Mobile forensics attracts confident claims in both directions: that a phone gives up everything or that deletion and privacy modes put data forever out of reach. Neither extreme is true. The assessments below are the same accuracy lines Sherlock Forensics holds in its own reporting, stated in public. Each verdict uses a five-point scale, from False to True. Every one is grounded in how iOS actually stores data and what a forensic acquisition can and cannot reach.
Forensic Fact Checks
iPhone Forensics Fact Checks
Twelve claims about iPhone evidence, rated by a working forensic examiner. Where a claim is true we say so, where it is false we say so and where the truth depends on the source we say exactly what the source has to be. No hype either way.
The Claim
"iPhone private browsing leaves no recoverable trace anywhere."
Verdict: Mostly False
Private browsing does keep visits out of Safari's history database, so the history view will not show them. That much is real. It does not follow that no trace exists anywhere. On a full-filesystem extraction, adjacent web caches and cross-app cached requests can still hold fragments of activity the history database never recorded. The honest position is narrow: private mode suppresses the history record, not every trace on the device.
The Claim
"Deleted iPhone photos are gone forever."
Verdict: False
A deleted photo first sits in Recently Deleted for about 30 days. Past that, its database record is not wiped on the spot; iOS marks the SQLite page free, so the entry can be carved back until new data overwrites it. Recovery is real but conditional: recent deletions on a lightly used phone often come back, while photos purged long ago on a busy device are usually overwritten and gone. Sherlock flags every carved photo as recovered, so nothing overstates what survived.
The Claim
"You must jailbreak an iPhone to analyze it forensically."
Verdict: False
A great deal of iPhone evidence comes from an encrypted logical backup, which needs only that the device is unlocked and set to Trust the computer, no jailbreak involved. Deeper full-filesystem evidence is produced by acquisition tools such as Cellebrite or a Magnet VeraKey workflow and then ingested for analysis, again without a jailbreak in the examiner's hands. Jailbreaking is neither required nor how mainstream mobile forensics works.
The Claim
"Any iPhone backup contains the keychain."
Verdict: Mostly False
Only an encrypted backup carries the keychain subset that holds saved credentials such as Wi-Fi passwords. An unencrypted backup deliberately omits it, which is why setting a backup password actually widens what an examiner can see. So the claim is true only for the encrypted case and false as a blanket statement, which lands it at mostly false.
The Claim
"Saved Wi-Fi passwords can be recovered from an iPhone."
Verdict: True
Saved Wi-Fi passwords live in the keychain. They come through in the clear from an encrypted backup as well as from a Cellebrite full-filesystem extraction. The one honest exception is a Magnet VeraKey image, which ships the keychain SEP-encrypted, so on that source the passwords stay locked. Outside that case the answer is a straight yes.
The Claim
"Significant Locations can be pulled from an ordinary iPhone backup."
Verdict: False
Significant Locations, the record of frequently visited places, is held behind the Secure Enclave and is not written into an ordinary logical backup. Reaching it requires a full-filesystem extraction from Cellebrite or VeraKey acquisition tooling. Promising Significant Locations from a plain backup is an overclaim. Sherlock scopes it to a full-filesystem source every time.
The Claim
"A forensic tool can decrypt the full iPhone keychain from any extraction."
Verdict: False
The source decides this, not the analysis tool. A full keychain in the clear depends on the decrypted keychain that a Cellebrite full-filesystem extraction ships. A Magnet VeraKey image ships the keychain SEP-encrypted, so that content stays locked from a VeraKey source no matter what tool reads it. Any product that claims to decrypt the whole keychain from every extraction is describing something the encryption does not allow.
The Claim
"Screen Time data proves who was using the phone."
Verdict: False
Screen Time records what the device did, which app was open and for how long, not who was holding it. That is device activity, not person activity. It is useful pattern evidence, but attributing it to a specific individual needs corroboration from other artifacts. Sherlock reports Screen Time as device behavior and leaves the question of the person to the wider record.
The Claim
"You can read WhatsApp messages from an iPhone image."
Verdict: True with scope
WhatsApp keeps its chats in an app database that an encrypted iPhone backup carries, so its messages, calls and shared media read from a backup as well as from a full-filesystem extraction. The scope is simply that the data has to be in the acquired image; Sherlock reads the WhatsApp record the evidence holds, it does not pull chats from WhatsApp servers or a cloud account. Within that scope the claim is true.
The Claim
"A Cellebrite extraction can only be opened in Cellebrite software."
Verdict: False
A Cellebrite UFED full-filesystem extraction is an evidence image, not a locked proprietary container. Sherlock Forensics iPhone Analyzer ingests a Cellebrite UFED or a Magnet full-filesystem extraction directly and gives full analysis, which is the entire point for a firm handed an extraction it could not otherwise open. You do not need the acquisition vendor's own analysis suite to read the image it produced.
The Claim
"Apple Health data can place a person at a location."
Verdict: Mixture
Health can hold GPS-tagged workout routes, so it does record device whereabouts. That part is real. What it does not establish is who was wearing the watch or carrying the phone that logged the activity. So it can support a location while it cannot, on its own, prove the person. It is corroborating whereabouts evidence, not identity evidence, which is why the honest rating is a mixture.
The Claim
"Find My proves who was carrying a device."
Verdict: False
Find My shows where a device is and which account it belongs to. Ownership of an account and possession of a device are not the same thing, so it cannot prove which person was carrying the phone at a given moment. It is strong association evidence that a specific device was somewhere. It needs corroboration to reach the person. Sherlock frames Find My as device and account evidence, never as proof of an individual.
Why We Publish Our Own Accuracy Lines
These verdicts are not marketing. They are the exact scopes Sherlock Forensics applies inside a real examination, put in public where anyone can hold us to them. A fact-check that quietly inflates a rating to sound more capable would be worse than none, because the whole value of forensic work is that the report says only what the evidence supports. If a claim is true we mark it true; where a claim is true only from a particular source, the source is named; and where a claim is false we say so plainly even when a softer answer would sell better.
Sherlock Forensics iPhone Analyzer is built the same way: it reads a backup or a Cellebrite or VeraKey extraction, reconstructs the device into a searchable timeline and produces a court-ready report, with recovered data flagged and every scope stated. Assessments by CISSP, ISSAP and ISSMP certified examiners with 20 years of court-defensible practice.
Related: All fact checks · The full parser list · Product page