If the evidence matters, the dollar amount should not decide whether anyone looks at it.
That is a view about which matters deserve a look. It is not a commitment to take one on, and the conditions are set out below.
Not every serious digital incident results in a large financial loss. That does not necessarily make the underlying evidence unimportant.
Individuals can encounter legitimate digital-evidence problems that fall below the financial thresholds normally associated with a large forensic engagement or formal investigation. The material in those matters is often ordinary: an account, a device, a configuration, a file, a record of something that changed.
AuditTrace Labs provides an inquiry path for people who believe meaningful digital evidence deserves technical review, preservation, or reconstruction.
If cost, case size, or the absence of a major financial loss has made it difficult to obtain forensic assistance, you are still welcome to contact AuditTrace Labs. When scope, authorization, technical fit, available evidence, and laboratory capacity allow, we may consider limited-scope assistance or other appropriate engagement options.
What an inquiry is
- A short description of what happened
- A statement of what you need to understand
- A technical read on whether evidence may still exist
- An assessment of scope, authorization, and fit
- A human decision, reached matter by matter
A matter can be small and still be technically serious.
The list below describes the kinds of circumstances this inquiry path exists for. They are circumstances, not criteria, and none of them commits AuditTrace Labs to accepting work.
Who this may apply to
- A comparatively small financial loss
- A matter below a firm's minimum engagement size
- A matter whose apparent monetary damages are small next to the technical question
- Digital evidence someone does not know how to preserve or interpret
- A system-state question that deserves technical review
- Records, devices, configurations, files, or communications whose context may matter
- A need for guidance on preserving evidence before it is overwritten
Timing often matters more than size
Logs rotate. Devices are reset and reissued. Accounts are tidied up. Configurations are overwritten. Whether a matter can be reviewed later depends largely on what still exists at the moment the question is finally asked.
The size of the loss is not the size of the evidence.
A financial figure describes an outcome. It does not describe what the system recorded, what changed, or how much of that record survived.
Whatever figure an inquiry mentions, the technical question sits elsewhere: what state still remains, and whether it can still be connected to the event it describes.
- An amount lost. The figure may be modest; the transaction record may not be.
- A compromised account. Access tends to leave traces across session, device and configuration state.
- A changed configuration. What changed, and when, is sometimes still recoverable.
- An unexplained file. Origin, chronology, and surrounding state carry most of the meaning.
- A disputed record. Two accounts of one event can sometimes be compared against the system itself.
- An altered device state. The condition of a device is itself evidence.
Each of these may still leave a technical story worth preserving, where the available source evidence and chosen retention scope support it. None of it implies that missing evidence can be recreated.
An inquiry can end in several places. None of them is promised.
These are possibilities AuditTrace Labs may consider. They are not a program, an entitlement, or a published offer.
Engagement paths
- A commercial forensic engagement on the usual terms
- A review scoped narrowly to a single technical question
- An engagement bounded by what the surviving evidence can actually support
Other outcomes
- Evidence-preservation guidance
- A referral, where another resource is more appropriate
- Research or laboratory consideration, where appropriate and authorized
- A conclusion that AuditTrace Labs is not the right fit for the matter
Nothing above is published as a rule
AuditTrace Labs does not publish eligibility criteria, thresholds, fee figures, discounts or free-work promises. Scope, authorization, and cost are agreed before any work begins, matter by matter.
Authorization comes before analysis.
AuditTrace Labs works only with systems, accounts, devices, records, and evidence for which appropriate authorization exists.
Authorization is part of the technical assessment rather than a formality after it. Before work begins we establish what is in scope, who is entitled to authorize it, which actions are permitted, and where the boundary sits.
Please describe only material you are entitled to have reviewed. Do not send another person's accounts, credentials, devices, or data, and do not attempt to access an account or device you are not authorized to use.
- Scope declared
- Authority confirmed
- Actions bounded
- Human approval
What a system kept does not depend on whether anyone filed a report.
Whether an incident was reported, and whether the report was complete, is a fact about the paperwork rather than a fact about the system. The two are easily confused: a matter that was never written up anywhere is assumed to have left nothing behind.
Retention does not work that way. Logs, configurations, and device state persist or rotate on their own schedule, indifferent to how serious the matter looked on paper. So the first useful question is not how the matter was categorized — it is what still exists, and for how much longer.
What AuditTrace Labs is not
AuditTrace Labs is not a law-enforcement agency, a law firm, a prosecutor, a court, an emergency service, or a government cybercrime reporting center. Technical assistance is not legal advice, and it does not replace reporting a crime or obtaining counsel.
If you are facing an urgent threat, an emergency, or immediate risk to safety, contact the appropriate authorities first.
The limits of what we will and will not claim are set out in Promises and Limits.
Describe what happened and what you need to understand.
The initial inquiry is deliberately brief. It is a first technical read on fit, evidence, and authorization — not an engagement, and not an acceptance.
Do not send credentials or sensitive evidence
Please do not send passwords, authentication credentials, private keys, access tokens or sensitive evidence through the initial inquiry form. If a matter is appropriate for further review, AuditTrace Labs can provide instructions for the next step.