Corporate Services

Defensible internal
investigations.

Forensic investigations engaged directly by HR, in-house counsel and corporate security — no law-firm intermediary required. Employee misconduct, IP theft, departing-employee data exfiltration and forensic readiness. Reports written for arbitration, internal action and litigation if it comes.

HR-ready
Report format
Direct
No law firm needed
Defensible
Survives arbitration
Corporate IntakePrivileged
Name
01 / Employee

Employee misconduct investigations.

When an internal complaint, policy violation, or HR escalation requires a forensic answer — what was on the device, who said what to whom and when. Quietly, before the rumor mill gets there.

  • Misconduct & harassment — chat, email, mobile communications between named parties
  • Policy violation — acceptable-use, confidentiality and conflict-of-interest review
  • Internal fraud — expense, procurement, payroll, time-tracking, vendor kickback patterns
  • Whistleblower corroboration — independent forensic validation of complainant claims
  • Workplace investigations — bullying, threats, intimidation, hostile-environment evidence
Typical engagement
Interview across a desk — employee misconduct investigation
Phone and laptop with code on screen — IP theft and trade-secret tracing
02 / IP Theft

IP theft & trade-secret investigations.

Suspected exfiltration of source code, customer lists, pricing models, design specs, or trade secrets. We trace the data path — USB, cloud, print, mobile, email, screenshot, peripheral — and produce a forensic timeline that holds up in injunction motions and trade-secret litigation.

  • USB & removable-media tracing — registry, USNJrnl, link files, jump lists, shellbags
  • Cloud exfiltration — personal Dropbox / iCloud / Google Drive / OneDrive uploads
  • Email exfiltration — forwarding rules, personal-email sends, attachment review
  • Print & peripheral output — spool files, printer logs, peripheral connect history
  • Anti-forensics detection — wipers, CCleaner, timestomping, secure-delete attempts
  • Source-code attribution — clone detection across the suspected destination
Typical engagement
03 / Departing Employee

Departing-employee forensics.

Standard exit forensics when an employee resigns under suspicious timing, joins a competitor, or has access to sensitive data. Run before the device is reimaged. A clean exit report is just as valuable as a flagged one — it protects everyone.

  • Exit-checklist forensic sweep — laptop, phone, M365 / GWS account, cloud-storage attachments
  • USB & cloud transfer detection — what left, when, where, how much
  • Customer / contact list extraction analysis — CRM exports, address-book copies
  • Email & chat archive review — final 30 / 60 / 90 day window
  • Image preservation — forensic image kept for the litigation-hold period
  • Plain-language report — for HR + counsel, signed and bates-stampable
Typical engagement
Employee packing belongings into a box — departing-employee forensics
Consultant reviewing documents — forensic readiness assessment
04 / Readiness

Forensic readiness assessments.

A one-time engagement that maps your environment for an incident before one happens. We assess endpoint logging, audit-log retention, identity logging, IR playbooks and chain-of-custody templates — then deliver a written assessment and 30/60/90 remediation roadmap.

  • Logging & retention audit — endpoint, identity, cloud, email, network
  • Custodial control review — laptops, phones, removable media, BYOD policy
  • IR playbook gap analysis — what you have vs. what you'll need on day one of an incident
  • Evidence preservation policy — drafting / refinement, with templated forms
  • Tabletop exercise — optional half-day scenario walk-through with execs
  • Insurer-aligned — readiness reports recognized by major cyber-insurance carriers
Typical engagement
Who engages us

The buyers we
work with most.

Direct engagement — no law-firm intermediary required, though we can route through counsel when you prefer.

In-house counsel

General Counsel and litigation managers who want a forensic partner without going through outside counsel. Findings are privileged; reports written to your standard.

HR investigations

HR investigators and Employee Relations handling internal complaints, policy violations, or pre-termination forensics. Reports formatted for HR review boards and arbitration.

Corporate security & CISO

Security teams running insider-threat programs. We supplement your EDR/DLP with deep forensic investigation when an alert needs to become a defensible finding.

