For Colorado public defenders, ADC and appointed counsel

The state has a forensic examiner. Your client should too.

Independent digital forensics for the defense in Colorado — including recovery of the damaged devices the state reported as unreadable. Reduced rates for indigent cases.

(720) 222-0110
Confidential and defense-only Documented chain of custody Rush service for court deadlines
The problem

The defense doesn't get the evidence. It gets the state's version of it.

Digital evidence arrives looking objective. It rarely is — someone else chose what to export, how to label it, and which timestamps to trust. These are the six failure points that come up most often in Colorado criminal cases.

“No data recoverable” ends the inquiry

When a phone is water damaged, crushed, burned, or a drive won't spin, the state's lab reports that nothing could be extracted — and everyone treats that as the end of it. It usually isn't. Their examiners image devices; they don't repair them.

You get an export, not the evidence

Cellebrite, GrayKey and AXIOM produce a full acquisition. What reaches you in Crim. P. 16 discovery is a report someone else generated from it, filtered by their search terms and their idea of what matters.

Deleted data is skipped by default

Logical extractions routinely pass over unallocated space, SQLite free pages and WAL journals — frequently the exact location of the deleted message, earlier draft, or removed photo that changes the story.

Timestamps are reported, not converted

UTC versus local time, device timezone changes, DST, and app-specific epoch formats routinely move an event by hours. A timeline built on unconverted timestamps can place your client somewhere they weren't.

Cell-site data is treated as GPS

CSLI shows which tower sector carried a call, not where the phone was standing. Sector coverage shifts with terrain and network load. “Consistent with the area” is not “located at the scene,” and juries hear those as the same sentence.

The tool attributes; nobody proves it

Forensic tools label artifacts by app and account, not by human being. Shared devices, cloud sync from a second phone, and auto-downloaded media all arrive labeled as your client's activity with no attribution analysis behind it.

The solution

A Colorado lab that recovers the data first, then examines it

Most forensic examiners can only work with a device that still powers on. Denver Data Recovery has been a data recovery lab since long before it did forensics — a 97% success rate on media other labs return as unrecoverable. When the state's report says nothing could be extracted, that is frequently a statement about their tooling, not about the device.

Physically failed and damaged media handled in a Class 100 / ISO-5 cleanroom — water, fire, crush, drop, and electrical damage
Chip-off and board-level repair to bring a dead phone back far enough to image it
Formatted, overwritten, and “wiped” drives, SD cards, RAID arrays and NAS volumes
Recovered media is then forensically imaged, hashed, and examined — one lab, one chain of custody, no shipping evidence out of state

Related capabilities: mobile device recovery, hard drive recovery, RAID and NAS recovery, and our general digital forensics services.

What we examine for the defense

Every examination is write-blocked, hashed, and documented for admissibility — whether it ends up in a suppression motion, a report, or on the stand.

Damaged-Device Recovery for Evidence
The service no general forensics shop can offer you
  • Cleanroom recovery from physically failed drives, phones, and flash media
  • Board-level repair and chip-off extraction on devices declared unreadable
  • Recovered data is imaged and hashed for examination, not just handed back as files
Mobile Device Forensics
iPhone, Android, and tablets — including locked devices
  • Full file-system or physical extraction where the device and OS permit
  • Messages, call logs, app data, media, location artifacts, deleted content
  • Independent re-examination of the state's Cellebrite / GrayKey / AXIOM output
Computer & Drive Forensics
Windows, macOS and Linux, imaged with write blockers
  • User activity timelines, browser artifacts, file history, USB device history
  • Analysis of what was actually accessed versus what merely existed on disk
  • Recovery and carving from unallocated space and file-system journals
Cell-Site & Location Analysis
CSLI, tower records, and on-device geolocation artifacts
  • Independent review of the state's mapping and its coverage assumptions
  • Device-side location artifacts (Wi-Fi, GPS caches, app check-ins) for alibi work
  • Plain-language explanation of what those records can and cannot establish
Video, Photo & Audio Authentication
Surveillance, body-worn, dash-cam, and phone media
  • Metadata and timestamp verification, re-encoding and edit detection
  • Frame-level review, stabilization, and defensible enhancement
  • Assessment of authenticity and provenance claims made by the other side
Reports, Declarations & Testimony
Findings your team, the court, and a jury can follow
  • Written reports and affidavits structured against CRE 702 / People v. Shreck
  • Rebuttal analysis of the prosecution expert's methodology and conclusions
  • Availability for motions hearings, depositions, and trial testimony

How an engagement actually runs

Built around indigent-defense realities: funding approval, filing deadlines, and a caseload that doesn't pause for a forensic examination.

