The device wrote down who managed it, what was enforced, and since when.
logcat.ai reads it back as a ledger: each entry dated, attributed to the subsystem that recorded it, cited to its line. Where the record stops, the ledger says so.
This is the device's account of itself, read from files you already hold. Acquisition, custody and admissibility stay yours.
The device wrote down who managed it, what was enforced, and since when.
logcat.ai reads it back as a ledger: each entry dated, attributed to the subsystem that recorded it, cited to the line it came from. Where the record stops, the ledger says so instead of filling it in.
The idea: a bugreport is the device's own account of who administered it and what was enforced, entry by entry, so laid out as a custody ledger the gaps become visible.
This is the device's account of itself, read from files you already hold. Acquisition, custody and admissibility stay yours.
The evidence is present and unreadable.
Not missing. Buried in the one file format nobody opens for pleasure.
Management state, policy, installed administrators and account activity are all in there, in different sections, in different shapes, next to a quarter of a million lines that are not about any of it.
Whether a device is enterprise-managed is a provisioning state and an administrator component name, not a sentence. Knowing which field settles it is the expertise the question is blocked on.
One snapshot tells you the current state. The question is almost always what it used to be, which means reading two captures against each other on a timeline that agrees.
Questions with an answer in the file.
Each of these is read out of what the device recorded, and cited back to the line it came from.
Whether it is fully managed, carries a work profile, or is unmanaged, and which management product is responsible. Read from the provisioning state and the enrolled administrators rather than inferred from installed packages.
provisioning state, enrolled administratorsbugreportPassword rules, screen capture restrictions, update policy and the user restrictions in force, as the device has them applied, not as an administrator intended them.
applied policy, user restrictions in forcebugreportFrom a packet capture: who talked to whom, client and server fingerprints derived from encrypted handshakes without decrypting anything, flows periodic enough to be worth a second look, and files reconstructed out of the stream.
flows, the clear part of each handshake, periodicitypacket captureHardware addresses and opaque identifiers resolved to named devices, using the reference tables in the same upload. Anything that cannot be identified is reported as unidentified rather than guessed.
reference tables in the same uploadcapture + tablesTwo captures from the same machine compared on one shared clock, with the differences named. This is the question a single snapshot cannot answer and the one most investigations actually start from.
two captures, one shared clockDelta, A vs BEvery finding carries the evidence it was drawn from, so a conclusion can be checked rather than trusted. An answer the files do not support is reported as unsupported.
every finding aboveany of the aboveHow this reaches you.
Three questions that arrive as an investigation, and what the files settle.
A handset whose history does not match its story. The management state, the enrolled administrators and the recorded activity are read out and dated, so what the device says about itself is on the table.
Policy read from the devices themselves rather than from the console that was supposed to apply it. The gap between intended and applied is the finding.
A bugreport and whatever captures exist from around the time. The investigation reads them together and reports what the evidence supports, including where it runs out.
What this is not.
This reads logs, captures and configuration that already exist. It is not a forensic imaging tool, it does not acquire evidence, it makes no chain-of-custody claim, and it cannot recover what the device never recorded. Where the files do not support a conclusion it says so instead of producing one.
Every attested entry there names a file you uploaded. Nothing on the sheet came from anywhere else, and the one gap was left as a gap.
It reads logs, captures and configuration that already exist. It does not image a device.
not thisNothing is pulled from a device by the platform. You bring the files.
not thisNo claim is made. The ledger is the device's account of itself; custody stays yours.
no claim madeA gap in the record stays a gap. It is reported as not recorded, never filled in.
cannotWhere the evidence runs out, the answer is marked unsupported instead of produced.
refusedFrequently asked questions.
A bugreport answers most management and policy questions on its own. Add a packet capture for the network side, and a second capture from another point in time for anything about change.
1 bugreport, optional pcap, optional second captureYes, and it distinguishes fully managed from a work profile from unmanaged, and names the management product where the device records it. It reads the provisioning state and the enrolled administrators rather than guessing from installed applications.
provisioning state, enrolled administratorsNo. Client and server fingerprints are derived from the parts of a handshake that are sent in the clear, which identifies the software making the connection without touching the encrypted payload.
the clear part of the handshake onlyWe make no such claim. This is an analysis tool over files you already hold: it reads them, cites what it found, and says where the evidence stops. Chain of custody, acquisition and admissibility are yours.
no claim madeYour log data is encrypted in transit (TLS 1.3) and at rest (AES-256), processed in your own tenant, and never used to train AI models. See the architecture page for where data goes and what leaves your environment. Files are deleted after 90 days, or immediately from your dashboard. Enterprise plans offer on-premise deployment for regulated or air-gapped environments.
your tenant, encrypted, 90 daysBring us a device and a question.
A bugreport, and what you are trying to establish. From there we will scope a pilot for your team.