Solutions
Built for the institutions and people who carry the most risk
The platform is the same in every deployment. What changes is the question being asked of it. These are the settings it is designed for.
Government & law enforcement
Investigation units and cybercrime teams
Investigative backlogs make prioritisation the real constraint. ForensicsGuard adds the behaviour-over-time dimension that a single bench examination cannot provide, so devices and cases can be ranked on observed activity rather than on suspicion alone.
- Triage devices against observed behaviour, not assumption
- Correlate activity across several devices in one case
- Preserve findings with provenance and custody context
- Operate entirely within your own facilities
Digital forensic laboratories
Laboratories building or extending capability
ForensicsGuard complements established acquisition and examination tooling rather than competing with it. It covers what a point-in-time examination structurally cannot: how a device behaves over a period, on a live network, under real conditions.
- Sits alongside existing examination platforms
- Adds live behavioural observation to the lab’s methods
- Produces exports usable in existing case processes
- Runs on laboratory hardware, under laboratory control
National & enterprise security
Teams responsible for sensitive estates
Where an environment must be understood continuously rather than examined occasionally, the Guardian’s General Monitoring mode establishes what normal looks like — so that departures from it are visible, and can be escalated into a bounded case when they warrant it.
- Establish a behavioural baseline for an authorised environment
- Escalate from monitoring into a scoped, evidential engagement
- Keep management and evidence handling as separate privileges
- Deploy into isolated networks as a supported configuration
Diplomatic environments
Missions and embassies
Diplomatic environments combine high exposure with a strong requirement that nothing leaves the premises. The platform is built to operate offline, with evidence written to systems inside the mission and no operational dependency on an external service.
- No requirement to transmit anything off site
- Designed to run fully offline
- Evidence stored on equipment the mission operates
- Verification performed locally, against published keys
Journalists, media & NGOs
Organisations supporting people at elevated risk
Journalists, human-rights defenders, lawyers and NGO staff face elevated risk from targeted digital surveillance. Where an organisation supports such people, ForensicsGuard provides a structured way to examine a device and a network with a documented, defensible method.
- A repeatable method rather than an ad-hoc examination
- Findings that can be explained to a non-technical reader
- Analysis performed locally, without sending material to a third party
- Clear statements of what was, and was not, observable
Being straight about this
These are the settings we build for
They are not a customer list. ForensicsGuard does not publish customer names, deployment counts or references on this website, and nothing on this page should be read as implying a particular organisation uses the platform.
If a reference is relevant to your procurement, ask us directly and we will tell you honestly what we can and cannot provide.
Responsible use
Lawful, authorised analysis only
ForensicsGuard is built for lawful forensic analysis, institutional capability-building and responsible investigation. It does not provide offensive surveillance capabilities and is not designed to spy on people.
We assess enquiries against this position, and we decline engagements that do not fit it. Our responsible-use policy sets out how we approach this.
Our commitments
- No offensive surveillance positioning
- No guaranteed-detection claims
- No replacement for qualified judgement
- Formal cases require expert interpretation
See it on your own network
A pilot puts a Guardian and a Lab Station into your environment, on a network you control, with your own team running the workflow.