§ Hub · Evidence sources · Reviewed September 2026

Every source, collected in a way that survives challenge.

Disclosure fails at the collection step far more often than at the review step. This hub sets out each source of electronically stored information we acquire for UK disclosure (US: discovery), the method used, what the source actually yields, and the failure mode we see most often with each.

Sources
16 principal
Method
Hash-verified
Standard
NPCC · ISO 27037
Mobilisation
24 to 72 hours
Ref · E-D · 2026 · §SRCClass · ConfidentialJuris · England & WalesStatus · Active
Forensic workstation with write blockers and devices, representing defensible collection from multiple evidence sourcesPlate · Collection
Plate · Plate · CollectionAcquired once, verified, never altered.
§ 01 · Audience

Who this page is for.

Anyone scoping a search and deciding which sources go into the Disclosure Review Document or the ESI protocol.

  • Litigation teams

    Building a custodian and source list that will not be reopened later.

  • In-house counsel

    Mapping where the organisation's evidence actually lives.

  • Investigators

    Prioritising the sources most likely to carry the conduct in issue.

  • IT and security

    Understanding what will be asked of each system and how disruptive it is.

§ 02 · The problem

How source scoping goes wrong.

Four patterns account for most of the failures we are asked to repair.

Risk
Mailbox-only scoping

A search built around email in a business that has run its conversations through Teams or WhatsApp for years.

Risk
Self-collection

Custodians exporting their own data, destroying metadata and quietly omitting what they would rather not disclose.

Risk
Retention blind spots

Nobody checks tenancy retention, so the 30-day deletion of a leaver's mailbox is discovered after the hold should have caught it.

Risk
Shadow systems

Personal cloud accounts, departmental databases and unsanctioned messaging apps that never appear on the IT asset list.

§ 03 · Scope

The source matrix.

Each entry: how it is acquired, and the trap to plan for.

§ 01

Email, Exchange and on-premises

Server-side collection of mailboxes, archives and PSTs. Trap: archives and locally stored PSTs on endpoints that the server export never sees.

§ 02

Microsoft 365

Purview and Graph collection across Exchange Online, SharePoint, OneDrive and Teams. Trap: retention and licensing determine what still exists.

§ 03

Microsoft Teams

Chats from participant mailboxes, channels from the group mailbox, files from SharePoint, reconciled together. Trap: edits and deletions are only retained under the right policy.

§ 04

Google Workspace

Vault-based collection of Gmail, Drive, Chat and Meet artefacts. Trap: shared-drive permissions hide relevant material from a custodian-scoped search.

§ 05

Slack

Discovery or export API with workspace holds, covering channels, DMs, files and edits. Trap: free and standard plans limit retained history.

§ 06

WhatsApp

Forensic handset extraction and database parsing, with attachments and deleted-message artefacts. Trap: screenshots and chat exports carry no reliable metadata.

§ 07

Signal and Telegram

Device-level acquisition where the app permits; disappearing-message settings recorded as part of the evidence. Trap: content may simply no longer exist, which is itself a finding.

§ 08

iOS devices

Logical and, where supported, full file-system extraction: messages, call logs, location, app data, deleted artefacts. Trap: passcode and encryption state decide what is achievable.

§ 09

Android devices

Extraction across a wide range of handsets and Android versions. Trap: vendor-specific security layers vary the achievable depth by model.

§ 10

Windows and macOS endpoints

Full disk imaging or targeted acquisition, plus user and system artefacts showing file movement and device connection. Trap: full-disk encryption keys must be secured before imaging.

§ 11

Servers and network shares

Targeted live acquisition of shares, mailboxes and exports, scheduled out of hours. Trap: permissions mean an administrator sees more than the custodian ever could.

§ 12

Cloud storage

Dropbox, Box, OneDrive, Google Drive and iCloud via administrative interfaces under account-holder authority. Trap: sync artefacts on endpoints often reveal deletions the cloud no longer shows.

§ 13

Databases and line-of-business systems

Structured extracts with the schema documented and the query recorded so the output is reproducible. Trap: an undocumented query is not defensible evidence.

§ 14

Social media and web content

Authenticated capture with hash and timestamp, preserving the page as served. Trap: a screenshot with no capture record proves nothing about when the content existed.

§ 15

Crypto wallets and blockchain

Wallet artefacts from devices and on-chain tracing across exchanges and mixers. Trap: exchange records need a formal request and time; start early.

§ 16

Vehicle, IoT and CCTV

Infotainment, telematics, smart-device and video acquisition where the matter turns on presence or movement. Trap: most of these systems overwrite within days.

§ 04 · Why e‑discovery.uk

How each acquisition is made defensible.

