Methodology
A documented process, from intake to handover
Investigative findings are only as useful as the record behind them. Our methodology exists so that any conclusion we report can be traced back to the material that supports it.
Ten Stages
How an engagement proceeds
Not every matter requires every stage. Where a stage is omitted, the report says so.
- 01
Intake and confidentiality
We record the general nature of the matter, confirm there is no conflict, and agree how information will be exchanged securely.
- 02
Scope definition
Objectives, boundaries, deliverables, timing and cost basis are set out in writing before any investigative work begins.
- 03
Evidence intake and preservation
Material provided by the client is catalogued on receipt, with dates, sources and handling recorded so provenance stays traceable.
- 04
Open-source and public-record research
Registries, filings, court and regulatory records, and publicly accessible digital information are collected and captured with timestamps.
- 05
Blockchain and transaction analysis
Where digital assets are involved, transactions are traced across public chains, related addresses grouped, and service interactions noted.
- 06
Digital evidence review
Emails, headers, logs, device exports and platform records the client is entitled to share are reviewed and normalized for analysis.
- 07
Corroboration and cross-checking
Each material assertion is checked against a second source where one exists; single-sourced points are labelled as such.
- 08
Timeline and relationship mapping
Events, accounts, entities and transfers are assembled into a chronology and relationship map that can be followed independently.
- 09
Reporting
Reports separate observation from interpretation, cite their sources, and state limitations, assumptions and unanswered questions explicitly.
- 10
Handover and next steps
We walk the client and their advisers through the findings and outline the realistic options, including where legal process or authorities are required.
Boundaries
What we do not do
These limits are not negotiable, and we decline instructions that require crossing them. They protect the client as much as the firm: evidence gathered unlawfully is rarely of any use later.
- Hacking, unauthorized access, or bypassing authentication
- Obtaining passwords, private keys, seed phrases or credentials
- Deploying malware, spyware or interception tools
- Unlawful surveillance, tracking or covert recording
- Pretexting or impersonation to obtain protected information
- Purchasing or handling stolen or unlawfully obtained data
- Interfering with law-enforcement or regulatory processes
- Guaranteeing identification, asset freezing or recovery
Information on this website is provided for general informational purposes and does not constitute legal, financial, cybersecurity, or investment advice. Investigative services are subject to the facts of each matter, applicable law, available evidence, and the agreed scope of work. No specific result is guaranteed.
Begin with a confidential conversation
Share the general nature of your matter and we will explain the realistic investigative options available to you.