Solutions

Built for the institutions and people who carry the most risk

The platform is the same in every deployment. What changes is the question being asked of it. These are the settings it is designed for.

Government & law enforcement

Investigation units and cybercrime teams

Investigative backlogs make prioritisation the real constraint. ForensicsGuard adds the behaviour-over-time dimension that a single bench examination cannot provide, so devices and cases can be ranked on observed activity rather than on suspicion alone.

  • Triage devices against observed behaviour, not assumption
  • Correlate activity across several devices in one case
  • Preserve findings with provenance and custody context
  • Operate entirely within your own facilities

Digital forensic laboratories

Laboratories building or extending capability

ForensicsGuard complements established acquisition and examination tooling rather than competing with it. It covers what a point-in-time examination structurally cannot: how a device behaves over a period, on a live network, under real conditions.

  • Sits alongside existing examination platforms
  • Adds live behavioural observation to the lab’s methods
  • Produces exports usable in existing case processes
  • Runs on laboratory hardware, under laboratory control

National & enterprise security

Teams responsible for sensitive estates

Where an environment must be understood continuously rather than examined occasionally, the Guardian’s General Monitoring mode establishes what normal looks like — so that departures from it are visible, and can be escalated into a bounded case when they warrant it.

  • Establish a behavioural baseline for an authorised environment
  • Escalate from monitoring into a scoped, evidential engagement
  • Keep management and evidence handling as separate privileges
  • Deploy into isolated networks as a supported configuration

Diplomatic environments

Missions and embassies

Diplomatic environments combine high exposure with a strong requirement that nothing leaves the premises. The platform is built to operate offline, with evidence written to systems inside the mission and no operational dependency on an external service.

  • No requirement to transmit anything off site
  • Designed to run fully offline
  • Evidence stored on equipment the mission operates
  • Verification performed locally, against published keys

Journalists, media & NGOs

Organisations supporting people at elevated risk

Journalists, human-rights defenders, lawyers and NGO staff face elevated risk from targeted digital surveillance. Where an organisation supports such people, ForensicsGuard provides a structured way to examine a device and a network with a documented, defensible method.

  • A repeatable method rather than an ad-hoc examination
  • Findings that can be explained to a non-technical reader
  • Analysis performed locally, without sending material to a third party
  • Clear statements of what was, and was not, observable

Being straight about this

These are the settings we build for

They are not a customer list. ForensicsGuard does not publish customer names, deployment counts or references on this website, and nothing on this page should be read as implying a particular organisation uses the platform.

If a reference is relevant to your procurement, ask us directly and we will tell you honestly what we can and cannot provide.

Responsible use

Lawful, authorised analysis only

ForensicsGuard is built for lawful forensic analysis, institutional capability-building and responsible investigation. It does not provide offensive surveillance capabilities and is not designed to spy on people.

We assess enquiries against this position, and we decline engagements that do not fit it. Our responsible-use policy sets out how we approach this.

Our commitments

  • No offensive surveillance positioning
  • No guaranteed-detection claims
  • No replacement for qualified judgement
  • Formal cases require expert interpretation

See it on your own network

A pilot puts a Guardian and a Lab Station into your environment, on a network you control, with your own team running the workflow.