Email, Exchange and on-premises
Server-side collection of mailboxes, archives and PSTs. Trap: archives and locally stored PSTs on endpoints that the server export never sees.
Disclosure fails at the collection step far more often than at the review step. This hub sets out each source of electronically stored information we acquire for UK disclosure (US: discovery), the method used, what the source actually yields, and the failure mode we see most often with each.
Plate · CollectionAnyone scoping a search and deciding which sources go into the Disclosure Review Document or the ESI protocol.
Building a custodian and source list that will not be reopened later.
Mapping where the organisation's evidence actually lives.
Prioritising the sources most likely to carry the conduct in issue.
Understanding what will be asked of each system and how disruptive it is.
Four patterns account for most of the failures we are asked to repair.
A search built around email in a business that has run its conversations through Teams or WhatsApp for years.
Custodians exporting their own data, destroying metadata and quietly omitting what they would rather not disclose.
Nobody checks tenancy retention, so the 30-day deletion of a leaver's mailbox is discovered after the hold should have caught it.
Personal cloud accounts, departmental databases and unsanctioned messaging apps that never appear on the IT asset list.
Each entry: how it is acquired, and the trap to plan for.
Server-side collection of mailboxes, archives and PSTs. Trap: archives and locally stored PSTs on endpoints that the server export never sees.
Purview and Graph collection across Exchange Online, SharePoint, OneDrive and Teams. Trap: retention and licensing determine what still exists.
Chats from participant mailboxes, channels from the group mailbox, files from SharePoint, reconciled together. Trap: edits and deletions are only retained under the right policy.
Vault-based collection of Gmail, Drive, Chat and Meet artefacts. Trap: shared-drive permissions hide relevant material from a custodian-scoped search.
Discovery or export API with workspace holds, covering channels, DMs, files and edits. Trap: free and standard plans limit retained history.
Forensic handset extraction and database parsing, with attachments and deleted-message artefacts. Trap: screenshots and chat exports carry no reliable metadata.
Device-level acquisition where the app permits; disappearing-message settings recorded as part of the evidence. Trap: content may simply no longer exist, which is itself a finding.
Logical and, where supported, full file-system extraction: messages, call logs, location, app data, deleted artefacts. Trap: passcode and encryption state decide what is achievable.
Extraction across a wide range of handsets and Android versions. Trap: vendor-specific security layers vary the achievable depth by model.
Full disk imaging or targeted acquisition, plus user and system artefacts showing file movement and device connection. Trap: full-disk encryption keys must be secured before imaging.
Targeted live acquisition of shares, mailboxes and exports, scheduled out of hours. Trap: permissions mean an administrator sees more than the custodian ever could.
Dropbox, Box, OneDrive, Google Drive and iCloud via administrative interfaces under account-holder authority. Trap: sync artefacts on endpoints often reveal deletions the cloud no longer shows.
Structured extracts with the schema documented and the query recorded so the output is reproducible. Trap: an undocumented query is not defensible evidence.
Authenticated capture with hash and timestamp, preserving the page as served. Trap: a screenshot with no capture record proves nothing about when the content existed.
Wallet artefacts from devices and on-chain tracing across exchanges and mixers. Trap: exchange records need a formal request and time; start early.
Infotainment, telematics, smart-device and video acquisition where the matter turns on presence or movement. Trap: most of these systems overwrite within days.
The method is the same discipline whatever the source.
Hash values are taken at the point of collection and re-verified on delivery, so any change is demonstrable.
A chain-of-custody record follows the evidence from acquisition to production and can be exhibited.
Filtering and search are applied after acquisition, never instead of it, so the unfiltered set still exists if scope is later widened.
The examiner who collected can give evidence about the method, the tooling and its limits.
Six questions we ask on every matter, in this order.
Consistent, whichever source the data came from.
Every system considered, collected or excluded, with the reason recorded.
Method, tooling, operator, timestamps and hash values for each item.
Processed, de-duplicated, threaded and loaded for review, with volumes before and after each step.
A plain-English account of how the evidence was obtained, suitable for a witness statement or an expert report.
Whether you are responding to a regulator, preparing for disclosure, or scoping an internal investigation, start the chain of custody with a short, confidential conversation.