Analysis workspace

Views built for the work, not for the storage format.

A database browser shows an examiner a table. A workspace shows them a conversation, a gallery, a call log, a map. The difference is the whole distance between a tool and something a laboratory will actually use every day.

  • Fourteen specialised views, plus a timeline and a map
  • Source path visible on every record
  • Recovered records marked as recovered

Views

Each evidence type gets a view designed for it.

Structured records appear in views built for the task. Messaging reads as a threaded conversation with attachments in place. Media appears as a gallery that can be searched by content. Calls, contacts, notes, accounts, applications and system traces each have their own view. The examiner moves between them without leaving the case, and the scope of a search follows them from view to view.

Timeline and Map assemble records that have already been indexed. They do not invent a chronology the sources did not contain.

  • Messages

    Threaded conversations, with timestamps, direction and attachments in place.

  • Media

    Photos, video and other files, searchable by what they contain.

  • Calls

    Incoming, outgoing and missed calls, with duration where the source holds it.

  • Contacts

    The address book, reconstructed from whatever produced it.

  • Location

    Position records, readable as a list and placed on the map.

  • Notes

    Notes and other stored text, searchable by keyword and by meaning.

  • Web

    Browsing history and visited pages.

  • Downloads

    Files the device saved from elsewhere.

  • Accounts

    Accounts present on the device.

  • Device

    Identity and configuration of the seized device itself.

  • Applications

    Applications installed on the device.

  • App activity

    How those applications were used.

  • Networks & proximity

    Network connections and nearby devices.

  • System log

    System events recorded on the device.

  • Timeline

    Every indexed record that carries a timestamp, in one chronological view.

  • Map

    Every indexed record that carries coordinates, placed on a map.

Provenance

Every record shows where it came from.

Provenance is carried in the record itself rather than reconstructed when something is displayed. A citation resolves to its source row even after the mapping that produced it has been revised, which matters the first time a mapping is corrected halfway through a case.

Recovered records carry their recovery status alongside their provenance. A carved row is never presented as a live one, and an examiner never has to guess which they are looking at.

Evidence integrity

The extraction is never written to.

Every source is opened read-only. Nothing VERA does modifies the files that arrived from the acquisition tool.

That is a property of the design, not a setting. It is the reason an examiner can defend the chain from extraction to report.

What is working today, and what is not

Working today

  • Fourteen specialised views: messages, media, calls, contacts, location, notes, web history, downloads, accounts, device, applications, application activity, networks and system events.
  • Timeline and map views over already-indexed records.
  • Search available inside each view.
  • Provenance and recovery status carried on every record.
  • Read-only evidence access.

In development

  • Automatic timeline reconstruction across sources.
  • The full breadth of export and report generation.

See it running on a real extraction

Usually thirty minutes on a video call, on fictitious data. On site if you need it, or a conversation first. If VERA does not fit what your service needs, that is a useful answer too.

Every request is reviewed before access is granted.