hexmortem · 0x00400420confidentialv24.04 · sha 9f4e…a2c1pgp 0x783E 8C5A
LIVE · incident intake operational pgp 5421 993B … EAB8 0385 lat EU-SW · 42ms tz UTC+01 · AD
uptime 99.98% queue 3 active · 2 pending last note · 2026-05-30
← /usr/bin/services

0x06 · service brief

Subrogation Forensics

Targeted forensic work product supporting insurer recovery against third-party vendors, MSPs, and software suppliers whose failures contributed to the loss. Findings are structured to meet the causation and breach-of-duty standards subrogation counsel must prove, not the operational standards of incident response.

pricefrom €40,000 / recovery action
turnaround4-10 weeks · recovery-window aligned
buyersSubrogation counsel and carrier recovery units pursuing third-party…
Have an artefact in front of you? request scoping →

01what you get

02how to start

Reply with the artefact identifiers you have in hand (hashes, firmware version, advisory ID, or a description of the evidence bundle). We confirm authorisation and scope before any analysis begins. If a deadline is in play, name it — we scope depth against the deadline, not against an internal pipeline.

03scoping intake

Identify the third party in the recovery action (vendor, MSP, software supplier), the loss event, the contractual standard of care in question, and the recovery-window deadline driving the engagement.