top of page

Privacy Policy

Who We Are and What This Policy Covers

Sawtooth Digital Forensics ("Sawtooth," "we," "us") is an Idaho Falls–based digital forensics, data recovery, and cybersecurity advisory practice. This policy applies to information we collect through our website intake forms, by phone or email, and in the course of an active engagement — whether you are an individual submitting a failed drive for recovery, an attorney retaining our expert-witness services, or an organization engaging us for a security assessment.

In the event a signed engagement letter, retainer agreement, or non-disclosure agreement for a specific matter conflicts with this policy, that document governs for that matter. Certain engagements — for example, those involving protected health information — may require a separate regulatory agreement, such as a HIPAA Business Associate Agreement; this policy does not replace that agreement where one is required.

Information We Collect

Contact and intake information. Name, company or organization, email, phone, and the details you submit through our Data Recovery, Forensic & Legal, Consulting, or Contact intake forms.

Engagement and matter information. The nature of your request or legal matter, jurisdiction, organizational details, timelines, and anything else you share to help us scope an engagement.

Devices, media, and digital evidence. Physical devices, storage media, forensic images, and electronically stored information (ESI) you submit for data recovery, forensic examination, incident response, or litigation support.

Communications. Correspondence with our practice, whether through standard channels or an encrypted channel established for your engagement (see "Encrypted Client Communications" below).

Website usage information. Basic technical and usage data collected through the site (see "Cookies & Website Analytics" below).

How We Use Your Information

We use the information above to:

  • Evaluate, scope, and deliver the service you requested — diagnosis, recovery, forensic examination, expert-witness support, or a consulting engagement.

  • Communicate with you about your matter, provide quotes, and deliver findings and reports.

  • Meet legal, regulatory, or court-ordered obligations, including discovery obligations, subpoenas, and preservation orders.

  • Maintain the business records an engagement requires — billing, scheduling, and quality assurance.

We do not use client, case, or evidentiary data for marketing; we do not sell personal information; and we do not use data you submit for recovery or forensic examination to train, develop, or improve any product, model, or service.

Evidence Handling, Chain of Custody & Federal Evidence Rules

When we receive digital evidence — a device submitted for recovery, a forensic image collected during an engagement, or ESI gathered for litigation — we handle it under a documented chain-of-custody process intended to preserve both the integrity of the data and its admissibility, including:

  • Documented receipt, transfer, and return of all evidence and media, with each transfer logged and time-stamped.

  • Write-blocked (forensically sound) acquisition wherever original media is imaged, to prevent alteration of source data.

  • Cryptographic hash verification of forensic images at acquisition and at each later access, to demonstrate the data has not changed.

  • Access-controlled, logged storage at every stage — physical original media secured offline, and every digital copy made from it encrypted at rest (see "Data Security: How We Store Evidence and Data" below for how originals, archival images, and working copies are each handled).

Our methodology is built with the framework of the Federal Rules of Evidence in mind — including the authentication requirements of Rule 901, the self-authentication provisions for certified electronic records and device data under Rule 902(13)–(14), and the original/duplicate standards of Rules 1001–1008 for electronically stored information. Where we are engaged to provide expert testimony, our methodology and reporting are prepared with the reliability standard of Federal Rule of Evidence 702 (and the Daubert framework it codifies) in mind. (See "Standards & Legal References" near the end of this policy for links to the current rule text.)

These references describe the standards that inform our process; they are not a guarantee of admissibility in any particular court or proceeding, which depends on your matter's facts, the presiding jurisdiction's rules, and the court's own rulings. Retaining counsel should evaluate admissibility questions specific to your case.

Confidentiality & Non-Disclosure Agreements

We treat all client information, case details, and evidence as confidential. For consulting and assessment engagements (security assessments, AI risk reviews, tabletop exercises, and related advisory work) and for incident response and forensic examination engagements, we offer a mutual non-disclosure agreement as a standard part of engagement setup. You may request one from your point of contact before sharing sensitive information, or we will include one with your engagement letter.

When we are engaged directly by an attorney on a legal matter, our communications and work product may also be protected by attorney-client privilege and the work-product doctrine; we coordinate with retaining counsel to help preserve those protections.

eDiscovery & Litigation Data Handling

For litigation support and eDiscovery engagements, we collect, preserve, and analyze electronically stored information using methodology intended to be defensible and to support your obligations under the Federal Rules of Civil Procedure — including the scope-of-discovery provisions of Rule 26(b), the ESI production requirements of Rule 34, and the preservation expectations reflected in Rule 37(e) (see "Standards & Legal References" below for the current rule text). Where a litigation hold is in place, we coordinate collection and preservation to help avoid spoliation and to document the reasonable steps taken to preserve relevant ESI.

We produce ESI in the format requested by counsel where feasible, and maintain metadata integrity throughout collection and processing.

Data Security: How We Store Evidence & Client Data

We do not maintain unencrypted digital data stores. What this means in practice depends on the stage of the evidence lifecycle: an original device, an archival forensic image, or a working copy under active examination.

Original media you send us. The physical device or media you submit — a hard drive, phone, SD card, or similar media — is preserved exactly as received. We do not write to it, and we do not apply digital encryption to it, as doing either would alter original evidence. Instead, it is protected physically: stored offline in access-controlled, logged storage, connected only through write-blocked hardware for controlled acquisition, and tracked through chain of custody from receipt to return.

Forensic images and evidentiary duplicates. The exact bit-for-bit copy created from your original — the archival "master" image made to preserve the evidentiary record — is hash-verified at creation and then stored encrypted at rest, with access limited to personnel working your matter. This verified copy is the basis for our subsequent work, and is used to demonstrate, by hash comparison, that nothing has changed since acquisition.

