route by which case material reaches us in normal operation.

Verifiable, not trusted

Integrity claims are backed by signatures a customer can check themselves, offline, against published keys.

Honest about limits

We publish what the platform cannot see — including where iOS and Android genuinely differ. An investigator who does not know the blind spots cannot reason about an absence of findings.

Offline is a supported case

Isolated deployment is a first-class configuration, not a degraded one. Connectivity improves updates; it is not a condition of operating.

Responsible about who we supply

We assess enquiries against our responsible-use position and decline those that do not fit.

Founder-led

Direct accountability, not a faceless vendor

ForensicsGuard was founded by Khireddine Garri, a digital-forensics practitioner with close to two decades of experience across digital forensics, security governance and cyber risk management.

The company was started to bridge the gap between advanced mobile threats and the practical investigative capability available to the institutions and people who need it most. It remains deliberately small and technically led — when you raise a question about the architecture, the answer comes from the people who built it.

ForensicsGuard is not a black-box product. It is a transparent initiative built for lawful analysis, institutional capability-building, and the protection of high-risk professionals.

Company details

Based in
Doha, Qatar
Founder
Khireddine Garri — LinkedIn profile

Procurement teams requiring full registered entity details, or documentation for a vendor-assessment process, should request them directly and we will provide them.

Sources

Where our threat intelligence comes from

Indicators of mercenary spyware activity are established by a small research community working in public. Our indicator sets draw on that published work — including the Mobile Verification Toolkit maintained by Amnesty International's Security Lab, and research published by The Citizen Lab at the University of Toronto.

We name them because attribution is the correct practice, and because an investigator weighing what an indicator means should know where it came from and who established it.

A citation, not a relationship

ForensicsGuard is not affiliated with, endorsed by, partnered with, or working alongside Amnesty International, The Citizen Lab, or any other research organisation named on this site. Their research is published; we use it as published, and we credit it. Nothing here should be read as implying anything further, and we would regard it as a misrepresentation if it were.

The limits

What we do not claim

For a company selling into procurement processes, what is absent from a website matters as much as what is on it. To be explicit:

No certifications
We hold no security certification or accreditation, and we claim none. The platform is designed against recognised evidence-handling principles, but no independent evaluation has been performed. If your process requires one, tell us early so we can be straight with you about it.
No published customer list
We do not publish customer names, logos, deployment counts or case studies. Nothing on this site should be read as implying a particular organisation uses the platform.
No partnerships or integrations claimed
Where we name other tools, it is to explain how our platform relates to them, not to assert a relationship with their makers.
No performance figures
Throughput and capacity depend heavily on the environment. We would rather establish real numbers with you during a pilot than publish a figure that will not hold on your network.

See it on your own network

A pilot puts a Guardian and a Lab Station into your environment, on a network you control, with your own team running the workflow.