FAQ
Questions practitioners ask about AI activity evidence.
Direct answers for forensic, eDiscovery, incident-response and legal teams.
What is AI Activity Evidence?+
It is observable evidence of how AI services, assistants and coding agents were used. Qavryn presents available records for professional review; it does not decide what those records mean.
Can Qavryn examine ChatGPT, Claude and Gemini activity?+
Qavryn covers these named services when relevant evidence exists in the acquired scope. Available output depends on the source material provided for examination.
Can Qavryn examine coding-agent activity?+
Qavryn covers OpenAI Codex CLI, Claude Code, Cursor, GitHub Copilot, Windsurf, Cline / Roo Code, Continue.dev and Gemini CLI at the name level.
Which acquisition formats are accepted?+
Qavryn accepts directory trees, ZIP and TAR archives, Cellebrite UFDR/UFD/UFDX, Magnet AXIOM Case.mfdb, raw and E01 disk images, and supported VM disk formats.
Does Qavryn modify evidence?+
No. Qavryn operates read-only against acquired evidence. The examiner remains responsible for preserving and assessing the material.
Is anything uploaded to the cloud?+
No. Qavryn is designed to run offline, with no cloud processing, telemetry or outbound network activity during a scan.
What does the output look like?+
Depending on the available evidence, Qavryn provides review-ready, source-linked records with sessions, prompts and responses, tool calls, terminal commands, agent activity and timeline placement.
Can Qavryn work with existing review platforms?+
Yes. Qavryn is a complementary layer and can provide JSON, CSV, HTML report, chain-of-custody manifest and eligible RSMF export for downstream workflows.
What if a source is absent?+
An absent or incomplete source is a scope condition. It is not proof that the relevant AI service or coding agent was not used.
Who interprets the findings?+
A qualified examiner interprets the observed records. Qavryn does not infer intent, guilt, relevance or completeness.
How does licensing work?+
Qavryn discusses per-examiner, per-lab and evaluation models according to the team’s needs.
How can I run an evaluation?+
Contact Qavryn with the workflow and acquisition types you need to assess. The evaluation conversation begins with the evidence question, not a generic demo.
A focused conversation
Bring the AI-evidence question your team needs to answer.
We begin with your acquisition scope, review workflow and required deliverable.
Contact Qavryn →
Start a conversation