Electronic Discovery

eDiscovery Services

Defensible collection. Forensic precision. Court-ready production.

eDiscovery is the forensic identification, preservation, collection, processing, review and production of electronically stored information for litigation or regulatory proceedings. Sherlock Forensics delivers EDRM-aligned eDiscovery services in Vancouver and across British Columbia with full chain-of-custody documentation and court-admissible methodology.

When litigation demands the disclosure of digital evidence, defensibility is non-negotiable. Our certified examiners manage the entire eDiscovery lifecycle - from legal hold notifications through final production - ensuring every byte is accounted for and every process is reproducible.

Capabilities

End-to-End eDiscovery Workflow

01 - Identification

Data Mapping & Identification

We map all custodians and data sources - email, cloud, endpoints, collaboration platforms - to build a defensible scope before a single byte is collected.

02 - Preservation

Legal Hold & Preservation

Automated legal hold notifications and in-place preservation across M365, Google Workspace and on-premises infrastructure. Documented spoliation avoidance.

03 - Collection

Forensic Collection

SHA-256 verified collection from endpoints, servers, mobile devices and cloud platforms. Every acquisition logged with examiner attestation and timestamp.

04 - Processing

Processing & Culling

De-duplication, date filtering, keyword culling and file-type exclusion to reduce review volume while maintaining defensibility. NIST NSRL hash filtering for known system files.

05 - Review

Review & Analysis

Technology-assisted review (TAR), concept clustering, email threading and near-duplicate detection. We reduce review costs without sacrificing recall.

06 - Production

Production & Testimony

Productions in any format - TIFF, PDF, native - with load files, Bates numbering and privilege logs. Expert testimony on methodology and completeness.

Supported Sources

Data Sources We Collect From

Source Category Platforms Collection Method
Email Systems Exchange, M365, Gmail, IMAP API / Forensic Image
Cloud Storage OneDrive, SharePoint, Google Drive, Dropbox API / Direct Export
Collaboration Slack, Microsoft Teams, Zoom API / Compliance Export
Endpoints Windows, macOS, Linux Forensic Imaging (E01/AFF4)
Mobile Devices iOS, Android Logical / Physical Extraction
Databases SQL Server, PostgreSQL, Oracle Targeted Query Export

Frequently Asked Questions

eDiscovery FAQs

What is eDiscovery and when is it required?
eDiscovery (electronic discovery) is the process of identifying, collecting, processing, reviewing and producing electronically stored information (ESI) in legal proceedings. It is required during civil litigation, regulatory investigations, internal investigations and any matter where digital evidence must be disclosed under court rules such as the BC Supreme Court Civil Rules or the Federal Rules of Civil Procedure.
How does Sherlock Forensics maintain chain of custody during eDiscovery?
We follow the EDRM (Electronic Discovery Reference Model) framework with forensic-grade chain-of-custody documentation at every stage. Every collection is hash-verified using SHA-256, every transfer is logged and every custodian interaction is documented. Our processes meet the evidentiary standards of BC courts and federal tribunals.
What types of data can be collected for eDiscovery?
We collect ESI from email systems (Exchange, Gmail, M365), cloud storage (OneDrive, SharePoint, Google Drive), endpoints (laptops, desktops), mobile devices, databases, collaboration platforms (Slack, Teams) and legacy storage media. We handle structured and unstructured data across all common file formats.
How long does the eDiscovery process typically take?
Timeline depends on data volume and complexity. A targeted collection from a single custodian may take 2-5 business days. Large-scale matters involving multiple custodians, terabytes of data and complex review workflows may span several weeks. We provide project timelines during the initial scoping consultation.
Does Sherlock Forensics provide expert testimony for eDiscovery matters?
Yes. Our certified examiners have provided expert testimony in BC Supreme Court, Federal Court of Canada and various tribunals. We can testify to the methodology, integrity and completeness of the eDiscovery process, including collection procedures, processing decisions and chain-of-custody documentation.

Authority Resources

Standards & References

Industry Standards

Our eDiscovery methodology aligns with recognized frameworks and judicial expectations.

Related Services

eDiscovery often intersects with our other forensic capabilities.

Certifications

Our examiners hold credentials recognized by courts and counsel across Canada.

CISSP

Get Started

Ready to streamline your eDiscovery?

Order eDiscovery support online - self-service checkout.

Order Online

Start Your eDiscovery Matter

Whether you are responding to a litigation hold, preparing for regulatory review or conducting an internal investigation, our team is ready to scope and execute your eDiscovery project.

Call 604.229.1994
Phone
604.229.1994
Burnaby Office
Burnaby, BC, Canada
Coquitlam Office
Coquitlam, BC, Canada
Availability
Urgent matters accommodated - call to discuss timelines