Discovery arrived as a Cellebrite UFED export, a GrayKey output, or a Magnet AXIOM report. An independent Cellebrite report review tells you what the production shows, what it leaves out, and what to request next. 19 years in digital forensics, casework in federal and state courts.
The production runs hundreds or thousands of pages of machine-formatted tables, and somewhere in it sits the evidence the other side plans to build on. You need to know what it proves, what it suggests, and what it omits.
Most attorneys read a Cellebrite Reader report front to back and take it at face value. That is how extraction reports get misread. The report is not the phone. It is a rendering of selected data, shaped by the extraction method, the tool version, and the choices of the examiner who produced it.
The review examines the report itself: extraction type, source metadata, tagging decisions, timestamp handling, and gaps. Then it explains, in plain English, what the report supports and where it stops.
A state extraction produced in criminal discovery. An opposing expert's mobile forensics report in a civil matter. A Reader file nobody in the office can confidently interpret.
The biggest mistake in mobile discovery is treating an extraction report as complete. Every one is shaped by decisions made before you ever saw it.
An extraction report reflects three things: what the tool could reach, what the tool could parse, and what the examiner chose to include. Change any one of those and the same phone produces a different report.
Extraction type sets the ceiling. A logical extraction pulls a limited set of live data. A full file system extraction reaches far more, including app databases and many deleted records. If the report does not state the extraction type, that is the first question to raise. The same logic applies to a GrayKey report review: the output reflects what the tool could reach on that device that day.
Examiner selections shape the rest. Reader files in particular often contain only the items the producing examiner tagged. What was not tagged is not in front of you, and nothing on the page announces the omission.
Absence from the report is not absence from the device. A message that does not appear may never have existed, may have been deleted beyond recovery, may live in an app the parser does not support, or may simply not have been tagged for production. Each of those carries different legal weight, and the report alone rarely tells you which one you are looking at.
The review therefore reads the report's metadata as closely as its contents, and ends with a clear statement of scope: what the extraction covered, what it could not, and what a broader request would add.
The same handful of misreadings turns up case after case. Any one of them can change what the evidence means.
A logical extraction with no trace of a message is not proof the message never existed. The report speaks only for the data its extraction method could reach.
Tools store most timestamps in UTC, and reports mix UTC and local-time fields by artifact. Miss the offset and an event moves by hours, sometimes onto the wrong day.
Whether a recovered record is reliable depends on where it came from and how intact it was. Treating every recovered fragment as a complete message overstates the evidence.
A Reader file frequently shows only what the producing examiner tagged. If the other side made the selections, you are reading their highlights, not the record.
Encrypted containers, unsupported apps, and cloud-only data may be absent because the tool could not reach them, and the report will not always say so. Reading that absence as deletion, or as innocence, is a mistake either way.
Tools parse thousands of app formats, and coverage changes between versions. An app unsupported on extraction day produces silence, not a notice. The tool version tells you what that silence means.
The review starts with the report's paper trail: extraction type, tool and version, device identifiers, hash values where present, and acquisition notes. It then works through the produced artifacts, the tagging pattern, the timestamp handling, and any recovered records the other side relies on.
You get a plain-English memo, not a stack of jargon. It states what the report shows, what it does not show, where the producing party's characterization goes beyond the data, and exactly what to request next: a fuller export, the extraction log, the complete UFDR, or a new acquisition.
If the matter is headed to deposition, the memo includes the questions a UFED report expert would put to the producing examiner about method, selections, and the limits of the extraction. If the case later calls for testimony, that work continues through the expert witness service.
Two ways to engage, both quoted in writing before any work begins. The initial consultation is free.
One flat fee for a defined report set. Full engagement details on the Opposing Expert Report Review page.
Billed hourly. The complete fee schedule, including testimony rates, is posted on the rates page.
If the produced report cannot answer your question, forensic acquisition is available at $1,500 per device through the mobile device forensics service.
Remote intake nationwide from Addison, Alabama. Most reviews work entirely from the produced files, so there is nothing to ship.
What to do with a Reader file, what these reports can and cannot tell you, and what a review costs.
Call or write for a free consultation. Describe the production, and you will get a plain assessment of whether a review would help, plus a written quote before anything is billed.
Free initial consultation · Written fee agreement before any work begins · Serving attorneys nationwide from Addison, Alabama
Cellebrite, GrayKey, and Magnet AXIOM are trademarks of their respective owners. The Waldrep Company is an independent consultancy and is not affiliated with or endorsed by these vendors. References are for identification only.
Tell us what the matter involves and we will respond personally. Initial consultations are free, and nothing you send here is a retention.