Every finding verified.
Every step documented.

Belkasoft X is the full-spectrum digital forensics platform trusted by law enforcement and defence agencies worldwide. 1,500+ artifact types. BelkaGPT offline AI. Forensically sound acquisition from first seizure to final verdict.

MOBILECLOUDCOMPUTERDATABASEVEHICLEIoTNETWORKRAMBELKASOFTX

About Belkasoft

Twenty-four years of forensic software. Now built around AI.

Belkasoft was founded in 2002 by a team of digital forensics practitioners and reverse engineers. Twenty-four years on, Belkasoft X is the company’s flagship platform, deployed across 130+ countries by law enforcement agencies, intelligence units, and corporate investigation teams handling some of the most sensitive casework in their jurisdictions.

Belkasoft X covers the full investigation lifecycle in a single platform. Forensically sound acquisition from mobile, computer, cloud, RAM, drone, and car sources. Deep artefact analysis across 1,500+ data types. Court-ready reporting with an unbroken chain of custody from first acquisition to final verdict.

BelkaGPT is the industry’s first fully offline AI assistant built for digital forensics workflows. It runs inside Belkasoft X. It processes evidence on the investigator’s own hardware, with no data egress and no third-party API in the loop. Every answer cites its source artefacts.

Belkasoft X — Connection Graph cross-device analysis
2002Founded
130+Countries
NZAuthorised Reseller

The Evidence Problem

The case environment has changed. The tools have to keep up.

97%
of investigations now involve digital evidence
Forensic Focus Digital Forensics Round-Up, 11 March 2026

The average examiner spends more than 20 hours reviewing evidence per case, while managing six to ten concurrent cases. Devices encrypt on timeout. Data syncs to cloud services the moment a suspect is in custody. Remote wipe commands travel at the speed of a mobile connection. The forensic software you choose determines how much of that data you can access, how fast you can triage it, and whether your findings will survive cross-examination. Volume is no longer the bottleneck on its own; the question is whether the analysis tier keeps up with what acquisition is now putting in front of you.

Device Complexity
Apple’s Secure Enclave and Android’s Titan M make hardware-level access increasingly difficult. Cloud-first architectures mean critical evidence may never exist on the physical device at all. A comprehensive platform must support logical, physical, cloud, and chip-off acquisition, because no single method works on every device.
Caseload Pressure
Investigators are managing six to ten concurrent cases while spending 20+ hours per case on evidence review. Manual correlation across dozens of data sources is no longer operationally sustainable. AI-assisted analysis is not a convenience, it’s an operational requirement.
Court Admissibility
Chain-of-custody gaps, unverified acquisition methodology, and tools that cannot produce hash-verified, auditable output are all grounds for evidence challenge. Every step in the forensic workflow must be documented, repeatable, and defensible under cross-examination.

The Platform

Belkasoft X. From first acquisition to final verdict.

One platform. Every device type. Every acquisition method. Court-ready output at every stage.

Belkasoft X is the end-to-end digital forensics platform built for law enforcement and DFIR professionals. It supports computer, mobile, drone, vehicle, cloud, and RAM forensics within a single case environment, eliminating the tool-switching and workflow fragmentation that introduces risk into complex investigations.

The platform supports every major acquisition method: logical, filesystem, physical, cloud, and JTAG/chip-off. iOS acquisition includes checkm8-based full file system extraction and agent-based methods. Android acquisition covers ADB, agent-based, APK downgrade, and chipset-specific methods for Qualcomm, MediaTek, and Spreadtrum devices. Every extraction step is logged, hash-verified, and exportable in formats accepted by NZ judicial proceedings.

Belkasoft X showing decrypted WhatsApp databases with recovered deleted messages

Encrypted messaging

WhatsApp, Signal & Telegram. Without rooting the device.

Belkasoft X recovers message history, media, and contact data from encrypted messaging apps on Android 12 and 13 without root access. Where the database itself is inaccessible, automated screen capture reconstructs chat logs as searchable, timestamped text.

Belkasoft X cloud acquisition — iCloud, Google, WhatsApp, Instagram, Telegram, Office 365

Cloud acquisition

Evidence that was never stored on the device.

Belkasoft X connects directly to iCloud, Google, WhatsApp, Instagram, Telegram, Office 365, MEGA, and Huawei, including accounts protected by two-factor authentication. Cloud acquisition pulls in the digital footprint the physical examination can't reach on its own.

Belkasoft X RAM forensics — volatile memory acquisition and analysis

Volatile memory

Evidence that only exists in RAM at the moment of capture.

In-private browsing sessions, cleared chat windows, and cloud service session tokens exist only in live memory, never written to disk. Belkasoft X captures and analyses volatile memory from Windows, Linux, and ARM systems before that evidence disappears.

Belkasoft X SQLite viewer showing deleted message records recovered from freelist space

Deleted data recovery

Messages the suspect thought were gone.

Belkasoft X uses its own low-level SQLite engine to recover deleted records from freelists, write-ahead logs, and unallocated space. In documented cases, evidence missed by both Cellebrite and Magnet was found using Belkasoft X’s SQLite viewer.

Belkasoft X device acquisition, iOS agent-based, Android passcode brute-force

Locked devices

iOS and Android acquisition with or without the passcode.

