Extraction and analysis of Android and iOS smartphones and tablets: messages, apps, location, media and deleted content, acquired with a method that preserves evidential value and protects every party.
Conversations, photos, movements, transactions, contacts: no other object concentrates as many traces as a smartphone. That is why it decides criminal, employment and family cases, as well as corporate investigations.
Yet the very device that holds the evidence destroys it just as easily: every unlock alters records, every sync overwrites data, and a single remote command can wipe everything. How the phone is accessed decides whether its content becomes evidence or a liability.
The Brazilian Superior Court of Justice (STJ) has been demanding method: in HC 943,895/PR (5th Panel, 2025), access to the phone before the forensic examination rendered the evidence unusable; in AgRg in HC 828,054/RN (5th Panel, 2024), screenshots taken directly on the device, with no extraction tool and no hash values, resulted in inadmissible evidence.
Forensic extraction exists precisely for this: to acquire the content of the device in a documented, verifiable and repeatable way, under ABNT NBR ISO/IEC 27037 and CPP, arts. 158-A to 158-F (Brazilian Code of Criminal Procedure).

Acquisition of live data through the system's own interfaces: contacts, calls, messages, media and accessible app data. It is the fastest and least invasive route; as a rule, it does not reach deleted content.
Access to the partitions and to the device's internal file structure, including app databases and their internal records: this is where deleted messages still present in the databases, settings and usage artefacts typically appear.
A bit-for-bit copy of the device memory, including unallocated areas: the greatest possible depth and the best chance of recovering deleted content. Feasibility depends on the make, model, operating system version and state of encryption.
The choice of method is not a preference: it is dictated by the device, by the operating system version and by the purpose of the examination. The report records which extraction was performed, with which tool and version, and what each choice does and does not reach, so that the method can be checked by either party.
The actual reach depends on the device and on the feasible method, but the typical repertoire includes:
WhatsApp, Telegram, Instagram, SMS and others: messages, groups, exchanged media and the apps' internal records, read directly from the device's databases.
Deleted messages, photos and videos that remain in unallocated areas or in residual database records. Even partial recoveries are often enough to demonstrate that the content once existed.
Date, time, source device and, where enabled, the GPS coordinates written into the file (EXIF): a photo stops being merely an image and becomes a dated, located event.
GPS records, known Wi-Fi networks and data from apps that record position: geolocation triage is often the first filter applied in a case with multiple devices.
Calls, contacts, calendar, browsing history, installation and removal of apps: the artefacts that reconstruct the user's digital routine.
Registered accounts, e-mail addresses, usage patterns and setup dates: the examination verifies whether the device handed over really is the one belonging to the person under investigation, including where someone attempts to present another phone as their own.
Extracted data is raw; it is the analysis that turns it into an answer. Two constructs underpin most conclusions:
Where the passcode is supplied by the owner or by whoever holds legitimate authority, extraction is the natural route. Without the passcode, the feasibility of access depends on the make, model, operating system version and condition of the device, and is assessed case by case, with no promise in advance: there are feasible scenarios, and there are scenarios in which the encryption prevails. The assessment states which scenario applies before any engagement.
A broken device is not a lost device: a dead screen, a damaged connector or a faulty board often conceal intact memory. In such cases, the recovery laboratory repairs the device until forensic extraction becomes possible, with every intervention documented. This subject has its own page: Forensic Data Recovery →
Most of the evidence lost on mobile phones is lost before the examination. The rules that preserve evidential value:
At the end of the extraction, the data is written to destination media finalised as read-only, with the hash calculated at closing and a numbered seal applied. From that point on, any insertion, alteration or removal of content becomes technically detectable: the hash would no longer match.
This design protects both ends of the case. Whoever brings the accusation receives evidence that withstands any allegation of tampering; whoever is under investigation receives the assurance that nothing can be added to their device after collection. A properly conducted forensic examination is not the instrument of one party: it is the neutral ground on which the data speaks for itself.
Production of evidence for the defence or the prosecution and technical review of official extractions: the experience of someone who trained the operators of the tool used by law enforcement also serves to check what was done on the case file.
Dismissal for cause, harassment, unfair competition and misuse of equipment: messages and records from the corporate or personal device, collected within legal limits.
Divorce, custody and parental alienation: conversations and media preserved with method, always starting from legitimate access to the device examined.
Internal investigations, sensitive dismissals, suspected breaches or fraud: the corporate device examined under a procedure that holds up if the matter reaches the courts.
Fraud, threats, account takeover: preservation of the victim's own device as evidence, before updates and everyday use erase the traces.
Attendance at a court-ordered extraction, drafting of questions to the expert and an opinion on someone else's report: the party's technical eye inside the proceedings.
See also
WhatsApp and Conversation Examination → Forensic Data Recovery → Computer Forensics → Expert Reports and Opinions →
The base is São Paulo; the reach is nationwide. Depending on the case, collection takes place at the laboratory, on site (an office, a company, a notary's office or a courthouse) or through an assisted remote procedure, under the same procedure of hashing and documented chain of custody.
A device at risk of remote wiping, an imminent procedural deadline or evidence about to expire: urgent preservation cases receive priority triage through the business WhatsApp line, including outside the standard response flow.
Before deciding, it is worth seeing what has already come through this laboratory: cases described without identifying the parties, in the format of challenge, method and result.
The intruder's control channel was written into smart contracts. The examination decoded what he had deleted and handed the authorities concrete routes to identification.
See the case Negative proofThe official examination had concluded that he took part. The re-examination showed the links were false positives, and the accused person was cleared.
See the case