The method is the same discipline whatever the source.

Verified at acquisition

Hash values are taken at the point of collection and re-verified on delivery, so any change is demonstrable.

Documented at every hand-off

A chain-of-custody record follows the evidence from acquisition to production and can be exhibited.

Minimised deliberately

Filtering and search are applied after acquisition, never instead of it, so the unfiltered set still exists if scope is later widened.

Explainable by the person who did it

The examiner who collected can give evidence about the method, the tooling and its limits.

§ 05 · Typical matters

Scoping a source list that holds up.

Six questions we ask on every matter, in this order.

  • Who are the custodians, and who has already left the organisation?
  • Which systems did those people actually use for the conduct in issue, as opposed to which systems the organisation provides?
  • What are the retention and deletion settings on each of those systems, and when does material start to disappear?
  • Which sources are personal rather than corporate, and what consent or order is needed?
  • What date range is proportionate, and can it be justified in the Disclosure Review Document?
  • Which sources can wait, and which are volatile enough to need collecting this week?
§ 06 · Deliverables

What each collection produces.

Consistent, whichever source the data came from.

  • Source inventory

    Every system considered, collected or excluded, with the reason recorded.

  • Acquisition record

    Method, tooling, operator, timestamps and hash values for each item.

  • Reviewable set

    Processed, de-duplicated, threaded and loaded for review, with volumes before and after each step.

  • Statement of method

    A plain-English account of how the evidence was obtained, suitable for a witness statement or an expert report.

§ 07 · Frequently asked

Answers to the questions counsel ask most.

How do you collect WhatsApp messages as evidence for UK court proceedings?
By forensic acquisition of the device rather than by screenshot. We take a logical or full file-system extraction of the handset, parse the WhatsApp database, and recover messages, attachments, timestamps, participants, edits and, where the artefacts survive, deleted content. The result is hash-verified, documented in a chain-of-custody record and exported in a reviewable, threaded format with the original database preserved. Screenshots and forwarded chat exports are admissible in principle but weak: they carry no metadata, are trivially editable, and invite an authenticity challenge.
How is Microsoft Teams data collected for disclosure?
Through the Microsoft 365 compliance and Graph interfaces rather than by exporting from the client. One-to-one and group chats are stored in the participants' mailboxes, channel messages in the team's group mailbox, and shared files in SharePoint or OneDrive, so a defensible Teams collection is really three collections reconciled together. We collect messages, attachments, edits, deletions where retained, reactions and call metadata, and we record the tenancy retention settings, because they determine what could still exist.
Can deleted messages be recovered from an iPhone for litigation?
Sometimes. Deleted records may persist in unallocated database space, in write-ahead logs, in recently deleted containers, in an iCloud or iTunes backup, or on a paired device. Recovery depends on the iOS version, the elapsed time, the volume of subsequent activity and whether the handset was encrypted or reset. The honest answer is that deletion is often recoverable within days and rarely recoverable after heavy use. We test rather than promise, and we report what was and was not recoverable.
How do you preserve Slack data for an investigation?
By placing a legal hold in the workspace where the plan supports it, then exporting through the Slack Discovery or export API rather than by scrolling the client. We capture public and private channels within scope, direct messages, files, edits, deletions and shared links, with user and channel metadata, and we reconcile the export against the workspace audit log so gaps are visible rather than silent.
Do you need to take an employee's device away?
Usually not for long. Most collections are done on site in under two hours per device, or remotely with the custodian present on a call. Where a full physical image of a laptop is required, we image on site overnight or provide a loan machine. For personal devices we take a scoped, consent-based logical extraction and document exactly what was and was not acquired.
What about data held in the cloud by a third party?
Cloud content is collected through the provider's administrative and compliance interfaces under the account holder's authority, not by scraping. Where the account holder will not cooperate, a court order or a Norwich Pharmacal-type application against the provider may be needed, and we scope realistically before anyone spends money on an application.
Can you collect from a server without shutting the business down?
Yes. Targeted, live acquisition of the relevant shares, mailboxes or database exports is the norm; full physical imaging of production servers is reserved for cases where the file system itself is in issue. Collection is scheduled outside business hours where the load matters.
What is the most commonly missed source?
Chat. Teams, WhatsApp, Signal and Slack now carry the conversation that email used to carry, and they are routinely left out of a search that was scoped around mailboxes. The second most commonly missed is the departed employee whose mailbox was deleted 30 days after leaving.
Instruct the practice

Bring us in early. Defensibility is built, not retrofitted.

Whether you are responding to a regulator, preparing for disclosure, or scoping an internal investigation, start the chain of custody with a short, confidential conversation.

WhatsApp