Systems, Websites & Platforms
(We call these Services; it's easier than listing them all)
Slack, Jira, Notion, Okta — the tools a business actually runs on. Most of them hold a record of who did what and when, and most of them will hand it over if you ask correctly.
The catch is that they all behave differently. Some give you everything back to the day the account opened. Some give you thirty days and nothing more, no matter who asks or what you pay. A page that told you we collect "any system" would be lying to you, so instead here is how we work out what's actually available.
Every platform has a ceiling
There is a maximum amount of evidence that can legitimately be obtained from any given system. Sometimes that's everything. More often it isn't, and the limit is set by the platform rather than by us — nobody else can get past it either. Three things usually decide where the ceiling sits:
How far back the history goes
This is the one that catches people out. What a platform shows you in the browser and what it will release through its interface are frequently different. Some systems display two years of activity on screen and release thirty days of it. Once a retention window has closed, the data is gone — not withheld, gone — and no provider can recover it.
What licence the account is on
Access to audit logs and administrative history is often tied to the subscription tier. Upgrading is usually not retroactive: buying the higher tier today does not produce the records you didn't have yesterday. If a matter is likely, this is worth knowing early.
What the platform chooses to expose
Some systems publish a complete record. Some publish a partial one. A few publish nothing usable at all, in which case we will say so rather than improvise.
We work the ceiling out for your specific systems before you instruct us, and we tell you what it is. If it's too low to be worth the fee, we'll say that too.
What is collected?
It depends on the system, but broadly:
Messages, posts, comments and the threads they sit in
Files and attachments in their original format
The record of who did what and when — access logs, edit history, permission changes
Membership and account details for the people in scope
For each system in scope we'll tell you which of these are available, and which aren't, before we start.
A note on what we can't reach. We don't collect from another party's accounts or from platforms with no usable interface — that includes most consumer messaging. If evidence sits somewhere your client doesn't control, that's a disclosure application rather than a collection, and we'll say so rather than take the instruction.
What do you need from me?
It varies by platform, but it always starts the same way: somebody with administrative rights on the account approves read-only access, through the platform's own authorisation screen, and can withdraw it whenever they like.
Some systems allow that access to be scoped to particular channels, projects or workspaces. Some don't, and it's all or nothing. We'll tell you which you're dealing with before anyone clicks anything, and the chain of custody records exactly what was accessed.
Where a system has no usable interface, there's sometimes a manual export route the administrator can run themselves. It works, and we'll give you the exact steps — but the collection is then only as good as their execution of it, which is a weaker position if anyone challenges it later.
What do I get back?
Your evidence
In a format you can actually open — usually JSON for structured records, with files and attachments in their original formats alongside. We are in development of a new approach to the disclosures of evidence; so you will receive your evidence, along with a human readable viewer. Contact us for more information.
Chain of custody
What was collected, from where, under what authorisation, and when. Anything that couldn't be reached is recorded in the table, along with why.
Hash list
A signature for every file, so any exhibit can be checked later against what we collected.
Item manifest
A readable CSV of what's in the collection, so you don't have to open a JSON file to answer a simple question.
Our own records of the engagement - who instructed us, what we were asked to do, what we did - is retained for six years. Traces will hold a copy of the ZIP for 90 days once we have confirmed you have downloaded and can access the bundle. You can at any time request the deletion of your collection from Traces.
