Products
Crucible — forensics & OSINT suite Recovery Lab — data recovery & repair GuardDex — family security Richey Authenticator — private 2FA All products How it works Services Downloads Portal Request a walkthrough
🔬 Crucible · Digital forensics & OSINT

Turn devices and scattered data into one defensible case.

Crucible is a self-hosted, court-grade platform of three connected studios — for evidence, intelligence, and device extraction — that pulls everything into one searchable, chain-of-custody timeline.

Built to do what the five-figure subscription suites do, and a few things they don't, while every byte of evidence stays on hardware you control.

What is Crucible?

Modern investigations drown in data — a phone backup, several mailbox exports, a Facebook download, login histories, screenshots, voicemails, location records. Crucible ingests all of it into one normalized, hash-verified timeline, makes it instantly searchable, lets a team work it together, and produces court-defensible documents where every sentence traces back to the evidence. Self-hosted. No per-seat licensing. Nothing leaves your premises.

Three studios, one case

Each is excellent alone. Together — sharing one sign-on and one case — they're a force multiplier.

🔎
The case

Forge Studio

Ingests every kind of evidence into one unified, UTC-normalized, SHA-256-verified timeline. Search, analyze, collaborate, and draft the filing — with findings that stay inside the evidence.

🛰️
The intelligence

OSINT Studio

21 intelligence sources, per-entity dossiers, link-analysis, geolocation and impossible-travel — with one-click pivots that feed straight back into the case.

🔬
The acquisition

Extraction Studio

Acquire from a connected phone or process a backup into a normalized, hashed, signed evidence bundle that Forge ingests by path.

What it does

The capabilities that turn raw data into an exhibit.

📥

Ingests anything

iOS/Android backups, iMessage/SMS databases, Gmail mbox, Facebook & Google exports, PDFs & Word (scanned pages OCR'd), screenshots (HEIC/JPG — OCR'd, with EXIF to the timeline), audio & voicemail (transcribed), location history, contacts, raw SQLite, or a whole ZIP — auto-detected.

🕘

One correct timeline

Every timestamp normalized to UTC through one converter that knows the traps — Apple Cocoa, WebKit, Unix, Android — so a message, a login, and a photo line up. Raw values preserved for audit.

🔍

Find it four ways

Full-text Search across everything · Explore messages by person/date · Ask in plain English (answered only from the case, every fact cited) · read-only SQL with a forensic cheat-sheet.

Work as a team

A collaborative timeline you can star, tag, and comment — every mark attributed — plus saved views and one-click "show everything involving this IP / number / account."

⚖️

Findings with discipline

Every finding is tiered (note → lead → pillar), carries its basis and what it does not establish, and is retractable with an audit trail. Over-reach is designed out.

✍️

Drafts & signs the filing

An AI writer composes a Statement of Facts or declaration grounded only in the record — every sentence cited — and exports a cryptographically signed .docx you verify before filing.

How it works

Acquisition to exhibit — with the chain of custody intact the whole way.

Acquire or import

Pull a connected phone in Extraction Studio (logical, full-filesystem, or chip-off), or just drop in the backups and exports you already have. Each source is SHA-256 hashed and journaled.

Everything lands on one timeline

Forge auto-detects every file type and normalizes it into a single, UTC-correct, searchable case — messages, emails, logins, photos, locations, documents, all together.

Investigate & enrich

Search, browse threads, ask questions, map relationships. One click sweeps the case's IPs, emails and numbers through OSINT and records the breach/abuse/VPN hits as leads.

Capture findings as a team

Star, tag, and comment the timeline; capture any result to a Page with its source and row reference recorded automatically. Tier each finding and state its basis.

Produce the exhibit

Draft a cited, signed .docx, print a report to PDF, or export the whole case as CASE/UCO — the standard forensic-exchange format — for any other tool.

Why Crucible

Court-grade capability, on your own terms.

Self-hosted & private

Runs on hardware you control — evidence never leaves your premises, and there's no per-seat cloud bill.

