With no pricing on this site, this page and the named principal carry most of the persuasive load. Every engagement, whatever the capability, is held to the standard described here.
Eight stages, every engagement: Direction — the question is defined before collection starts. Collection — sourced, dated material gathered against that question. Verification — each item checked against known reliability standards. Corroboration — findings cross-referenced against at least one independent source wherever the material allows. Analysis — verified findings assembled into a coherent picture. Assessment — the analyst's judgement on what the picture means. Analyst sign-off — a named individual takes personal accountability for the report. Monitoring — where the engagement is ongoing, the cycle repeats against the same standard.
An unverified finding reads as a lead in an analyst's working notes — flagged, dated, not yet corroborated. A corroborated finding reads as a sourced, dated statement in the delivered report, cross-referenced wherever the underlying material allows it. We do not present the two the same way.
All inquiries are received under strict internal confidentiality protocols. A confidentiality agreement is provided before any detailed case discussion. We collect only the information necessary to assess fit, held on UK-jurisdiction infrastructure, encrypted in transit and at rest.
We issue a written scoping note covering the question to be answered, the methodology to be applied, the deliverable, the standard it will be produced to, and the fixed fee. We do not work on open-ended hourly retainers.
Conducted to ACPO Principles for Digital Evidence: original data is not altered, contemporaneous records are kept, and the audit trail is reproducible by an independent third party. Updates are provided at agreed intervals.
A written report covering scope, methodology, findings, supporting evidence, and a non-technical summary. Litigation-aligned engagements include chain-of-custody documentation and expert-evidence formatting where required.
Analytical tradecraft, source reliability grading, and how AI-assisted collection is used — with mandatory analyst verification on every output.
Read →OSINT, SOCMINT, cyber threat intelligence, entity resolution, identity intelligence, behavioural analysis, network and link analysis, digital forensics, and dark web intelligence.
Read →Chain of custody, capture tooling, admissibility, and how evidence is preserved and handed over — the standard every Greyline deliverable is built to.
Read →Report formats, sample redacted extracts, and expert-evidence structure — including where to view a full anonymised sample report.
Read →The named tool stack behind Greyline's analysis, and the platform layer — Greyline Sentinel, live today, and the Greyline Intelligence Cloud, on our roadmap.
Read →Digital evidence work is conducted to the ACPO Principles for Digital Evidence. All personal data handling is governed by UK GDPR and the Data Protection Act 2018. Chain-of-custody documentation is maintained as standard, and reports destined for litigation are formatted to CPR Part 35 requirements where the instruction calls for it.
Every report identifies the analyst personally accountable for it. Litigation-aligned work receives peer review before delivery. The reproducibility standard means an independent third party could follow our documented process and arrive at the same audit trail — that is the bar we hold ourselves to, not just an internal sign-off.
We do not hack accounts, intercept private communications, impersonate individuals to extract information, or pay for unlawfully obtained data — see the full published list of exclusions on /about. Outside the UK, our reach is via named, vetted in-country partners under written confidentiality agreements; we do not use anonymous subcontractors, and jurisdictional limitations are disclosed in every affected report rather than left implicit.