Most of what matters now lives in the cloud, not on the device. Cloud forensics preserves and analyzes online accounts — files, mail, photos, messages, and the activity logs behind them — in a way that stands up to scrutiny in court.
What can cloud forensics recover?
- iCloud — messages, photos, backups, notes, and device sync history
- Google Workspace / personal accounts — Gmail, Drive, Photos, and full Takeout exports
- Microsoft 365 — Exchange mail, OneDrive, SharePoint, and Teams content
- Dropbox and other storage — files, prior versions, and share history
- Audit and login logs — who accessed an account, when, and from where
- Deleted items and version history still within the provider’s retention window
How do you collect cloud data without changing it?
We use documented, repeatable acquisition methods — authenticated account exports, provider APIs, and admin audit logs — and cryptographically hash every artifact so its integrity can be demonstrated later. The source account is never altered during collection, and every action is recorded. ROHOVOT works under a licensed California investigator (California BSIS PI License No. 190161) and a court-qualified computer-forensics expert witness.
Will cloud evidence hold up in court?
Yes — when it is collected lawfully, with the account holder’s authorization or a court order, and with an unbroken chain of custody. Our acquisition and hashing practices follow the digital-evidence handling principles published by the National Institute of Standards and Technology, so the results are defensible and repeatable. See NIST’s guidance at nist.gov/programs-projects/digital-forensics.