Analysis workspace
Views built for the work, not for the storage format.
A database browser shows an examiner a table. A workspace shows them a conversation, a gallery, a call log, a map. The difference is the whole distance between a tool and something a laboratory will actually use every day.
- Fourteen specialised views, plus a timeline and a map
- Source path visible on every record
- Recovered records marked as recovered
Views
Each evidence type gets a view designed for it.
Structured records appear in views built for the task. Messaging reads as a threaded conversation with attachments in place. Media appears as a gallery that can be searched by content. Calls, contacts, notes, accounts, applications and system traces each have their own view. The examiner moves between them without leaving the case, and the scope of a search follows them from view to view.
Timeline and Map assemble records that have already been indexed. They do not invent a chronology the sources did not contain.
-
Messages
Threaded conversations, with timestamps, direction and attachments in place.
-
Media
Photos, video and other files, searchable by what they contain.
-
Calls
Incoming, outgoing and missed calls, with duration where the source holds it.
-
Contacts
The address book, reconstructed from whatever produced it.
-
Location
Position records, readable as a list and placed on the map.
-
Notes
Notes and other stored text, searchable by keyword and by meaning.
-
Web
Browsing history and visited pages.
-
Downloads
Files the device saved from elsewhere.
-
Accounts
Accounts present on the device.
-
Device
Identity and configuration of the seized device itself.
-
Applications
Applications installed on the device.
-
App activity
How those applications were used.
-
Networks & proximity
Network connections and nearby devices.
-
System log
System events recorded on the device.
-
Timeline
Every indexed record that carries a timestamp, in one chronological view.
-
Map
Every indexed record that carries coordinates, placed on a map.
Provenance
Every record shows where it came from.
Provenance is carried in the record itself rather than reconstructed when something is displayed. A citation resolves to its source row even after the mapping that produced it has been revised, which matters the first time a mapping is corrected halfway through a case.
Recovered records carry their recovery status alongside their provenance. A carved row is never presented as a live one, and an examiner never has to guess which they are looking at.
Evidence integrity
The extraction is never written to.
Every source is opened read-only. Nothing VERA does modifies the files that arrived from the acquisition tool.
That is a property of the design, not a setting. It is the reason an examiner can defend the chain from extraction to report.
What is working today, and what is not
Working today
- Fourteen specialised views: messages, media, calls, contacts, location, notes, web history, downloads, accounts, device, applications, application activity, networks and system events.
- Timeline and map views over already-indexed records.
- Search available inside each view.
- Provenance and recovery status carried on every record.
- Read-only evidence access.
In development
- Automatic timeline reconstruction across sources.
- The full breadth of export and report generation.
See it running on a real extraction
Usually thirty minutes on a video call, on fictitious data. On site if you need it, or a conversation first. If VERA does not fit what your service needs, that is a useful answer too.
Every request is reviewed before access is granted.