Service

eDiscovery and Electronic Evidence Collection

When two companies are in litigation, when a business receives a federal preservation letter, or when a court order requires the collection of electronic records, the question is not whether the data exists. It almost always does. The question is where it lives, how to collect it correctly, and how to manage the volume without running up a bill that approaches the value of the dispute itself.

Cyber Agents, Inc. has conducted more than 125 eDiscovery collections in business litigation, federal investigations, contract disputes, and corporate fraud matters across Microsoft 365, Google Workspace, on-premise Exchange, SharePoint, OneDrive, Teams, and major cloud storage platforms. We work for plaintiffs, respondents, and in cases where both sides need a neutral party to conduct the collection and neither will accept the other’s examiner.

Preservation and litigation holds

The obligation to preserve relevant electronic data often arises before litigation is filed. A preservation letter from opposing counsel, a federal investigative inquiry, or counsel’s own judgment that litigation is likely triggers the duty. The window between that trigger and the moment data is lost — through routine deletion, cloud account expiration, or employee device turnover — is frequently shorter than it appears.

We assist with litigation holds at the technical level: identifying where relevant data lives across the organization’s systems, issuing preservation instructions that account for cloud accounts and personal devices used for business, and collecting data in a forensically sound manner that maintains chain of custody through trial. Court-ordered collections proceed on a defined timeline. Pre-discovery collections can be planned, scoped, and executed before the opposing party or the government has an opportunity to define the universe of what they want.

Where the data actually lives

Modern organizations do not store their data in one place. Email lives in the cloud. Documents are shared via links, not attachments. Collaboration happens in platforms that most discovery requests do not address by default. On-premise infrastructure still exists alongside cloud services, sometimes running systems the organization has not fully migrated and sometimes running systems they are not aware are collecting data.

We collect from Microsoft 365 and Google Workspace, including SharePoint, OneDrive, Google Drive, Teams, and all major cloud storage and collaboration platforms. We collect email from any provider. We collect from on-premise Exchange servers, network shares, local file servers, and database servers providing network services.

Modern attachments require specific handling. When a user shares a file from OneDrive or SharePoint via email, the email contains a hyperlink — the file lives in the cloud, not in the message. A standard email export captures the link but not the document. We collect the linked file alongside the email, preserving the complete record rather than a reference to something that may no longer exist by the time opposing counsel reviews the production.

We have also conducted application-level analysis — internal line-of-business apps, web applications, accounting systems, and custom-built software. In cases where the software itself is the subject of the dispute, we have analyzed application completeness and identified functional gaps relevant to contract performance claims.

Scoped collection and the cost of doing it wrong

eDiscovery platforms charge by the gigabyte. A broad, unfiltered collection loaded directly into a review platform — and billed at platform rates — is one of the fastest ways for litigation costs to exceed what either side anticipated when the case began.

We filter and cull data before it enters the review platform. Date range filtering. Custodian filtering. Deduplication. Near-deduplication. File type exclusions for data that will never be responsive. The result is a document set sized to the actual scope of the dispute rather than everything the organization has ever stored. In matters where we have been engaged early, the reduction in platform volume has been significant enough to materially affect the overall cost of the litigation.

We operate our own Relativity instance. Attorneys review documents directly in the platform, apply coding decisions, run searches, and prepare production sets without relying on a third-party hosting provider as an intermediary. Our team can assist with review workflow setup, search term validation, and production formatting to the opposing party’s specifications.

What attorneys are looking for

In business litigation, the most consequential email in a case is rarely marked important. It is the internal message that describes a known problem before anyone anticipated it becoming a legal matter. The safety concern raised by an employee and not acted on. The incident report drafted the afternoon of the event and revised the following morning. The thread where executives discussed a product defect and chose not to disclose it.

Business email compromise cases present a different target. When a company is defrauded by a spoofed or look-alike email address and wire transfers funds to the wrong account, the forensic record of that email — headers, routing data, authentication failures, and send timestamps — establishes the origin of the message and whether it passed through the organization’s mail systems as authentic. That analysis requires the underlying mail data, not the forwarded message a user printed to PDF.

When a PDF itself may be disputed, preserving the native file is essential to a defensible forensic report.

We have worked contract disputes in software development, automotive supply chain, and the music industry. The pattern is consistent: both sides have the same email system, both sides preserved some of what they needed, and neither side has the complete record until a neutral party collects from all custodians under a defined scope.

Case types we handle

  • Business-to-business litigation requiring collection from cloud and on-premise systems across multiple custodians
  • Federal investigations and grand jury matters requiring court-ordered or voluntary preservation collections
  • Contract disputes in technology, manufacturing, automotive supply chain, and entertainment
  • Business email compromise fraud cases requiring email header analysis and authentication review
  • Internal investigations where the organization needs a neutral party to collect without involvement of internal IT
  • Corporate disputes requiring collection from departing or terminated employee accounts before data is lost

Why you need an expert

eDiscovery done wrong creates two problems. The first is a spoliation motion when relevant data was not preserved. The second is a document review budget that consumes resources the litigation cannot support. Both are avoidable.

Cyber Agents has conducted collections in federal and state court matters and in arbitration proceedings. We produce collections that are defensible — clean as a properly hashed image, with documented methodology, chain of custody, and processing logs that satisfy opposing counsel and court scrutiny. We have testified to collection methodology in proceedings where the completeness or integrity of a collection was contested.

When we scope a collection, we scope it with the litigation strategy in mind. The goal is not to collect everything. It is to collect what matters, preserve it correctly, and deliver it in a format that moves the case forward rather than buries it.

Related services and litigation support

Contact Cyber Agents to discuss whether ediscovery — o365 and beyond fits your matter.

Free consultation

Talk to an examiner before the evidence moves.

Digital evidence degrades, overwrites and expires. The earlier we are involved, the more of it survives to be examined.