"My battery drains fast, so I must be monitored"
Battery degradation, a recent OS update, or one badly behaved app explain this far more often than monitoring software does. It is worth checking, but on its own it establishes nothing.
Monitoring software detection · Brooklyn, NYC
Maybe they know things they shouldn't. Maybe they turn up where you are. We examine iPhones, iPads and Macs for monitoring software, management profiles and account access that shouldn't be there — and we tell you plainly what we find and what it proves.
Searching this subject turns up the same checklist everywhere. Almost none of it holds up, and believing it leads people to either panic over nothing or dismiss something real.
Battery degradation, a recent OS update, or one badly behaved app explain this far more often than monitoring software does. It is worth checking, but on its own it establishes nothing.
Charging, sunlight, video calls and background photo syncing all do this. Heat is not evidence.
This one dates from analogue telephone lines. On a modern mobile network it indicates a poor connection, not interception.
Consumer scanners look for known malicious software. The tools most often used to monitor a partner are ordinary, signed applications from mainstream vendors — family locators, device managers, screen sharing, cloud backups. A scanner has no reason to flag any of them.
The honest answer is that you usually cannot tell from the outside. That is the whole reason this service exists.
The examination
We make a forensic copy of the device and work on the copy. Nothing below requires guessing at your behaviour or reading your private messages for their own sake.
An enrolled management profile can grant sweeping control over an iPhone. We list every profile on the device, when it was installed, and what it is permitted to do.
Shared credentials are the most common route by far, and they leave no software on the phone at all. We review which devices and computers have access to the account and when they last used it.
Which applications hold location, microphone, camera, screen recording and accessibility permissions — and, where the operating system records it, when each was last used.
Active sharing arrangements, family setups, sign-in history and anything installed outside the App Store.
The parts of the operating system that log access after the fact. These are often where an answer actually comes from, and they are also the parts with the shortest memory.
Just as important, and it goes in the report. Some questions cannot be answered from the phone alone, and you should know which ones before you rely on the findings.
Before you call
The usual advice — "just factory reset it" — can destroy the answer and tell the other person you know. Here is what we do instead.
On the first call you decide the channel. We use only that one. Nothing we send names the service, and we will not leave voicemails or send follow-up email unless you tell us it is safe.
Do not reset it, do not delete apps, do not change the password yet. Every one of those actions removes evidence, and some of them send a notification to whoever else has access.
Your office, a neutral public place, wherever you are comfortable. Before any work starts, the usual paperwork: a short service authorization confirming the device is yours.
A forensic copy is taken first and the analysis runs on that. We document the method used and what it does and does not change on the device itself.
What was found, where it came from, what it means — and what it does not establish. If we find nothing, you get that in writing too, with the limits of the examination stated.
Removing access safely is its own decision, and timing matters when someone may notice. We go through the options with you rather than acting on your behalf.
We document technical findings, the method behind them, and their limits. What those findings are worth in a legal process, and what to do with them, is a conversation for you and an attorney or an advocate — not for us. We will say so plainly rather than imply otherwise.
This subject attracts people selling certainty. We would rather you heard the real shape of it before paying anyone.
A device can show that an account had access, or that an application ran. Tying that to a particular person usually needs records held by the service provider, not by the phone.
Finding nothing narrows the possibilities; it does not close them. Some monitoring leaves no trace on the device because it never touched the device — it used the account instead.
Phones keep their system records for weeks, not years. If the events you are asking about are months old, the relevant logs may simply no longer exist. We will tell you that before you pay, not after.
We examine devices you own, and we ask you to confirm that in writing. If the device is not yours, we stop there. There are no exceptions to this and we would rather lose the work than make one.
Tell us what has been happening and which device is involved. Fifteen minutes is usually enough to say whether an examination can answer your question — and sometimes the answer is that you need an advocate or a locksmith more than you need us. You will hear that too.
Please don't put passwords, account details or case details in an email. Bring those to the call — and if this device might be monitored, call from a different one.