1. Mobile Device Forensics and Data Recovery
Forensic acquisition, extraction, examination, and lawful recovery of data from smartphones, feature phones, SIM cards, memory cards, tablets, smartwatches, GPS devices, drones, and digital cameras. Services may include the recovery and analysis of messages, calls, contacts, application data, photographs, videos, documents, location records, and deleted data, where technically possible.
2. Computer, Server, and Storage Forensics
Forensic imaging, preservation, examination, and recovery of data from desktop computers, laptops, servers, hard drives, solid-state drives, flash drives, memory cards, and other storage media. Services may include deleted data recovery, volatile memory acquisition, user activity reconstruction, file system analysis, and digital timeline development.
3. Network and Cyber-Incident Forensics
Collection and analysis of network traffic, security logs, and infrastructure artifacts to investigate cyberattacks, unauthorized access, suspicious communications, data leakage, and affected systems. Evidence may include firewall, router, switch, VPN, IDS/IPS, server, cloud, and packet-capture records.
4. Malware, Memory and Specialized Digital Analysis
Static, dynamic, and memory-based analysis of suspicious software, scripts, attachments, URLs, and system artifacts to determine behaviour, persistence, communication, impact, and indicators of compromise.
5. Digital Media Authenticity and Emerging-Technology Forensics
Technical examination of digital documents, emails, messages, photographs, audio, video, CCTV/DVR exports, and screenshots to assess integrity, metadata, and alteration indicators. RFI may also examine cloud, Internet of Things, and other emerging-technology evidence, subject to legal and technical assessment.
6. Expert Consultation, Legal, and Court Support
Interpretation of digital forensic findings, preparation of court-admissible reports, expert consultation, presentation of findings, and expert witness testimony for judicial, investigative, regulatory, disciplinary, or administrative proceedings.
What Our Services Support
Criminal and cybercrime investigations
Fraud, financial crime, corruption, and economic-crime investigations
Civil litigation and administrative proceedings
Corporate and internal investigations
Cybersecurity incident investigation and reconstruction
Electronic evidence preservation and lawful data recovery
Expert interpretation and presentation of digital evidence
How to Request a Digital Forensic Service
Submit an official request letter or approved service application describing the required service, incident, or dispute, available evidence, and the purpose of the examination.
Provide proof of lawful authority, ownership, or institutional authorization, together with relevant case or incident information.
RFI will conduct a preliminary legal and technical assessment to confirm the evidence condition, feasibility, scope, expected output, and estimated turnaround time.
RFI communicates the applicable fees and provides secure instructions for physical submission, approved electronic transfer, or authorized on-site evidence acquisition.
After acceptance, the request is registered and tracked through the RFI Laboratory Information Management System (LIMS), and the authorized forensic examination is conducted.
The final report and approved outputs are released only to authorized recipients through controlled physical collection, official dispatch, or approved secure electronic transmission.
Typical Service Outputs
Forensic images, extractions, and hash-verification records
Recovered digital data and identified artifacts
Activity timelines and incident reconstruction
Indicators of compromise and technical findings
Metadata and authenticity observations
Formal forensic reports, expert opinions, and testimony
Important Service Conditions
Digital forensic services are chargeable. The applicable fees will be communicated after technical evaluation and in accordance with approved RFI tariffs.
RFI accepts only requests supported by lawful authority, verified ownership, institutional authorization, or another valid legal basis.
RFI does not provide unlawful access, covert monitoring, or unauthorized examination of devices, systems, accounts, or data.
Chain-of-custody documentation is mandatory for criminal, judicial, regulatory, and institutional investigations. Evidence receipt and handling are documented for all other services.
Clients should avoid resetting, repairing, altering, or repeatedly accessing devices and digital evidence before forensic submission.
The normal service benchmark is generally seven working days under applicable SOPs, but the final turnaround time depends on evidence condition, volume, encryption, urgency, complexity, technical feasibility, and the required level of review.
Where technical limitations prevent full recovery or analysis, RFI reports those limitations and the results obtained.
Our Commitment to Quality
Every digital forensic examination is conducted using validated methods, approved procedures, controlled access, secure evidence handling, and documented chain-of-custody practices. RFI is committed to impartial, accurate, confidential, and legally defensible scientific findings that support the administration of justice.
Why Choose RFI?
Experienced digital forensic specialists
Independent and impartial scientific examination
Validated forensic methods and controlled procedures
Secure evidence handling and confidentiality
RFI LIMS-supported case and evidence workflow
Formal technical review and approval process
Commitment to quality management and international good practice
Contact and Service Request
For information on submitting digital evidence or requesting a digital forensic service, contact the Rwanda Forensic Institute through the official contact details published on the RFI website.
RFI-Advancing Justice Through Science!!
