NODE · LON-01|LONDON --:--:--
DAC | Digital Asset Claims
Digital Asset Claims · How It Works

How a Case Runs from Intake to Evidence Report

A plain-language walkthrough of the case journey, from secure intake and evidence collection to final handover of the structured evidence report.

01 · Module

Intake

Material is received through secure channels with no system access or authority sought.

02 · Module

Analysis

Blockchain, network, OSINT and infrastructure evidence is examined and logged.

03 · Module

Corroboration

Findings are tested against a second source before being graded.

04 · Module

Report

The final pack includes findings, exhibits, source citations and documented gaps.

How It Works

Digital Asset Claims How It Works

From a fragmented trail to a structured evidence report.

Every engagement moves through the same ten investigative stages, in the same order, from first contact to final report.

Stages
10
Custody required
None
Guaranteed outcome
None
Status notes
Per stage
Case OpenedEvidence IntakeWallet AnalysisEvidence ReportCase Closure
01 / 05
Case Opened
Stage 01 · intake
Stage 01 of 10

Ten Investigation Stages, Step By Step

01 · Case Intake

Scope, lawful basis and available identifiers are agreed in writing before any research begins. No account credentials are ever requested or collected.

Stage output
Written scope letter, agreed identifiers and a case reference.

Case Stages

Ten stages, end-to-end — every one documented.

From case intake to evidential reporting.

Stage 01
01

Case Intake

Scope, lawful basis and available identifiers are agreed in writing before any research begins. No account credentials are ever requested or collected.

Stage 02
02

Initial Evidence Review

Client-supplied material — transaction hashes, wallet addresses, correspondence, screenshots — is logged and assessed for what it can plausibly support.

Stage 03
03

Data Normalisation

Raw records from different sources and formats are converted into a single structured dataset so blockchain, OSINT and infrastructure data can be analysed together.

Stage 04
04

Blockchain Reconstruction

Public ledger data is pulled into a timeline of transactions, tracing hops across wallets, bridges and swap protocols where funds moved between chains.

Stage 05
05

Wallet Relationship Analysis

Addresses are clustered and mapped against counterparties, exchange deposit addresses and known typologies to surface plausible ownership and control patterns.

Stage 06
06

OSINT Research

Lawfully available public records, filings, domain history and public activity are researched to corroborate or contradict findings from the on-chain analysis.

Stage 07
07

Infrastructure Intelligence

Lawfully obtained network and hosting indicators are reviewed to assess whether separate online activity shares common infrastructure.

Stage 08
08

AI-Assisted Correlation

Automated analysis surfaces patterns and cross-references across large datasets; every output is reviewed by an analyst before it is treated as a candidate finding.

Stage 09
09

Evidence Verification

Each candidate finding is tested against an independent source for provenance, chronology and consistency, and graded according to how strongly it is supported.

Stage 10
10

Evidential Reporting

A structured report is compiled: timelines, sourced findings, methodology, evidence grades and a written record of what remains unresolved.

Investigation · Floating Stages
depth · 3d composition
Source Indexing
Primary
Source Indexing
Verification Bench
Structured Evidence
Live Operations
Handover
z-stack · 5 panels
live render
Section · 01

What you receive at the end of a case

Each case closes with one structured evidence report containing timelines, wallet relationships, source references and a written record of unresolved gaps.

01 · Module

Findings narrative

A written narrative sets out what the evidence shows and does not show.

02 · Module

Exhibit index

A numbered index lists every exhibit referenced in the report.

03 · Module

Evidence grading

Each finding is graded from verified to insufficient evidence.

04 · Module

Documented gaps

Unanswered questions are recorded rather than glossed over.

Section · 01

How a case unfolds from open to close

A general shape is published so clients can see what comes next, what is needed from them and roughly when the evidence report is expected to land.

01 · Module

Open

Scope sign-off and a secure channel are issued.

02 · Module

Collection

Evidence collection and technical analysis begin across agreed domains.

03 · Module

Corroboration

Findings are tested, graded and drafted into the report.

04 · Module

Close

The report is released with documented gaps and exhibits.

Section · 01

How client material is handled during a case

Client material is treated as the most sensitive part of a case, held under role-based access with encryption in transit and at rest.

01 · Module

Restricted access

Case material is available only to analysts assigned to that case.

02 · Module

Encrypted

Material is protected in transit and at rest.

03 · Module

No reuse

Client material is never reused for system training.

04 · Module

Confidential

Case material is not shared beyond the agreed scope.

Section · 01

How a case is formally closed

Each case closes with a written evidence report and a handover note, without pressure into further engagements or open-ended billing.

01 · Module

Handover

A written handover summarises the report and exhibit index.

02 · Module

No recurring fees

Clients are not enrolled into automatic billing cycles.

03 · Module

Optional follow-up

Further work is only offered where the client requests it.

04 · Module

Retention

Case material is retained under a published retention schedule.