Thin-file subjects
Credit header from all three nationwide bureaus, plus an alternative consumer credit layer. That second layer is where recent arrivals, young subjects, and people who deal in cash show up.
Most investigative firms rent the same few databases and forensic suites as everyone else. We built our own search platform, our own forensics platform, and our own reporting system, and we run every file through them.
Our search platform. One query returns credit header, alternative credit data, phone records, digital footprint, and county assessor records, sorted by identity and scored on the evidence behind each line.
Credit header from all three nationwide bureaus, plus an alternative consumer credit layer. That second layer is where recent arrivals, young subjects, and people who deal in cash show up.
Landline and wireless, with carrier, line type, and whether the number is still active. Address history comes with reported date ranges.
The best addresses on each identity go straight to the county assessor for owner of record, assessed value, and transfer history with the recorder's document number.
Start from a single identifier and see where it is registered across the consumer internet, and whether it appears in a known breach.
When eight people share a subject's name, Lodestone keeps each one as a separate candidate with their own identifiers and address history, ranked against what we searched. It names the identifiers that did the matching, so the ranking can be checked.
Addresses, phones, and emails are scored one to five based on how recently they were reported, whether the carrier and line type are known, and how many independent sources agree. Every material field shows where it came from.
Our forensics platform. It turns phone, computer, and disk evidence into findings, and records every action taken on that evidence in a custody ledger that can't be quietly altered.
Each evidence item is hashed when it is acquired and checked against that hash every time it is opened. Every custody event (who accessed what, when, and why) goes into an append-only ledger, and each entry is cryptographically linked to the one before it. If a record is changed, the chain breaks and the break is visible.
When a methodology is challenged, there is a signed trail from acquisition to final report.
Register the item and hash the source before anything else touches it.
The working copy is matched to the original. A mismatch stops the case.
Records are extracted and recovered, with their location in the image kept.
Timeline, link analysis, and hash matching across all items.
Findings and the custody ledger are assembled, signed, and exported.
The tool is tested too. Bloodhound runs its parsers against known reference data and produces a signed validation report, so tool reliability is documented before anyone asks.
Our asset and locate reports are built in an in-house system that checks each report against our standards and won't print until the problems are fixed.
Public record pages are captured by our own tool. Each capture is numbered, stamped with its source URL and time, and added to the report as an exhibit.
The tool refuses a capture if the page is an error or block page, if it is nearly empty, or if the identifier it should show (a parcel number, for example) isn't on it. That keeps a screenshot of "Access Denied" out of the exhibit list.
Authorized engagements run by Kyeson Utley, an OSCP- and CEH-certified penetration tester. Scope is agreed in writing before any testing starts.
Introduce your firm and we'll explain what we would run and what the report will show.