Methodology and Limitations
The detector normalizes mapped CSV fields and applies five deterministic, time-windowed rule families: removable media, staged collection, cloud/web upload, email transfer, and print/export. Findings are ranked screening indicators, not proof of theft, intent, attribution, or unauthorized transfer.
The detector does not assess authentication compromise or determine whether an account was hacked.
Results depend on the completeness, accuracy, timestamp quality, and field mapping of the supplied timeline. Validate each indicator against original artifacts and case context.
This is a technical screening tool, not a final expert opinion. Findings require contextual review and do not independently establish intent, attribution, theft, or unauthorized transfer.
Privacy: Analysis occurs locally in this browser. The evidence file, filename, findings, and report are not transmitted to Precision Forensics.