

Mobile devices create a constant stream of app data evidence. Extraction gets the data out. The next job is understanding what it means, where it came from and whether it can be trusted.
Apps change. Support can break overnight. Even supported apps can produce results that are incomplete or inaccurate.
Firefly gives examiners one workspace to recover, interpret, validate and report app data evidence, with a clear path back to the source.
Decoded output does not always tell the whole story. Firefly helps you examine deleted records, BLOBs, timestamps, sidecars and nested structures across SQLite, RealmDB, LevelDB, IndexedDB and Apple Biome / SEGB, giving you a more complete picture of the evidence.
Every finding traces back to the file, page and byte offset it came from. See how it was recovered. See how it was interpreted. Check it against the raw bytes. The source remains visible throughout the review, so every finding can be verified in context.
Firefly works from hash-verified copies validated with SHA-256. The original evidence is never altered. You can recover, review and report without changing the source.
One workspace for SQLite, RealmDB, LevelDB, IndexedDB and Apple Biome / SEGB. Supported app databases open from the same launcher, so examiners work consistently across every format.


For examiners, investigators, prosecutors and defense teams who need source-backed findings they can stand behind in court.


For forensic teams, eDiscovery examiners, litigation support and counsel who need clear, reviewable app data evidence.


For CID teams, field investigators and intelligence analysts who need fast access to app data findings, activity and location data, with source context.
James Eichbaum
Head of Product & Training
Co-founder
Elusive Data
Register for the launch webinar on August 31, 2026. See the Firefly workspace, the recovery workflow, and how a finding traces back to its source.
Have a question, want to book an early demo, or need to speak with us before launch? Send us a note and we’ll get back to you.
One forensic workspace for app data investigations, built on provenance. It is made for the work that begins after extraction: recovering, interpreting, validating and reporting the data inside the databases modern apps run on.
No. Extraction gets the data off the device. Firefly is what you do with it afterwards. It complements your existing toolkit.
SQLite, including encrypted SQLite, RealmDB, LevelDB and IndexedDB.
It recovers records where the data survives, and shows the mechanism that surfaced each one. Firefly shows its work rather than promising more than the data supports.
Firefly keeps findings connected to their source context, so examiners can explain what was found, where it came from and how it was interpreted.
Pricing and licensing will depend on the team, use case and deployment needs. Contact us at contact@elusivedata.io and we will help you find the right option.
Elusive Data Firefly launches August 31, 2026. Register for the launch webinar above, download the brochure, or contact us at contact@elusivedata.io.