The Greyline Verification Standard

The reason a buyer believes the output.

With no pricing on this site, this page and the named principal carry most of the persuasive load. Every engagement, whatever the capability, is held to the standard described here.

The Greyline Intelligence Cycle

Direction, collection, verification, corroboration, analysis, assessment.


Eight stages, every engagement: Direction — the question is defined before collection starts. Collection — sourced, dated material gathered against that question. Verification — each item checked against known reliability standards. Corroboration — findings cross-referenced against at least one independent source wherever the material allows. Analysis — verified findings assembled into a coherent picture. Assessment — the analyst's judgement on what the picture means. Analyst sign-off — a named individual takes personal accountability for the report. Monitoring — where the engagement is ongoing, the cycle repeats against the same standard.

An unverified finding reads as a lead in an analyst's working notes — flagged, dated, not yet corroborated. A corroborated finding reads as a sourced, dated statement in the delivered report, cross-referenced wherever the underlying material allows it. We do not present the two the same way.

Method In Detail

The five sub-pages.


Evidence Standards

ACPO Principles, UK GDPR, CPR Part 35.


Digital evidence work is conducted to the ACPO Principles for Digital Evidence. All personal data handling is governed by UK GDPR and the Data Protection Act 2018. Chain-of-custody documentation is maintained as standard, and reports destined for litigation are formatted to CPR Part 35 requirements where the instruction calls for it.

Quality Assurance

Named accountability, peer review, reproducibility.


Every report identifies the analyst personally accountable for it. Litigation-aligned work receives peer review before delivery. The reproducibility standard means an independent third party could follow our documented process and arrive at the same audit trail — that is the bar we hold ourselves to, not just an internal sign-off.

Limitations & Boundaries

What we will not do, and where jurisdiction ends.


We do not hack accounts, intercept private communications, impersonate individuals to extract information, or pay for unlawfully obtained data — see the full published list of exclusions on /about. Outside the UK, our reach is via named, vetted in-country partners under written confidentiality agreements; we do not use anonymous subcontractors, and jurisdictional limitations are disclosed in every affected report rather than left implicit.

See It Applied

Read the capability pages.