Ask the phone.
On your own hardware.
A seized handset is often the whole case. Trace Vantage lets an investigator interrogate that device in plain language, recover what was deleted, and read what the owner said, entirely on the force's own hardware. Every answer cites the exact record it came from, and nothing about the device leaves your boundary. This is on-box mobile forensics, operator-initiated and audited, that unlocks the moment a device dump is ingested.
The phone is the case. Cloud-first tools send it off-island.
Modern investigations turn on a device. The messages, the deleted calls, the app data and the locations sit inside one extraction, and the analyst's job is to find the thread that matters inside tens of thousands of records. The problem is not capability, it is where that capability runs. The frontier features of the mainstream tools reach for the cloud, which means a seized device, and the private lives it holds, is processed on someone else's infrastructure, in another jurisdiction, under someone else's terms.
The extraction is enormous
A single dump holds messages, calls, contacts, media, app data and location artefacts in the tens of thousands. Finding the answer by hand is slow, and slow is where lines of enquiry are missed.
The important records were deleted
The message that matters is often the one the owner erased. Recovering it takes deep carving of the device's own databases, not a surface read of what is still visible.
Cloud processing is a sovereignty problem
Sending a seized device's contents to an external AI service hands intimate personal data outside the force boundary. For a small jurisdiction that is a governance risk before it is a technical one.
The court asks how you knew
An answer that cannot point to the record it came from is not disclosable. Interrogating a phone has to leave a trail a court can follow, not a black-box summary.
Once a dump is ingested, the phone becomes searchable, answerable and disclosable.
These capabilities unlock when an operator ingests a Cellebrite extraction. They are initiated by a person, they run on the force's own hardware, and every pass writes to the audit log.
Ingest & parse the extraction
Read Cellebrite UFDR and raw UFED-XML extractions, including encrypted and multi-gigabyte streams, and parse messages, calls, contacts, media, app data and location artefacts into one reviewable case, with pairing-hash verification on the way in.
Deleted-data deep recovery
Carve the device's own databases to recover deleted iMessage, WhatsApp, SMS, calls and contacts that a surface read misses. Self-serve dry-run then commit, so the operator sees what would be recovered before it is written, and every recovery is audited.
Ask the phone
Put a plain-language question to a single device and get an answer built from its records, with every answer citing the exact source it drew on. Runs on a local model, on-box, so the question and the device never touch the cloud.
Transcription & translation
Transcribe voice notes and media audio and translate foreign-language content, all on locally hosted models, so a recording in another language becomes searchable text without leaving the boundary.
OCR over images
Read text out of screenshots and photos so the words inside an image are searchable alongside the rest of the extraction, surfacing the screenshot that would otherwise stay invisible to search.
Crypto-artefact detection
Scan the dump for cryptocurrency wallet addresses and BIP-39 seed phrases, flagging the artefacts that connect a device to hidden value for an analyst to follow up.
Contraband detection
Match media against known-illegal hash sets and by perceptual near-duplicate similarity to surface contraband inside the extraction. Indecent imagery is handled hash-only, suppressed from view, and never routed to any external service.
Behavioural pattern-of-life
Read iOS behavioural artefacts, the device's own usage and interaction records, to reconstruct a pattern of life: when the device was active, and how it was used over time.
Disclosure pack
Produce a signed, hashed disclosure pack with a methodology appendix that names every model and tool version that touched the data, so the way an answer was reached is on the record.
Ask the phone a question. Get an answer that cites its source.
Instead of building a search by hand, an investigator asks the device a plain-language question, "who did this handset speak to about the shipment, and when", and receives an answer assembled from the device's own records. Every answer carries validated, expandable citations back to the exact messages, calls or artefacts it was built from, so the analyst reads the source, not just the summary.
The model runs locally, on the force's own hardware. The question, the device contents and the answer never leave the boundary and are never routed to a cloud AI service. A generated answer is a starting point for a person to verify against the cited records, not a conclusion.
Plain language in
Ask in the words an investigator would use, over one device at a time, without writing a query or knowing the schema.
Cited records out
Every answer points to the exact records behind it, expandable in place, so the claim can be checked against the source.
Runs on-box
A local model does the work inside your environment. Nothing about the device is sent to an external service.
Human verifies
The answer is a lead to confirm against its citations, held to the same standard as any other investigative step.
Device dump in. Cited answers and exhibits out. Nothing leaves.
One path, and the whole of it runs inside the force boundary. An operator ingests the extraction, the device is analysed and made answerable on locally hosted models, and the output is cited answers and signed exhibits that carry their own methodology into a disclosure pack.
The extraction is ingested by a person and analysed on the force's own hardware. The local model answers questions over the device and cites its sources. The output is signed exhibits and a disclosure pack, and at no point does the device, its contents or a question about it leave the boundary.
The questions your DPO and information-assurance team will ask.
Where does the device data go?
Nowhere outside the force boundary. Ingest, recovery, ask-the-phone, transcription, translation, OCR and contraband matching all run on the force's own hardware on locally hosted models. The local model is the default and seized imagery is never routed to a cloud API.
Who starts an analysis?
A person. Every capability here unlocks on an operator ingesting a device dump and is initiated by an investigator, not run automatically against a stream of devices.
How is an answer defensible?
Every ask-the-phone answer cites the exact records behind it, expandable in place, so a human confirms the claim against its source. A generated answer is a lead to verify, not a conclusion.
Is deleted-data recovery auditable?
Yes. Recovery runs as a dry-run the operator reviews before committing, and both the review and the commit are written to the audit log.
How is indecent imagery handled?
Hash-only. Suspected indecent imagery is matched against known hash sets, suppressed from view, and never sent to any external service. The detection is factual and the material is not rendered for browsing.
What does the court receive?
A signed, hashed disclosure pack whose methodology appendix names every model and tool version that touched the underlying data, so the method behind an exhibit is on the record.
Who controls retention?
The extraction, the recovered records and the analysis outputs are held under the force's own retention policy, reviewable and disposable on the force's own schedule.
See Data Sovereignty › for where the data lives, and Governed AI › for the full model-governance and audit picture.
A phone rarely stands alone in a case.
What comes off a device feeds the rest of the governed platform: the same recovered records place a subject, connect a network and reach a court bundle.
Faces & vehicles
Match a face or a vehicle from the device's media against your enrolled gallery and case material.
Where a photo was taken
Work out where a device image was captured, on-box, to place a subject on the ground.
Network & entities
Resolve the numbers, handles and contacts on the device into one entity and map the network.
Vault & court bundles
Promote a recovered message or media item to a signed exhibit with provenance held to disclosure.
Mobile forensics you can put in front of a court, and keep on-island.
Faster answers
A question that once meant hours of manual search returns an answer built from the device's own records, with the sources to confirm it, in minutes.
Sovereign by design
The device, its contents and every question asked of it stay inside the force boundary, on the force's own hardware, never routed to a cloud AI service.
Answerable use
Every answer cites its records, every recovery is audited, and the disclosure pack states the method, so the way you interrogated the phone holds up.
See a seized device answer questions on your own hardware.
Walk through how ingest, deleted-data recovery and ask-the-phone run entirely inside your boundary, and how each answer reaches a disclosure pack a court can follow.