Cloud and SaaS Collections
Direct-from-source collection from every major cloud platform, with forensic integrity, full chain of custody, and authentication documentation at every step. Powered by GDF's proprietary eCloudDiscovery platform.
What This Solves
Cloud data is not the same as printed documents. A Slack message carries sender, recipient, channel, timestamp, edit history, reactions, and thread context that a simple screenshot cannot preserve. A Teams call might have a recording, a transcript, a chat log, and shared files, all linked by the same meeting ID. Collecting cloud ESI by asking custodians to forward emails or export chats manually introduces authenticity problems that opposing counsel will exploit.
GDF collects cloud and SaaS data directly from the source platform, using authenticated API connections that preserve original metadata in full. The result is a collection that can be traced back to its origin, verified against hash values at every stage, and supported by documentation specific enough to withstand a Daubert challenge or a production completeness dispute.
The eCloudDiscovery Platform
GDF's proprietary eCloudDiscovery platform is a fully functional, forensically sound, secure collection environment built specifically for cloud and SaaS evidence. eCloudDiscovery connects directly to cloud services across email, document storage, collaboration, messaging, and AI applications, collecting all relevant data types while maintaining full chain of custody and authentication from the moment collection begins.
Every collection session through eCloudDiscovery generates a real-time activity log: which service was accessed, under which credentials, at what time, which filters were applied, what data was returned, and what hash values were calculated on the collected output. That log is immutable and becomes part of the matter record. The platform transfers collected data directly to GDF's secure infrastructure, eliminating the manual export and re-import steps that introduce custody gaps in traditional workflows.
eCloudDiscovery supports targeted, filter-based collection, meaning GDF can scope a collection by custodian, date range, keyword, file type, folder location, or any combination the matter requires. Collections are proportional by design. The platform does not pull everything and ask attorneys to sort it out later. It pulls exactly what the scope parameters define, with documentation of those parameters in the collection record.
Supported Platforms
eCloudDiscovery supports direct-source collection from the following platforms:
Microsoft 365
Exchange Online mailboxes (including shared mailboxes and mail-enabled groups), Microsoft Teams messages and meeting recordings, SharePoint document libraries and site collections, OneDrive for Business, Viva Engage (formerly Yammer), and Microsoft To-Do task records. All collections preserve native metadata including thread IDs, reply chains, edit histories, and meeting attendance records.
Google Workspace
Gmail (including all labels, threads, drafts, and deleted items retained in Vault), Google Drive (including Shared Drives, version histories, and permission records), Google Chat messages and spaces, Google Meet recordings and transcripts, and Google Sites content. Collection is performed through the Google Vault and Workspace APIs with audit logging at the account level.
Slack
Public channels, private channels, direct messages, multi-person direct messages, and Slack Connect external communications. Collection includes message text, timestamps, sender information, edit and deletion records, file attachments, emoji reactions, and thread parent-child relationships. GDF collects from Enterprise Grid and standard workspace deployments.
Box
File and folder content, version histories, comments, task records, and collaboration sharing records. Box collections through eCloudDiscovery preserve the original file metadata, upload timestamps, contributor identities, and any access audit logs available at the organizational level.
Zoom
Meeting recordings (video and audio), automated transcripts, in-meeting chat logs, polling records, and whiteboard content. GDF collects Zoom evidence through the Zoom API at the account administrator level, preserving recording metadata including participant lists, join and leave times, and meeting IDs for chain of custody documentation.
AI Collaboration Platforms
Enterprise AI systems are an emerging eDiscovery frontier. GDF supports collection from ChatGPT Enterprise and Google Gemini (Workspace AI) deployments, capturing conversation histories, prompts, responses, and shared outputs available through enterprise-level administrative access. Collection scope and data availability vary by contract and deployment configuration; GDF advises counsel on what is collectible and documents any limitations in the collection record.
Mobile Platforms
For custodians using corporate mobile device management (MDM) environments, GDF can collect cloud-synced mobile data through platform APIs, including iCloud Drive content, Google Workspace data accessed from mobile devices, and collaboration app data synchronized to cloud accounts. For direct device collections, GDF's mobile device forensics team handles physical acquisition.
Our Process
Source Authentication
GDF establishes authenticated connections to each target platform using tenant administrator credentials or delegated service account access. Authentication credentials are documented, and GDF confirms that the access level obtained is sufficient to collect the data within scope. This step produces a Connection Authentication Record for each platform.
