Digital Evidence Readiness

Would your evidence hold up in court?

When an investigation, a dispute or a breach lands on your desk, the evidence you collect is only as strong as the process behind it. Opposing counsel does not attack the data; they attack the handling. This self-audit walks the evidence lifecycle the way an examiner and a cross-examining lawyer both would, scores your readiness and explains what each control means and why it decides admissibility. Built by court-qualified examiners, digital forensics since 2006.

This is a readiness self-assessment, not legal advice. Admissibility is decided by a court on the facts of each matter. These are the controls that make evidence defensible, not a guarantee of any outcome.

0%
At Risk Evidence is likely challengeable. These are gaps a competent opponent will find.

Digital Evidence Readiness Self-Audit · Sherlock Forensics · a self-assessment, not legal advice.

1. Evidence Identification and Scope

0/5

You can list every system, account, device and cloud service that may hold relevant data.

You know which data is transient and will be lost first (RAM, logs, cloud tenancy, ephemeral messaging).

Scope is documented and defensible (why these sources, why not others).

You distinguish evidence you must PRESERVE from data you will ANALYZE.

Personal-device and BYOD data in scope has a lawful basis to collect.

2. Preservation and Legal Hold

0/5

A legal hold can be issued and tracked the day a matter is reasonably anticipated.

Auto-deletion, retention rules and journaling are paused for held custodians.

Preservation is verified, not assumed (you confirm the data still exists after the hold).

Cloud and third-party data is preserved before tenancy or contracts lapse.

Original evidence is never worked on directly. You preserve a master and work on copies.

3. Forensic Collection Integrity

0/6

Collections use write-blocking or read-only acquisition so the source is never modified.

Every acquired item is hashed (SHA-256) at collection and the hash is recorded.

Hashes are re-verified before analysis and before it goes to court.

Collection is documented: who, what, when, how, tool plus version.

Where deleted or damaged data is recovered, the method and its limits are stated.

You capture the acquisition context the tool records (device state, access decisions, what was and was not reachable).

4. Chain of Custody

0/4

Every transfer of evidence is logged (from whom, to whom, when, why).

Evidence storage is access-controlled and the access is auditable.

Custody records tie to the hash, so the item in the log is provably the item in hand.

The chain survives personnel changes (it is a record, not one person's memory).

5. Email and Archive Evidence (PST / OST / MSG)

0/5

Email is examined from the archive, not from a live mailbox that keeps changing.

You can read PST, OST and MSG without Outlook altering the source.

Message authentication is checked (SPF, DKIM, DMARC, full headers, transport path).

Timestamps are handled in a stated, consistent timezone (originals unchanged).

Deleted and recovered items are labelled as recovered, with their limits.

6. Mobile Device Evidence

0/5

Collection is consent-based or under lawful authority, and that basis is recorded.

You understand what a logical acquisition can and cannot reach on modern devices.

Recovered records (deleted rows, gaps) are distinguished from live data and labelled.

Encrypted content is decrypted with a lawful key, never cracked.

Mobile findings can be reproduced from the same extraction by another examiner.

7. Analysis and Reporting

0/5

Reports state the tool, version and method for every finding.

Findings are reproducible: another examiner, same inputs, same result.

Every reported artifact carries its own integrity hash.

Reports state limits and what was NOT found or not reachable.

Timestamps, timezones and units are consistent and explained across the report.

8. Legal Defensibility and Expert Readiness

0/4

A qualified examiner can explain and defend the method under cross-examination.

Methods meet a recognised standard (reliable, tested, reproducible, the Daubert factors).

Disclosure obligations are met (the other side can examine your process and exhibits).

The organisation knows when to bring in a qualified examiner rather than improvise.

What your score means

  • At Risk (0-40%): Evidence is likely challengeable. These are gaps a competent opponent will find.
  • Developing (41-70%): The basics exist but the chain has weak links.
  • Defensible (71-90%): A sound process. Tighten the last gaps.
  • Court-Ready (91-100%): A process built to survive cross-examination.

Gaps in this audit are exactly where cases are won and lost. Sherlock Forensics builds the tools that close them. PST Viewer for court-ready email examination, Android Acquirer and iPhone Analyzer for consent-based mobile collection and Recover for what others miss. We also provide court-qualified examiners when a matter needs to hold up. Digital forensics since 2006.

See the forensic tools Talk to an examiner

Email me my results plus the companion remediation playbook

Optional. Get a copy of this audit and a short next-steps playbook for closing the gaps. No spam, one email.

This self-audit is general guidance for digital evidence handling and is not legal advice. Admissibility standards and procedural rules vary by jurisdiction. Confirm the requirements for your matter with counsel.