Automatic coverage

Coverage that does not wait for a release cycle.

Every forensic tool decodes what its vendor has already implemented. VERA generates its own coverage for anything else, presents it to the examiner as a preview over the real data, and applies nothing until a human has accepted it.

  • Generated automatically, validated by a human
  • Visual editor, no code
  • Applies to versions as well as to applications

The problem

An unsupported application is a dead end, and it is not rare.

A suspect installs a regional social application, or updates a familiar messaging application, and the storage layout changes. The acquisition suite has not implemented it. The data is sitting in the extraction, fully present, and it is unreadable until someone ships a parser for it.

That wait has nothing to do with the case in front of the examiner. It is governed by another company's release planning, and by how commercially interesting the application looks to that company.

Three tiers

Known, unknown, and corrected.

Coverage is produced in three ways, ordered by how much of the examiner's attention each one costs.

  • Known applications, matched on import

    Sources are matched against a library of validated mappings and applied automatically when the seal is opened. The examiner sees a populated viewer, not a task.

  • Unknown sources, generated

    VERA examines the sources, works out what they contain, and generates the mapping itself. What reaches the examiner is a preview over the real data rather than a specification to read.

  • Correction, in a visual editor

    Where the result needs adjusting, the examiner connects boxes in a node editor and keeps full manual control. Writing code is never part of the job.

Mapping previewGenerated · awaiting review
TIMESTAMPSENDERMESSAGE BODY
11/03 21:04Contact 7you around this weekend
11/03 21:06Ownerdepends what for
11/03 21:11Contact 7saturday, same as last time
11/03 21:12Ownerfine. 14th works
Validate and indexCorrectFictitious data

The validation gate

Mappings are generated automatically and validated by a human before use.

That sentence is the whole public description of the mechanism, and it is deliberate. What matters to a buyer is the guarantee rather than the method: no generated mapping is ever applied to a case without an examiner accepting it, and the examiner sees the result over real records before deciding.

For a procurement conversation this is usually the decisive point. The software proposes. Your examiner disposes, and the audit trail records which.

Nothing is applied to a case without a human accepting it first. That is a property of the design, not a setting.

The visual editor

Correction by connecting boxes, not by writing code.

The node editor exists so your examiners keep control, rather than because they are expected to do the work. A source table sits on one side, the fields a viewer expects sit on the other, and transformations in between handle the ordinary cases: reformatting a timestamp, mapping stored values to readable labels, joining two tables, extracting part of a string.

An examiner who has never written a line of code can correct a generated mapping and see the effect on real records immediately.

The VERA mapping editor: a source table on the left connected by curves to the fields of a messaging viewer on the right, with a value transformation between them
The mapping editor, on fictitious data. Interface shown in French; the product ships in 17 languages.

What it changes

Coverage grows with use instead of with release cycles.

A laboratory running VERA is no longer waiting on a third party to decide which applications are worth supporting. The examiner who meets an unfamiliar application today gets a working viewer today, and the validated mapping can then be contributed to a shared library so that other laboratories get it too.

Expertise stops disappearing when an examiner retires or transfers. It becomes something the service keeps.

What is working today, and what is not

Working today

  • Automatic mapping generation for sources that have never been seen.
  • A mandatory human validation gate before anything is applied.
  • A visual node editor for correction and full manual control.
  • Matching against a library of validated mappings at import.
  • Coverage that applies to changed versions, not only to new applications.

In development

  • The full breadth of the viewer catalogue.
  • Automatic relationship mapping and knowledge graphs.
  • Deduplication and linking across seals.

See it running on a real extraction

Thirty minutes, on fictitious data, with time for your questions. If VERA does not fit what your service needs, that is a useful answer too.

Every request is reviewed before access is granted.