Compliance & risk

Compliance officers and risk teams running PIPEDA, GDPR, SOX, or HIPAA matters. We provide regulator-facing findings and breach-scope determinations.

Mid-market businesses

Companies without in-house forensic capability. A departing senior employee, a suspected fraud, a vendor anomaly — we handle the investigation end-to-end.

M&A diligence teams

Acquirers conducting forensic due diligence — looking for hidden data theft, IP encumbrance, undisclosed breach history, or insider activity at the target.

Why Data Rescue Labs

HR sales cycles beat law-firm sales cycles.

Most forensic firms only take engagements through outside counsel. That works for trial-bound matters — but it adds extra time and cost for everything else.

We engage directly with HR, in-house counsel and corporate security. Faster start, lower friction, same forensic rigor. Reports are written to the standard counsel would expect if the matter escalates, so escalation costs nothing extra.

If the case ends up in court, we can testify. If it doesn't, we still produce work product that protects you — quietly.

Open a case →

Direct engagement

No law firm required to start. HR, in-house counsel and corporate security can engage us directly under retainer or per-case.

Privileged when needed

If escalation looks likely, we route work product through your outside counsel. Privilege protected from intake forward.

HR-format reports

Findings written for HR review boards and arbitration panels, not just judges. Plain language + technical appendix for if it goes further.

Fast turnaround

Departing-employee forensics: 3–10 days. Misconduct investigations: 5–30. We don't slow down because HR doesn't bill in 6-minute increments.

Corporate FAQ

Internal investigations, FAQ.

What HR, in-house counsel and CISOs ask before commissioning a corporate forensic engagement in Canada.

Can my company investigate an employee's work laptop forensically?

Generally yes, with two conditions: the company owns the device and the AUP / employment agreement permits monitoring or investigation. Most well-drafted Canadian AUPs include this language; if yours doesn't, we recommend updating it before any investigation begins.

For BYOD or personal devices, consent or court order is required. We always recommend a quick consult with employment counsel before imaging if there's any ambiguity.

What is departing-employee forensics?

Preserving evidence of what an employee did in their last 30–90 days before resignation. Specifically: USB devices connected, cloud-upload destinations, email attachments sent, recent file access (especially on confidential project folders), print jobs, browser history and Slack / Teams DMs.

We image laptops and phones before the device is wiped or re-provisioned. The image lives in cold storage for 90 days minimum, available if a non-compete or trade-secret issue surfaces post-departure.

How do you investigate suspected IP theft?

Multi-source: endpoint forensics (shellbags, recent files, USB history, prefetch), email and Slack search (attachments, forwards to personal accounts), cloud audit logs (Google Drive, OneDrive, Dropbox, GitHub) for download or sharing events, print and badge logs for physical egress and network logs for unusual upload volume.

The story is rarely in one source. We assemble a timeline across all of them and produce a defensible report counsel can use for injunctive relief.

Can a forensic exam be conducted without alerting the employee?

Yes. Covert imaging during off-hours (laptop left on the desk overnight, imaged in our van or off-site lab, returned before morning). Cloud-side investigation (M365 / Google Workspace audit log review) requires no endpoint access at all.

For active employees still suspected of ongoing theft, we can install enterprise endpoint monitoring with legal authorization, time-limited and scoped.

What is forensic readiness?

Infrastructure and policy designed so future investigations are feasible, defensible and fast. Concretely: enable M365 UAL retention extension, configure endpoint EDR for forensic-quality artifact preservation, document the chain-of-custody intake process for IT, establish a covert-imaging vendor relationship (us, or someone else), review IT-access policies, train HR / IT on what to preserve and what to avoid.

A readiness assessment is engaged as a one-time SOW and pays for itself the first time the lab uses what we set up.

Are HR forensic investigations subject to privacy law?

Yes — PIPEDA federally, plus PIPA (BC, AB), the Quebec Act and PHIPA / health-sector laws where applicable. The general rule: investigations must be proportionate, scope-limited and not used for general surveillance.

We help structure investigations to meet the legal threshold. Sealed reports, named-purpose access, destruction-on-completion. Our reports anticipate the privacy-review questions before they're asked.