Chain of custody, end to end

Every source hashed at ingest; every exhibit Ed25519-signed and re-verifiable. Acquisition to filing, provable.

Defensible by design

Tiered, cited findings separate fact from inference and never assert beyond their basis — claims are retractable on the record.

AI that summarizes, never invents

Built FRE 707-aware: the assistant cites records, it does not generate evidence. The discipline is in the product.

Standards-based

One-click CASE/UCO export makes the whole case portable to other forensic tools — and credible in the file.

Real people behind it

Built and supported by Richey Business — you can actually reach us.

Going further

The depth that separates Crucible from a folder of exports.

🛰️

21-source OSINT

Breach, people, and threat-intel providers (DeHashed, HIBP, Shodan, Censys, GreyNoise, VirusTotal, AbuseIPDB and more) in one query, with per-entity dossiers and recursive auto-pivot.

🗺️

Impossible-travel detection

Plots every login geographically and flags accesses that are physically impossible for one person in the time available — the heart of a location alibi.

📱

Full-filesystem acquisition

checkm8/palera1n for eligible iPhones, version-specific jailbreaks for newer ones, MediaTek BROM and Qualcomm EDL for Android — each into a signed bundle.

🧰

Every engine, automated

iLEAPP/ALEAPP, mvt (encrypted-backup decryption), imessage-exporter with device-of-origin, macOS Unified Logs, disk images — the right one runs automatically.

🔐

Single sign-on & roles

All three studios share one login with role-based access (admin / analyst / viewer) and two-factor.

🎨

Made for long sessions

Six themes and six fonts (high-contrast and dyslexia-friendly included), tuned for review work — and usable on a phone for light field tasks.

🛟

Recovery & repair included

The full Recovery Lab ships inside Extraction Studio — undelete deleted files, carve formatted drives, and repair broken/truncated media, with recovered files flowing straight onto the case timeline.

A look inside

From the live demo — synthetic data only, no real case information.

Forge Studio — unified case overview with CASE/UCO export and OSINT auto-enrich
Forge — one unified case (CASE/UCO export & OSINT enrich)
Forge collaborative timeline with stars, tags, comments and filters
Collaborative timeline — star · tag · comment · filter
Forge AI court-document drafter with Ed25519-signed exhibit export
AI drafter — cited, signed .docx exhibits
OSINT Studio per-entity dossiers list
OSINT — a dossier for every identifier
OSINT Studio geolocation and impossible-travel case map
Geolocation & impossible-travel map
OSINT Studio link-analysis relationship graph
Link-analysis relationship graph
Extraction Studio device acquisition with every forensic engine
Extraction — acquire a device, every engine ready
Extraction Studio in-app acquisition guidance
In-app acquisition guidance
Forge Studio built-in how-to guide
Guided — an in-app how-to for every workflow
Recovery Lab — data recovery & media repair, included in Crucible
Recovery Lab — undelete, carve & repair (included)
Recovery Lab — repair broken & truncated media
Repair broken & truncated media

Try the live demo

Loaded with synthetic data — explore freely, even drop in test files; it's reset regularly. Each studio is key-gated by design (that's the security model), so here are throwaway demo keys.

Forge— open, no key needed
OSINTb83395f9e4bb75000431afa75b0c7d96df510b883fd4d552
Extractionf25bd76f651715c9ec8221867eefa32a1ad5ac93f33a6789

Paste a key into that studio's ⚙ Settings → API key. Every request to OSINT & Extraction requires a key (or a Forge single-sign-on token) — nothing is reachable without authentication, with role-based access and an audit trail behind it. In a real deployment these are your private keys; the demo's burn no third-party credits.

See Crucible on your own evidence.

Investigators, counsel, and security teams: book a walkthrough of the live demo, or talk to us about a private, self-hosted deployment.

Self-hosted (Docker or native) · Synthetic-data demo, access on request · Built & supported by Richey Business