Forensic examinations and audits in corporate environments: technical inquiry into internal fraud, IT contracts and projects, software licensing and digital assets, with documented evidence and a method that withstands adversarial scrutiny.
Under the label of compliance, the market offers standardised adequacy programmes that promise conformity within a few weeks. This forensic unit does something else. The work here is forensic: examining systems, contracts, records and devices in order to establish facts capable of supporting a decision, be it dismissing an employee for cause, terminating an IT contract, responding to a software audit notice or closing an acquisition.
That is why this forensic unit does not promise conformity. Conformity is a state that depends on the continuous conduct of the company; what forensic examination delivers is different and, in a dispute, worth more: the technical and documented demonstration of what happened, of who did what, and of what the records actually prove.
The method comes from computer forensics: preservation of the evidence before any analysis, cryptographic hashing, chain of custody under arts. 158-A to 158-F of the CPP (Brazilian Code of Criminal Procedure) and ABNT NBR ISO/IEC 27037, and conclusions confined to what the evidence supports. The difference lies in the setting: here the object is the company, its systems, its contracts and its people.
Those who turn to this forensic unit are usually the legal department, the board, the audit committee or the law firm advising the company: someone who needs an impartial technical answer before taking an expensive decision.

Corporate litigation, regulatory investigations and international cooperation proceedings frequently require locating and producing electronic evidence scattered across mail servers, corporate systems, laptops and mobile phones belonging to dozens of custodians. Doing that without method means producing too much, exposing what did not need to be exposed, or producing too little and answering for concealment.
The work follows the ISO/IEC 27050 series framework, the international reference for electronic discovery, which organises the process into linked and documented phases. The result is a defensible body of evidence: every document produced has its origin, hash and processing trail on record.
Technology projects fail often, and the contract alone rarely says where responsibility lies. Forensic examination reconstructs the project from the evidence: proposals, schedules, minutes, emails, support tickets, code and system logs.
A go-live postponed or disastrous, corrupted data migration, endless customisations. The examination separates what was the implementer's obligation, what depended on the client and what the product was never able to do, and sizes the breach in technical terms.
Item-by-item comparison between contracted scope and actual delivery: requirements, acceptance records, SLAs, schedules and technical evidence of operation. A basis for termination, claims, defence or well-founded renegotiation.
Technical examination of systems in production: how features actually work, availability, content published on a given date and adherence of what was developed to what was specified, with a record fit to support court proceedings.
Forensic assessment of technology assets in mergers, acquisitions and investments: ownership and quality of the code, licensing liabilities, critical dependencies and hidden risks that change the price of the deal.
The allegation arrives through the internal channel, from a manager or from a client: suspected fraud, misappropriation of funds, information leakage, conflict of interest, harassment documented by digital means. From then on, every wrong step is costly: accessing the computer of the person under investigation without formal preservation, confronting before collecting, inadvertently destroying what would have proved the wrongdoing.
A forensic inquiry begins with the silent preservation of the evidence: forensic images of corporate equipment, preservation of mailboxes and system logs, all with hashing and chain of custody.
The examination is impartial by definition: the commitment is to what the evidence shows, including when it clears the person under investigation. The final report documents method, findings and limits, and serves as the basis for the internal disciplinary procedure, for dismissal for cause, for a recovery claim or for a criminal complaint, according to the decision of the company and its lawyers.
The processing of personal data during the inquiry observes the limits of the investigative purpose, with access restricted to what is necessary and segregation of out-of-scope material.
Documented technical survey of the estate: inventory of installed software and the corresponding licences, critical dependencies, single points of failure and business continuity risks. A faithful picture of the environment, backed by evidence, before it becomes the object of a dispute.
Technical defence against audit and infringement notices sent by major software vendors: independent review of the vendor report, identification of counting inaccuracies and a technical basis for negotiation. Also in the opposite direction: investigation of irregular use of the company's own software.
Forensic examination of attendance records in high-volume employment claims: integrity of the clockings, processing and adjustments applied, consistency between the timesheet, the database and the working hours alleged. Mass analysis, with a method reproducible case by case.
Impartial technical inquiry with chain of custody control. The report provided the grounds for the internal disciplinary procedure.
An audit of the vendor report identified technical inaccuracies. Technical negotiation reduced the amount originally claimed by 60%.
See also
Computer Forensics → For Companies → Expert Reports and Technical Opinions →
Before deciding, it is worth seeing what has already come through this laboratory: cases described without identifying the parties, in the format of challenge, method and result.
The intruder's control channel was written into smart contracts. The examination decoded what he had deleted and handed the authorities concrete routes to identification.
See the case Negative proofThe official examination had concluded that he took part. The re-examination showed the links were false positives, and the accused person was cleared.
See the case