Platform

One system, from observation to case file

ForensicsGuard is a single integrated platform. Sensors observe authorised activity, an analyst environment correlates it, and the resulting case carries its own integrity and provenance. Every part of it is designed to run inside your own environment.

The platform flow runs in three stages: collect, correlate, then decide.

  1. 01 Collect

    Mobile Sensor

    Android · iOS

    Records device-side observations on the handset itself.

    Guardian

    On-premise appliance

    Observes authorised network activity on a network you control.

  2. 02 Correlate

    Lab Station

    Analyst environment

    Ingests both sources into a case, correlates them, and preserves the result.

  3. 03 Decide

    Analyst

    Human judgement

    Reviews correlated findings and produces the reported conclusion.

Method

Observe, detect, correlate, preserve, report

These five movements are the spine of the platform. Each one is a distinct stage with its own record, so a finding can always be traced back to the observation it came from.

01

Observe

Mobile Sensors record device-side activity on the handset. The Guardian observes network activity on a network you operate and have authorised for observation. Neither requires the other — but together they see more than either does alone.

02

Detect

Observations are evaluated against indicator sets and behavioural rules — known indicators, unusual connection patterns, beaconing, and communications that stand out from a device's own established baseline.

03

Correlate

The Lab Station brings sources together. Device-side observations and network observations that describe the same activity are matched into a single account of what happened, across devices and across time.

04

Preserve

Evidence is hashed and sealed as it is taken in. What was collected, when, by which sensor, and under which case remains attached to the material for the life of the case.

05

Report

Findings are assembled into reports for both technical and non-technical readers, with the underlying evidence referenced rather than summarised away.

Components

What makes up a deployment

A deployment is sized to the work. A single Guardian and one Lab Station is a complete, working system; Mobile Sensors are added per device under investigation.

Why two sources

A device describes itself. The network describes it too.

Device-side observation tells you what an application asked for. Network observation tells you what actually left the device. Each has blind spots the other does not.

Correlating them is the point of the platform: when both describe the same activity, the finding rests on two sources collected differently — a materially stronger position than either alone.

What the device can show

  • Installed applications and their permissions
  • Background and intermittent activity
  • Device-side name resolution
  • Indicator matches evaluated on the handset

What the network can show

  • Connections that were actually established
  • Name resolution as it appeared on the wire
  • Encrypted-session characteristics, without decryption
  • Timing, volume and repetition across a whole session

Operating model

Yours to run, yours to keep

The platform is designed so that the parts which matter forensically do not depend on us, on an internet connection, or on anything outside your control.

On your premises

Guardian and Lab Station run on hardware in your environment. Cases, captures and exports are written to storage you operate.

Offline by design

Collection, analysis, correlation and reporting do not require an internet connection. Network access adds updates and intelligence; it is not a condition of operating.

Separated planes

Management traffic and evidence traffic are handled as distinct planes, so administering an appliance and handling case material are not the same privilege.

Verifiable software

Releases are distributed with signed integrity manifests, so a deployment can establish that it is running the software it is supposed to be running.

See it on your own network

A pilot puts a Guardian and a Lab Station into your environment, on a network you control, with your own team running the workflow.