Forensic Software
Every finding verified. Every step documented.
Authorised Reseller of MSAB, Belkasoft, Detego, and xBit, and an Authorised Belkasoft Training Partner. Forensically sound from first seizure to final verdict.
The Reality
The case environment has changed. The tools have to keep up.
A single phone now stores more data than a whole seizure used to. The forensic platform you choose decides what evidence you can access, how fast you can triage, and whether your data and process will hold up in court.
of investigations now involve digital evidence.
SOURCE: FORENSIC FOCUS DIGITAL FORENSICS ROUND-UP, MARCH 2026
Hardware-level access is now the gating constraint.
Apple's Secure Enclave and Google's Titan M2 make hardware-level access increasingly difficult. Cloud-first design means critical evidence may never sit on the device. A platform must support logical, physical, cloud, and chip-off acquisition, because no single method works on every device.
Six to ten concurrent cases is the new baseline.
Investigators typically work on multiple concurrent cases, each demanding tens of hours of evidence extraction and review. Manual correlation across dozens of data sources is no longer operationally feasible. AI-assisted digital forensic analysis tools are not a convenience, they are essential.
Every step must be documented, repeatable, and defensible.
Chain-of-custody gaps, unverified acquisition methodology, and tools that cannot produce hash-verified, auditable output will increase the risk that your evidence will be challenged in court. Every step in the forensic workflow must be documented, repeatable, and defensible under cross-examination.
The forensic platform decides what you can extract, what evidence stands up in court, and whether the case becomes a defence of your methodology instead of an argument on the facts.
Four solutions partners
Meet our four Forensic Software Partners
Solutions matched to your investigation environment and your unique needs.
Mobile-first, every device.
MSAB XRY · XAMN · Frontline · XEC
Mobile device extraction across every category of smartphone, tablet, drone, and legacy handset. Trusted by law enforcement in over 100 countries. Custodi is MSAB's Partner Reseller for New Zealand.
- Every mobile device category
- Court-ready extraction and analysis
- Trusted by 100+ countries
- Frontline field kits included
AI analysis, on-device.
Belkasoft X · Belkasoft T · BelkaGPT
1,500+ artifact types parsed across mobile, computer, cloud, and vehicle. BelkaGPT runs the AI locally, so case evidence never leaves the workstation.
- Lab acquisition and analysis
- 1,500+ artifact types parsed
- BelkaGPT (on-device AI)
- Court-ready reporting
Triage at the scene, not the lab.
Ballistic Imager · Field Triage · Analyse AI+ · Fusion
Field Triage runs at seizure, in the hands of non-specialist officers. Analyse AI+ carries the same evidence into the lab through Fusion.
- Rapid field imaging
- AI-assisted field triage
- Analyse AI+ for lab work
- Fusion case collaboration
Chain of custody, always intact.
Case data · Audit trail · APEx · Licence tracking
The audit-trail layer beneath the forensic stack. Case and evidence tracking, custody log, plus APEx reference for JTAG/ISP work and licence management.
- Digital case management
- Chain-of-custody audit trail
- APEx (JTAG/ISP/chip-off)
- Licence and asset tracking
MSAB
Mobile-device depth, from lab to frontline.
Four software families across the mobile-forensics lifecycle: XRY for extraction, XAMN for analysis, UNIFY for multi-investigator collaboration, Frontline for first-responder deployment. All writing to one shared .XRY case format. Depth over breadth, four decades in.
Every mobile device. 43,400+ profiles.
The extraction engine. Logical, physical, cloud, and Photon screen-capture across smartphones, tablets, drones, and legacy handsets. 4,300+ application versions parsed. Chinese chipset coverage (Mediatek, Spreadtrum, CoolSand, Infineon) is a differentiator for organised-crime and counter-narcotics work.
- Logical, physical, and cloud extraction
- 43,400+ device profiles supported
- 4,300+ application versions parsed
- Chinese chipset coverage
The extraction engine at the heart of every MSAB deployment, from lab bench to first responder.
Read more on the MSAB pageCourt-defensible reports. Every time.
