Review all collected evidence for a case from the Case Data page. Data is organized by source in the Data Sources sidebar.
Open Case Data
Case Data is where all collected evidence lives.
From My Cases, click a case to open it, then click Case Data in the left sidebar. You can also click View next to any data source on the Collection Requests page to go directly to that source's data.
Data Sources
The Data Sources sidebar lists every collected source for the case.
Sources are grouped under device and account headers. The number next to each source shows how many conversations, files, or records it contains. Click a source to view its contents. Use Filter by custodian/code to narrow the list when a case has multiple custodians or extraction codes. Click the collapse arrow to hide the sidebar into a dropdown bar, or expand it again.
Data types
Each data source contains one or more of the following data types.
Messages are iMessage and SMS conversations collected from a phone backup. Select a phone source in Data Sources, then click Messages to see a list of conversations with contact names, message previews, dates, and message counts. Click a conversation to read the full message history. See How do I review phone data?.
Voicemails are audio recordings collected from a phone backup. Select a phone source, then click Voicemail to see recordings with contact names, dates, durations, and transcript previews. See How do I review phone data?.
Photos and Videos include media collected from a phone backup. Select a phone source, then click Photos and Videos to browse thumbnails. Filter by Photos or Videos, or search by filename. See How do I review phone data?.
Contacts are address book entries collected from a phone backup. Select a phone source, then click Contacts to browse the contact list with names and phone numbers. Use the alphabet index to jump to a letter, or search by name. See How do I review phone data?.
WhatsApp conversations are collected from a phone backup. Select a phone source, then click WhatsApp to see a list of conversations. The review interface works the same as Messages. See How do I review phone data?.
Call logs show the phone call history collected from a phone backup. Select a phone source, then click Call Logs to see calls with contact names, numbers, call types, and durations. Filter by call type and export to CSV or PDF. See How do I review call logs?.
Files include documents, images, audio recordings, videos, and other files uploaded manually or collected from a device. Select Files in Data Sources to see all uploaded files with name, type, size, and date. Filter by type and search by name. See How to review uploaded files.
Emails are threads collected from Gmail, Outlook, or Yahoo accounts. Select an email account in Data Sources to see collected threads with sender, subject, preview text, message count, and date. Group by search term, filter by folder, date, domain, or tag, and search within results. See How do I review collected emails?.
Social media messages include Facebook Messenger, Instagram, and Threads direct messages. Select a social media account in Data Sources to see a list of conversations. The review interface works the same way across all platforms. See How to review social media messages.
Financial records include bank transactions and investment holdings collected through Plaid. Select a financial institution in Data Sources to see linked accounts. Credit card and bank accounts show transactions; investment accounts show holdings. See How to review financial data.
Review tools
These tools are available across data types while reviewing.
How do I use review tools?: toolbar, View Settings, Jump to date, Translate, Gap Analysis
How do I search within a conversation?: keyword search within a single conversation
How do I use Case Search?: search across the entire case
How do I add comments?: annotate conversations, messages, and email threads
How do I compare conversations?: side-by-side comparison across sources
How do I tag messages?: organize evidence with tags


