Describe what happened
Tell us what you noticed and when: a security alert, an unfamiliar application, unexplained settings or messages you don't recognise. Include any recent repair, loss of the phone or access by someone else.
Battery drain or a slow phone alone doesn't establish malware. We consider the circumstances alongside the evidence available for examination.
Agree what we can examine
We start with the exact device model, software version, current condition and available access. The review may cover installed applications, configuration changes, device events and other relevant records supported by the method.
If you already have account alerts or activity records, we can discuss including them within the agreed scope. Direct access to cloud accounts is separate from this device assessment.
Get findings with the limits explained
We report the material reviewed, relevant indicators and the examiner's interpretation. We also identify unavailable records and other gaps that limit the conclusion.
Finding no indicators means none were observed in the data and methods used. It cannot establish that a phone has never been compromised.
The report can inform your IT or incident-response team's next steps. Agree any recovery or remediation work separately from the assessment.
Before making changes
Record the symptoms and approximate times. Tell us about resets, updates, removed applications or other changes already made.
A factory reset or cleanup may remove useful records. If it is safe to wait, discuss preservation before changing the phone. If there is an immediate risk, follow your organisation's incident-response or security procedure.
Common questions
Can you certify that a phone is clean?
No. We can report the results of a defined examination and explain its limits. A clean-device guarantee would go beyond those findings.
Is the problem necessarily on the phone?
No. Suspicious activity can involve an account, another signed-in device or legitimate software behaviour. We use the reported events to define the assessment and explain if the concern needs a different specialist.
Can you check someone else's phone?
Only within the consent requirements for the agreed examination. We don't accept covert monitoring or access requests.
Can you remove malware or restore the phone?
This enquiry is for an assessment. We discuss any remediation requirement separately so that changes to the phone and their effect on evidence are understood.
Start with a short description
Describe the concern, the phone model and when the activity began. Do not include messages, credentials or evidence files in the enquiry.
Request a compromise assessment
Don't submit passwords, private messages or evidence files through the website.
For other investigation questions, explore mobile forensics.
