Defensive mobile forensics · export-controlled

Defensive.By design, not by policy.

LUMA examines phones its operator is authorised to hold, and finds the spyware placed on them. It cannot reach into someone else's device, it cannot intercept, and it ships no exploit. That boundary is built into the product, not written into a terms page.

OPERATIONAL SCOPE
+Examination of devices you are authorised to hold
+State-sponsored spyware and commercial stalkerware
+A report written to be produced in court
+Air-gapped and on-premise deployment
Reaching into a third party's device
Remote surveillance or interception
Offensive tooling of any kind
What LUMA does

A phone is either clean, or it is evidence.

Your people carry devices into places where being targeted is a working assumption. LUMA turns that assumption into an answer you can act on, and a document you can defend.

01

Examine

LUMA reads the diagnostic material a phone already holds about itself - what ran, what connected, what was granted access - without altering the device.

02

Decide

The examination ends in one verdict with the reasoning behind it, so the person holding the report knows what to do next rather than what to investigate next.

03

Defend

Each finding carries its evidence and its limits. When somebody disputes the conclusion, the answer is already in the document.

04

Footprint

No agent, no profile, no persistent software on the examined device. LUMA reads what the phone already records about itself and leaves nothing behind.

05

Distance

An examination can be carried out on a device that never reaches your lab, with the owner's consent recorded as part of the record.

The report

A finding is worth what its limits are worth.

Most tools report what they found. LUMA also reports what it could not reach - so the boundary is read from the document, instead of discovered later by the person challenging it.

The same structure every time, in the language your organisation works in, so two examinations months apart can be placed side by side.

FORENSIC REPORT · EXCERPTCHAPTER 4
Proximity attack rests on two sources present on the device. One was examined and no evidence was found. The other is absent from this capture and was therefore not read. A source that could not be read supports no conclusion, and none is drawn from it here.
How it is deployed

LUMA is software you run. It is not a service.

It installs on a computer your organisation owns and controls, and the examination happens there. The material read from the device stays on that machine. There is no LUMA cloud in the path, no account to create, and nothing is uploaded for analysis - including in fully air-gapped installations with no network at all.

Your machine, your building

The examination runs where you put it. Nobody outside your organisation sees the device, the material, or the result.

No agent on the phone

Nothing is installed on the device being examined. LUMA reads what the phone already records about itself and leaves nothing behind.

Works with no network

Designed for air-gapped operation. A licensed installation examines devices and produces reports with the network cable out.

Remote when you allow it

Where your policy permits, the device owner can provide the capture without travelling to you, with their consent recorded. The examination still runs on your machine.

Two sides of mobile forensics

Built for the protectors. Not the investigators.

The industry built powerful tools for investigators to extract data from somebody else's device. LUMA covers the opposite side: protecting the owner of the device in your hand.

Offensive forensics

Investigation tools

Acquisition platforms for seized devices.

Purpose
Extract and decrypt data from a device that has been seized.
Question
What did this person do?
Client
Law enforcement, forensic labs, prosecutors.
Output
Recovered messages, location history, media.
Defensive forensics · LUMA

Protection tools

Built for the owner of the device.

Purpose
Establish whether a device you are responsible for has been targeted.
Question
Who did this to this person?
Client
Intelligence services, embassies, executive protection.
Output
A verdict, its evidence, and what to do about it.
Who it is for

Different missions. One question.

Every organisation below has the same problem in a different shape: a device carried by someone worth targeting, and no way to prove it is still clean.

Intelligence services

Before deployment

Establish the state of a device before a person carries it into a hostile environment, so anything found later has a baseline.

Diplomatic missions

After the trip

Screen staff devices returning from a posting as routine, rather than as a reaction to a suspicion somebody had to raise.

Executive protection

Around the principal

Extend the protective perimeter to the phone in the principal's pocket, which goes where the detail cannot.

Counter-intelligence

Inside the organisation

Examine devices across a team when an internal question is being asked, with a result that holds in a disciplinary process.

Foreign service

As policy

Make examination a standing requirement for officers returning from designated countries, not a decision to justify each time.

Legal and compliance

When it has to hold

Produce a forensic record that survives disclosure, cross-examination and an opposing expert.

Operational scope

What LUMA is. What LUMA is not.

Organisations in regulated environments need this in writing before a procurement conversation can begin. It is on the first page rather than inside a terms document.

LUMA is a defensive forensic platform. It operates only on devices for which the operator has explicit authorisation. It does not facilitate access to third-party devices, does not provide surveillance capabilities, and is not an offensive cyber tool.TSCM Intelligence Agency Ltd. · Operational Scope Statement

In scope by design

  • Examination of devices you are authorised to hold
  • Detection of state-sponsored spyware
  • Detection of commercial stalkerware
  • Reports written to be produced in court
  • Air-gapped and on-premise deployment
  • Reporting in the language your organisation works in

Explicitly not enabled

  • Reaching into a third party's device
  • Remote surveillance or interception
  • Offensive tooling of any kind
  • Collection at scale
  • Any use without the device owner's consent
  • Capability beyond defensive proportionality
Procurement

Built for how government actually buys.

Annual licensing aligned to fiscal cycles, documentation prepared in advance, and a deployment model that answers the security question before it is asked.

On your hardware

Runs entirely within your environment, including fully air-gapped installations with no external connection in the path.

Annual, predictable

A standard licence term designed to fit a budget cycle and a multi-year plan.

Documented early

Capability disclosure, scope statement, sample reports and training outline, ready for an RFI or RFP.

Auditable

Every examination leaves a record that can be reviewed later, including by someone who was not present.

Briefing

See it examine a device, then decide.

A briefing includes a live examination, a walk through a real report, and the documentation your legal and procurement teams will ask for.

Enquiries are handled by TSCM Intelligence Agency Ltd. Nothing you write here is shared outside the company.