Working and analysis copies. Copies created for active examination — file carving, partition repair, or similar work — are also stored encrypted at rest. They are decrypted only within our controlled forensic environment while actively in use, never stored unencrypted on portable or general-purpose systems, and deleted once no longer needed for the engagement, consistent with the retention terms below.

Original media is therefore secured physically, and every digital copy created from it — archival or working — is encrypted at rest.

 

This distinction between secured, unencrypted originals and encrypted copies reflects how forensic-lab accreditation and consensus digital-forensics standards treat evidence; it is not an arbitrary internal practice. Forensic-lab accreditation is administered today by ANAB, which now runs the ASCLD/LAB forensic-accreditation program on the ISO/IEC 17025 standard plus forensic-specific requirements. That framework centers on chain-of-custody integrity, access control, and documented quality management rather than a specific encryption mandate for stored copies. Encrypting our forensic images and working copies is a confidentiality control applied on top of those integrity requirements, consistent with the digital-evidence handling practices published by the Scientific Working Group on Digital Evidence (SWGDE), which describes creating a hash-verified working copy and archive from every original. (See "Standards & Legal References" below for links.)

Encrypted Client Communications

Sawtooth Digital Forensics uses public-key (asymmetric) cryptography to protect sensitive communications and to share case or evidence data with clients. For engagements involving sensitive data exchange, a unique data encryption key is established for your engagement prior to the transmission of any evidence, case file, or report — key exchange is completed before sensitive data leaves our custody, not after.

A self-service secure-communications tool — consisting of a published public key and an in-browser encryption option — is in development for this website and is not yet available. Until it is released, encrypted communications and key exchange are arranged directly as part of engagement setup; please contact your point of contact to arrange this before sending sensitive files or details. Many routine data-recovery inquiries do not require this level of protection; however, an encrypted channel is available upon request for any engagement.

No Third-Party Disclosure Without Consent

We do not sell, rent, or share your personal information, case details, or evidence with third parties for their own marketing or business purposes. We disclose information to a third party only:

  • With your written consent,

  • To subcontractors or partners engaged to help deliver your service, under confidentiality obligations at least as protective as this policy,

  • When required by law, subpoena, court order, or other valid legal process, or

  • To law enforcement in connection with a report you have asked us to make (for example, in a ransomware or breach matter), or where we are legally obligated to report certain conduct.

Where legally permitted, we will notify you before disclosing your information in response to legal process, unless prohibited from doing so (for example, by a sealed order).

Data Retention & Destruction

We retain case files, evidence, and communications for as long as needed to complete your engagement, satisfy any legal, regulatory, or court-imposed retention obligation (including litigation holds), and support any anticipated expert-witness testimony related to your matter. Outside those obligations, we do not keep evidence or personal data longer than necessary.

At the close of an engagement, and consistent with any retention obligation, we return or securely destroy physical media and delete forensic images and case data per your instructions and our standard retention schedule, available on request. Recovered personal data (for example, from a data-recovery engagement) is provided back to you and not retained beyond what is needed to complete and support that engagement.

Your Rights

You may ask us to:

  • Tell you what information we hold about you or your matter,

  • Correct inaccurate contact or case information,

  • Delete personal information we hold, where we are not required to retain it for legal, evidentiary, or engagement-related reasons — chain-of-custody integrity and active legal holds may limit deletion of evidence or case records while a matter is open, or

  • Provide a copy of any NDA in place for your engagement.

To make a request, contact us through the form on our Contact page.

Cookies & Website Analytics

Our website may use cookies or similar technologies for basic site functionality and, if enabled, aggregated analytics to understand which pages are useful. We do not use cookies to build advertising profiles, and we do not run third-party ad tracking.

Standard & Legal References

This policy references several external rules and standards. The source material for each is available at the following:

  • Federal Rules of Evidence — official text: uscourts.gov/forms-rules/current-rules-practice-procedure/federal-rules-evidence (rule-by-rule reading version: law.cornell.edu/rules/fre)

  • Federal Rules of Civil Procedure — official text: uscourts.gov/forms-rules/current-rules-practice-procedure/federal-rules-civil-procedure (rule-by-rule reading version: law.cornell.edu/rules/frcp)

  • ANAB forensic laboratory accreditation (ISO/IEC 17025) — the body that now administers the ASCLD/LAB forensic-accreditation program: anab.ansi.org/accreditation/iso-iec-17025-forensic-testing-laboratory

  • ASCLD — the American Society of Crime Laboratory Directors, a professional society and not itself an accrediting body: ascld.org

  • SWGDE — the Scientific Working Group on Digital Evidence, publisher of the digital-forensics best practices referenced above: swgde.org

These links direct to the official websites of each standards body. They describe the frameworks that inform our process and do not constitute a guarantee regarding the outcome of any particular matter. See the note at the end of "Evidence Handling, Chain of Custody & Federal Evidence Rules" above.

Children's Privacy

Our services are directed at businesses, legal professionals, and adult individuals. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with information, please contact us and we will delete it.

Changes to This Policy

We review this policy periodically and update the Effective Date and Last Reviewed date above when we do so. Material changes — for example, once the self-service encrypted-communications tool described above becomes available — will be reflected here.

Contact Us

To ask about this policy, request an NDA, or arrange an encrypted communication channel, please contact us through the intake form on our Contact page. We do not publish a direct email address; submissions are routed to our practice inbox.

bottom of page