Agent-based acquisition covers iPhone XS through iPhone 14 across iOS 10 through 16. Android passcode brute-force supports MTK and Kirin chipsets. Chip-off, EDL, and JTAG methods extend coverage to devices where software acquisition isn’t possible.

Belkasoft X drone and vehicle forensics — flight routes, GPS tracks, infotainment data

Beyond the phone

Drones, vehicles, and connected devices.

DJI drone flight routes, operator GPS tracks, and onboard logs. Vehicle infotainment data via Berla integration, location history, Bluetooth pairings, call logs, and app activity from the car itself. Evidence sources that most tools don’t reach.

AI-assisted investigation

Ask questions. Surface evidence. Every answer verified.

BelkaGPT is the industry’s first fully offline AI assistant built for digital forensics workflows. Query case evidence in natural language, surface evidence narratives, and verify every answer against source artifacts, all within a secured environment where case data never leaves.

BelkaGPT was built from the ground up for the specific workflows, evidence types, and operational constraints of a digital forensics lab, including the security requirement that case data never leaves the investigative environment. Examiners query case evidence in natural language. BelkaGPT evaluates the most pertinent artifacts per question, maintains full conversational context within an investigation, and directs the examiner to the source artifacts behind every answer.

Unlike general-purpose AI tools that require data to be sent to external servers, BelkaGPT runs entirely within your case environment. There is no cloud dependency, no data egress, and no third-party processing. For agencies handling sensitive casework under NZ privacy legislation and judicial evidence standards, that distinction is not optional, it is a prerequisite. BelkaGPT meets it without compromise.

Contextual Q&A with source verification
Every answer cites its sources. BelkaGPT surfaces the three most relevant artifacts per response with direct links to source evidence, examiner validation is built into the workflow, not an afterthought. Full conversational context maintained within a topic, with up to 10 questions per topic.
Offline facial recognition
Identify persons of interest across large photo libraries directly within the platform. Upload a reference photograph, results grouped by similarity and sorted by relevance. No export to external tools required.
Timestamped transcription
Audio and video files transcribed with timestamps. Jump directly to relevant moments without reviewing full recordings. Transcriptions are searchable by keyword and available for BelkaGPT queries. Multilingual transcription supported.

BelkaGPT reduces triage time and aids with narrative building, its outputs still require examiner validation, which reinforces its role as an assistive rather than autonomous tool in digital investigations.

Practitioner review; Gartner Peer Insights, 2026

BelkaGPT — UFD import in progress
BelkaGPT processing a Cellebrite UFD extraction — no reprocessing required
BelkaGPT — Topics and Q&A interface
BelkaGPT topics view showing conversational evidence querying with source verification
Interoperability
Brings AI to the case files you already have.

If you’ve processed cases in Magnet Axiom or Cellebrite, Belkasoft X reads those files directly. Magnet Axiom .mfdb, Cellebrite UFD/UFDX/UFDR, plus the broader ecosystem below. Open the case, BelkaGPT queries it from there. No reprocessing required.

The sceptical-buyer answer: a forensic team can adopt BelkaGPT without abandoning prior work or existing tooling. The AI lives in the case, not in a parallel platform.

Magnet Axiom (.mfdb)
Cellebrite UFD / UFDX / UFDR
GrayKey
EnCase (.E01)
X-Ways
Oxygen Forensic Detective
Import
Any supported format

BelkaGPT
No reprocessing
Team deployments
BelkaGPT Hub; centralised AI for the whole lab.

In a busy forensics lab, waiting for a single GPU workstation creates bottlenecks that slow every examiner on the team. BelkaGPT Hub eliminates that constraint, AI processing runs on one dedicated server, giving every examiner simultaneous full-capability access without compromise.

  • Single GPU-equipped server supports the whole team
  • No per-workstation GPU requirement
  • Scales with team size without additional hardware
  • Separate Hub licensing available, ask us about options for your agency

Enquire about BelkaGPT Hub →

Training and Certification

Belkasoft training and certification. Delivered in New Zealand.

Custodi is Belkasoft’s Certified Training Provider for New Zealand. Practitioners take official Belkasoft courses through Belkasoft’s own training portal, with local enrolment, GST invoicing, and CPE tracking handled here in NZ. On-site instructor-led delivery available at your facility on request.

Certification Pathways

Belkasoft X — practitioner certification

Full certification course covering acquisition, artifact analysis, and reporting on the Belkasoft X platform. Delivered through Belkasoft's official training portal, with certification issued by Belkasoft on completion.

BelkaGPT AI certification

Six CPE credits covering offline AI-assisted investigation with BelkaGPT. Included free for Belkasoft X licence holders. Covers contextual query over case evidence, source verification, and safe workflow use under judicial evidence standards.

Delivery Model

Computer-based training via Belkasoft's portal

Self-paced official Belkasoft coursework, accessed through Belkasoft's training portal. Practitioners work through modules on their own schedule, with progress and certification tracked by Belkasoft.

On-site instructor-led delivery

For agencies that need instructor-led sessions at their own facility, Custodi delivers on-site training as a Belkasoft-certified provider. Available across New Zealand on request.

Belkasoft

Built for court. Ready for New Zealand.

Pre-sales guidance, formal quotations, and licence configuration specific to your agency or team. Responded to within one business day.

Trusted by NZ Government NZ Police · NZDF · NZ Customs · MFAT · DIA · Parliamentary Service
Authorised Channel Mission Darkness · Belkasoft · Detego · MSAB · OffGrid