Search, filter, visualise, and decode extracted evidence. Presents recovered mobile data as visual timelines, chat reconstructions, and geolocation maps. Every report exports in a form that stands up to disclosure and cross-examination.
- Visual timelines and chat reconstructions
- Geolocation mapping
- Court-defensible export formats
- Cross-examination ready
Where extractions become evidence a court will accept and a jury can follow.
Read more on the MSAB pageOne workspace. Every source.
UNIFY Collaborate brings multi-investigator case work together across specialists, investigators, and reviewers. Ingests Cellebrite UFDR and GrayKey extractions alongside native .XRY, so mixed-vendor environments consolidate under one case-management layer without abandoning existing tools.
- Multi-investigator real-time collaboration
- Ingests Cellebrite UFDR and GrayKey
- Consolidates mixed-vendor case work
- Centralised evidence storage
For agencies running mixed toolchains. Consolidate case management, keep your extraction stack.
Read more on the MSAB pageXRY in the hands of first responders.
Pro Express, Kiosk, Tablet, and Express package the XRY engine into turnkey deployments. Field officers with minimal training run consistent, ISO 17025-compliant extractions at the point of seizure. Reduces lab backlogs and accelerates suspect processing.
- Pro Express, Kiosk, Tablet, Express
- Minimal training required
- ISO 17025 compliant
- Reduces lab backlogs
Advanced extractions, built for the frontline. Same evidence standard as the lab.
Read more on the MSAB pageBelkasoft + BelkaGPT
Lab analysis depth, with on-device AI.
The forensic examination platform of choice for digital forensics labs in 130+ countries. Full-spectrum acquisition across mobile, computer, cloud, drone, vehicle, and RAM. Deep artifact analysis across 1,500+ data types. BelkaGPT querying without case data leaving the environment.
From first acquisition to final verdict.
The laboratory-depth platform that anchors a forensic case. Mobile, computer, cloud, drone, vehicle, and RAM acquisition with deep artifact analysis across 1,500+ data types.
- 1,500+ artifact types parsed
- iOS checkm8 + Android multi-method
- Cloud, drone, vehicle, RAM data
- Court-ready NZ-accepted formats
Cloud acquisition does not replace the physical examination. It completes it.
Read more on the Belkasoft pageAn AI assistant that never leaves your machine.
BelkaGPT runs entirely within the case environment. No cloud egress. No third-party processing. For agencies operating under NZ privacy legislation and judicial evidence standards, that distinction is a prerequisite, not an option.
- Offline, no cloud, no telemetry
- Sovereign, evidence stays in the agency
- Defensible, auditable, reproducible queries
- Natural-language case queries
An offline AI co-pilot that surfaces evidence through natural-language queries, with cited source artifacts for every answer.
Read more on the Belkasoft pageFirst-responder triage from the same vendor.
The free, field-side companion to Belkasoft X. Designed for first responders making a rapid "is there evidence here" call before a device leaves the scene. T runs from a USB drive on a Windows machine at the scene and produces an export the lab examiner ingests directly into Belkasoft X, no installation, no reprocessing.
- Free Belkasoft tool, no licence required
- Runs from a USB drive on Windows machines at the scene
- Same 1,500+ artifact detection engine as Belkasoft X
- Direct lab handoff, no reprocessing
Same vendor. Same artifact engine. No format conversion between field and lab.
Read more on the Belkasoft pageAuthorised Belkasoft Training Partner for New Zealand and the Pacific.
Custodi is the sole Belkasoft-certified training provider in the Pacific. Training is delivered in New Zealand by a Belkasoft Certified Instructor.
- Belkasoft Certified Instructor
- Full training catalogue available
- Delivered in New Zealand
- On-site training is available for agencies that cannot travel
Tailored courses for organisations that require specific toolset focus within the Belkasoft suite.
Read more on the Belkasoft pageDetego
Field forensics. Built for the seizure point.
The window between device seizure and evidence loss is measured in seconds, not hours. Detego is the field platform that closes that window. Forensic imaging at industry-leading speed, AI-assisted triage that any trained operator can run, and lab-grade analysis that maintains chain of custody from seizure to the courtroom.
