Investigations

Determine what actually happened.

Independent digital forensic examination and incident reconstruction for contested matters, litigation, AI-related incidents, and critical organizational decisions.

Examination
Independent
Evidence
Traceable
Finding
Bounded
FORENSIC RECONSTRUCTION MODELObserved ≠ inferred
Documented recordTested inferenceFinding boundary

Capabilities

From preserved artifact to defensible finding.

We examine the available evidence, distinguish observation from inference, test competing explanations, and report conclusions no stronger than the evidence supports.

PreserveSource integrity
ReconstructEvent sequence
TestCompeting explanations
ReportBounded conclusion

AI forensics / Incident investigation

Investigate incidents where AI is part of the evidence.

Reconstruct incidents involving AI systems, autonomous or agentic workflows, AI-assisted actions, and generated media. Examination may draw on prompts, outputs, system and tool-call logs, configuration, identity records, access events, and surrounding device or network evidence.

Establish what the system did, what a person or process authorized, and where the record is incomplete.

Discuss an AI-related incident
AI incident evidence registerSources examined together
  • Prompts and outputsInteraction record
  • System and tool logsExecution record
  • Identity and accessControl record
  • Generated mediaProvenance record
Related practiceWhen the question extends beyond the incident.

AI assurance examines system behaviour, controls, accountability, and governance readiness.

Explore AI assurance ↗
  1. Digital forensic examination

    Examination of computers, devices, accounts, and available records when user activity, data handling, preservation, or the integrity of the record is disputed.

    Typical triggers
    Suspected data or intellectual-property theft, employee misconduct, insider activity, preservation disputes, or contested device use.
    Evidence examined
    Devices, storage media, files, metadata, email, cloud and account records, and other sources available within the authorized scope.
    Typical work product
    An evidence inventory, examination findings, a supported timeline where possible, stated limitations, and a client or counsel briefing.
    Material limits
    Access authority, encryption, retention, device state, missing records, and evidence integrity can limit what can be recovered or concluded.
    Discuss an examination
  2. Incident reconstruction

    Forensic preservation and reconstruction of breaches, ransomware events, and other incidents using the records that remain available.

    Typical triggers
    A breach or ransomware event requires a preserved record, tested timeline, review of suspected entry or spread, or post-incident findings.
    Evidence examined
    Host, identity, network, security-tool, cloud, application, and backup records available within scope.
    Typical work product
    A reconstruction timeline, evidence register, supported findings, unresolved questions, limitations, and an agreed technical or executive briefing.
    Service boundary
    Zemi North provides scoped forensic preservation, examination, and reconstruction. Emergency containment, eradication, restoration, negotiation, and continuous monitoring require separate operational arrangements. Root cause is reported only when the available evidence supports it.
    Discuss an incident
  3. Expert evidence

    Independent examination and reporting for legal proceedings, including affidavits, testimony, and review of another expert’s work.

    Typical triggers
    Counsel or a decision-maker requires an independent technical opinion, a reviewable report, or examination of another expert’s analysis.
    Evidence examined
    The defined evidentiary record, relevant examination materials, opposing reports, instructions, and applicable procedural requirements.
    Typical work product
    An independent report, affidavit where instructed, technical briefing, expert consultation, testimony, or a scoped review memorandum.
    Material limits
    The opinion depends on mandate, qualifications, evidence completeness, procedural requirements, and the independence of the examination.
    Discuss expert support
  4. Litigation support

    Technical examination of messages, email, metadata, documents, and timelines for civil, employment, family, and insurance matters.

    Typical triggers
    A party disputes when a document was created or changed, whether communications remain recoverable, or what a digital sequence establishes.
    Evidence examined
    Original devices and files where available, message and email records, metadata, platform exports, backups, and related account records.
    Typical work product
    A preservation or examination record, recovered material where technically available, timeline analysis, authenticity findings, and stated limitations.
    Material limits
    Deleted content is not always recoverable. Recovery and authenticity findings depend on the original evidence, platform retention, access, and corroboration.
    Discuss litigation support

Initial discussion / Non-confidential

Have a matter where the facts are contested?

Begin with the question that needs to be answered. Evidence transfer follows authority, conflict, and scope checks.