Platform overview
How the three components work as one system, and the method they follow from observation through to reporting.
Resources
This is the index for ForensicsGuard reference material. It lists what is published today and what each category is intended to hold. Where something is not written yet it says so, and gives you a route to the substance directly instead.
An empty category is more useful than a list of documents that resolve to nothing. No link on this page points at material we have not produced, and no category has been padded out to look fuller than it is.
Where a category is not yet published, the fastest route to the same substance is a direct conversation — and each card says which route that is.
Published
Written, current, and public. These are the pages most technical evaluations start from.
How the three components work as one system, and the method they follow from observation through to reporting.
How the components fit together, what each one holds, and precisely what does and does not depend on connectivity.
Identity, licensing, software integrity, evidence sealing and key custody, described mechanism by mechanism rather than as assurances.
Public verification keys and the verification contract, so signatures can be checked offline without involving us.
What the Android and iOS sensors can each observe, including the observations iOS does not permit an application to make.
Where the platform fits for the kinds of organisation that run it, and the constraints each one brings with it.
The library
These are the categories we publish into. Where material exists but is not public, the card says how to obtain it. Where it has not been written, the card says that instead.
Component-level documentation covering configuration, integration and verification. It is provided under NDA to organisations evaluating the platform rather than published openly.
How the platform's method — observe, detect, correlate, preserve, report — maps onto forensic practice, and what an analyst can and cannot conclude at each stage. The method itself is described today on the platform page; written methodology material is in preparation.
Placement, network prerequisites, isolated-network deployment and fleet enrolment. Provided alongside technical documentation, because the right answer depends on the environment it is being given for.
Release notes will be published here as releases are made generally available. Until then, the software a deployment is running is identified by the version shown in its interface, and its integrity can be checked against the published verification contract.
Where our own work produces findings that are useful to others and that we can stand behind publicly, this is where they will appear. We would rather publish nothing than publish research that does not meet that standard, so the category is empty rather than padded.
The questions that recur across evaluations — connectivity, out-of-band updates, licensing offline, integrity states, and access to case material. Maintained on the support page.
Direct requests
Technical material is provided through a conversation rather than a download button, so that it reaches a named organisation for a known purpose and arrives with the context needed to read it correctly.
Tell us what you are evaluating and what you need to establish. We will tell you what exists, what does not, and what we can provide under NDA.
If the material you are looking for is not published yet, describe what you need it for and we will tell you what exists, what does not, and what we can provide under NDA.