The world's fastest forensic imaging tool.
Patented imaging architecture that holds the current world record for forensic imaging speed: 1TB in 4 minutes 34 seconds. Hash-verified, court-defensible output from first acquisition.
- Current world record: 1TB in 4 minutes 34 seconds
- 4x faster than industry average
- Hash-verified, court-defensible output
- 30-minute training overhead
Speed without courtroom admissibility is not a forensic tool. It is a liability.
Read more on the Detego pageIntelligence from the device. Without moving it.
Search, keyword-match, and alert on a device in the field. Identify whether relevant content is present before the device is transported, without waiting for laboratory acquisition. Designed for non-technical personnel.
- Real-time keyword search with text indexer
- Hash matching against known files
- Patented Match / Review / Clear alerts
- Read-only acquisition (forensically sound)
Field Triage highlights what to prioritise.
Read more on the Detego pageAI-powered analysis. Included as standard.
AI-powered analytics across all forensic acquisitions on the Detego platform. Face recognition, multi-language OCR, password decryption, and steganography detection, included at no additional cost.
- Face recognition
- Multi-language OCR (103 languages)
- Password decryption (300+ formats)
- Steganography detection
Every Analyse AI+ output carries an unbroken chain of custody from device seizure through to courtroom presentation.
Read more on the Detego pageConnect the dots across every device, every case, every suspect.
Investigations rarely involve a single device. Fusion is the link analysis layer that assembles fragments from multiple phones, laptops, USB drives, and accounts into a complete operational picture.
- Advanced link analysis
- GPS coordinate matching
- Hash matching across exhibits
- Multi-case intelligence
Organised crime and serious fraud investigations involve dozens of devices and hundreds of exhibits. Fusion is the capability that makes scale manageable.
Read more on the Detego pagexBit
The audit-trail layer underneath your stack.
xBit is the management layer that sits beneath whichever forensic tools you use. Case data, chain-of-custody log, lab licence and asset management, plus APEx, a chip-level reference library for JTAG, ISP, and chip-off recovery. Built for digital forensics teams that need a single defensible record of every case they handle.
One defensible record of every case.
The central record for every case your unit handles. Devices logged in, examinations performed, evidence catalogued, exhibits exported, custody transfers recorded, all timestamped, all auditable, all available as a single export at disclosure time.
- Case and device intake logging
- Examination history tracking
- Custody transfer records
- Disclosure-ready exports
When a defence lawyer asks how the chain of custody was maintained, xBit is the answer.
A reference library for chip-level recovery.
When a phone has no working extraction path, the case can still proceed via JTAG, ISP, or chip-off recovery. APEx is the reference library that supports that work, with proven diagrams, board pinouts, recovery procedures, and tested techniques.
- JTAG pinout reference
- ISP recovery procedures
- Chip-off technique library
- Board-level documentation
When a phone has no working extraction path, the case still proceeds.
Track what your lab actually owns and runs.
Forensic labs accumulate licences, hardware, write-blockers, USB dongles, and software seats over years. xBit gives the lab manager a single view of what is licensed, what is current, what is deployed, and what is sitting on a shelf.
- Licence inventory and renewal tracking
- Hardware and dongle assignment
- Capability and version coverage
- Lab-wide asset visibility
Lab capability is not what you have on paper. It is what you can prove is licensed, current, and deployed.
The Workflow
Six steps from seizure to courtroom.
A digital forensics case moves through the same six phases regardless of jurisdiction or agency. Here’s how Belkasoft, Detego, and xBit map onto each phase.
Seizure & imaging
Detego Ballistic Imager
Field triage
Detego Field Triage
Belkasoft T
Lab acquisition
Belkasoft X
Deep analysis
Belkasoft X
BelkaGPT
Detego Analyse AI+
Case management
xBit Case Manager
Detego Fusion
Courtroom reporting
Belkasoft X
xBit audit trail
Acquire. Analyse. Report.
Belkasoft, Detego, and xBit are three different toolsets for three different jobs. We help you spec the right platform and get you started with trial versions.