1

Free scoping call

Tell us the charges, the devices, what the state produced in discovery, and your next court date. We tell you what is realistically recoverable and what it costs. No charge, no obligation.

2

Written estimate for your funding request

You get an itemized, scoped estimate suitable for an OSPD or ADC ancillary-services request, or a CJD 04-04 motion for court-paid expert fees — written to be read by an administrator or a judge, not by an engineer.

3

Recovery, then forensic imaging

Damaged media goes to the recovery lab first. Working media goes straight to imaging. Either way the evidence is write-blocked, hashed, and logged, and nothing is examined on the original.

4

Analysis and early interim findings

We work the image and call you as soon as we know whether there is something there. You hear it early enough to change strategy — not the week of trial.

5

Report and testimony

A written report in plain English with the technical exhibits behind it, and the examiner who did the work available to explain it under oath.

Built for Colorado indigent-defense caseloads

Defense-only on your matter — we do not take the prosecution's side of a case we've been retained on
Denver lab: evidence stays in Colorado and is never shipped across the country
Itemized estimates written for OSPD / ADC ancillary-services and CJD 04-04 requests
Rush handling when a motions deadline or trial date is driving the schedule
One examiner as your point of contact from intake through testimony
Reduced rates for indigent-defense and court-appointed matters
Consulting-expert-only engagements available if you'd rather not disclose
Confidential and privileged — findings are yours and go nowhere else

Where we work

Denver-based lab serving defenders across the Front Range and the Western Slope. Devices can be delivered, couriered, or shipped, and evidence stays in Colorado.

Denver
Arapahoe
Jefferson
Adams
Boulder
El Paso
Larimer
Weld
Douglas
Pueblo
Mesa
Statewide by arrangement

Questions defense counsel actually ask

The state's lab said the phone was too damaged to extract. Is that the end of it?

Usually not. A forensics lab images devices; it does not repair them. We're a data recovery lab first — Class 100 / ISO-5 cleanroom, board-level repair, chip-off extraction — so a water-damaged, crushed, burned, or dead device that the state wrote off is often still readable. Once recovered, it's imaged and hashed for forensic examination like any other exhibit.

Can expert fees be covered for an indigent client?

Generally yes. OSPD and ADC counsel request ancillary services through their office, and counsel appointed under CJD 04-04 can seek court-paid expert and investigator fees. What makes any of those requests easier to grant is a scoped, itemized written estimate rather than a placeholder number — we provide that at no cost before you file.

The state already extracted the device. Why do I need my own examiner?

Because what you received in discovery is an export the state's examiner generated from a much larger acquisition. An independent review works from the full image: what was left out of that export, the deleted and unallocated data, whether timestamps were correctly converted, and whether the attribution in the report is actually supported by the artifacts underneath it.

How fast can you turn something around?

Scoping call same day in most cases. Imaging typically begins within 24 to 48 hours of receiving the device. Analysis time depends on the device and the scope. If you're against a filing date, lead with the date — we schedule backward from it and will tell you honestly if it can't be met rather than take the case and miss it.

What happens if the examination hurts my client?

You hear it from us privately, and early. The engagement is with the defense, the findings are your work product, and nothing is disclosed by us to anyone. Learning a weakness before the prosecution raises it is often worth the examination by itself.

Will your examiner testify, and how are the reports written?

Yes, and the examiner who performed the work is the one who testifies to it. Reports are written to be defensible under cross and structured against the CRE 702 / People v. Shreck reliability framework Colorado courts apply, with the methodology and verification hashes documented rather than summarized.

Do you work with private criminal defense attorneys too, or only appointed counsel?

Both. This page exists because appointed counsel are the ones most often working without a forensic examiner, but retained defense counsel and civil litigators use the same lab and the same process.

Tell us the case, the device, and the deadline

We'll tell you what's recoverable, what it costs at indigent-defense rates, and whether your date is achievable. The scoping call is free and there's no obligation.

Call (720) 222-0110
info@denverdatarecovery.netDenver lab — serving defenders statewide