Least-Privilege Access Configuration
GDF configures collection access using the minimum permissions required for the specific data in scope. Over-permissioned access is identified and flagged to counsel before collection begins. This limits the organization's exposure and narrows the chain-of-custody documentation to only the data GDF actually accessed.
Targeted Collection with Filters
Collection parameters are applied before data is pulled: custodian accounts, date ranges, keyword or subject filters, file types, and folder paths. eCloudDiscovery executes the collection against these parameters and documents what filters were active during the session. Filters are reviewed and approved by counsel before execution.
Metadata Preservation
All original metadata fields are captured and written alongside the collected content: sender, recipient, date sent, date received, date modified, thread identifiers, file version information, sharing permissions, and platform-specific fields that differ by source. GDF does not flatten or normalize metadata at the collection stage; attorneys and reviewers see the data as it existed in the source system.
Real-Time Logging
eCloudDiscovery maintains a continuous activity log throughout every collection session. The log records each API call, the data returned, the volume collected, and any errors or rate-limit responses encountered. Hash values are calculated on collected data packets in real time. The complete log is archived as a chain-of-custody record.
Direct Transfer to Review
Collected data is transferred directly to GDF's secure processing infrastructure or to the client's designated review platform without intermediate manual handling. Transfer integrity is verified through hash comparison at both origin and destination. A Collection Completion Report documents the final counts, file types, date ranges, and hash values for the entire collection.
Chain of Custody and Forensic Integrity
Every eCloudDiscovery collection produces a Chain of Custody Record that documents the entire lifecycle of the data from source to delivery: who authenticated to the platform, which accounts were accessed, what data was collected, when each step occurred, and what hash values were calculated. This record is structured to support authentication testimony under Federal Rule of Evidence 901(b)(9) for process-authenticated records and to answer the specific questions courts ask when production completeness is challenged.
GDF's analysts can provide declarations or testimony describing the collection methodology, the authentication steps, the platform-specific evidence of data integrity, and the absence of alterations between collection and production. For complex matters, GDF prepares a Collection Methodology Report that describes the technical process in non-technical terms suitable for court submission.
Targeted Collection, Not Bulk Exports
Many providers default to bulk exports: pull everything, then cull. That approach creates proportionality problems, increases processing costs, and creates custody gaps when large exports pass through multiple hands before review. GDF takes a different position. The filter-first approach means that what goes into the collection is already within scope. Volume is lower, processing time is shorter, and the collection record is specific enough that counsel can defend it with confidence.
For matters where scope is genuinely uncertain, GDF can perform a targeted sampling collection first: pulling a representative set of data to inform culling decisions before committing to full collection. That sample is documented the same way as a production collection, so it can be expanded directly into the full collection if the matter requires it.
Deliverables
For each cloud or SaaS collection engagement, GDF delivers:
- Connection Authentication Records for each platform accessed
- Collection Parameter Documentation: the filters, custodians, date ranges, and data types in scope for each collection session
- Real-Time Activity Logs from eCloudDiscovery for each collection session
- Chain of Custody Record: a complete custody document from source authentication through transfer confirmation
- Hash Verification Report: file-level hash values calculated at collection and verified at transfer
- Collection Completion Report: item counts, volume, date ranges, platform breakdown, and any collection limitations or errors
- Collection Methodology Report: a non-technical description of the collection process suitable for court submission or expert disclosure
Last reviewed and updated: April 2026
Microsoft 365 Collections
- Exchange Online, Teams, SharePoint, OneDrive
- Viva Engage, shared mailboxes, mail-enabled groups
- Meeting recordings and transcripts
- Edit histories and deletion records in scope
Google Workspace Collections
- Gmail via Vault API with label and thread preservation
- Drive, Shared Drives, and version histories
- Chat spaces and direct messages
- Meet recordings and Google Sites
Collaboration and Messaging
- Slack: public, private, DM, and Connect workspaces
- Box: files, versions, comments, and task records
- Zoom: recordings, transcripts, and in-meeting chat
- ChatGPT Enterprise and Google Gemini conversation records
eCloudDiscovery Platform
- Proprietary, forensically sound cloud collection environment
- Direct-source API connections: no manual exports
- Real-time activity logging and hash verification
- Filter-first collection to avoid overcollection
Ready to Begin Cloud Collections?
All matters are strictly confidential. GDF can scope and begin a cloud collection engagement quickly for active matters with pending discovery deadlines.
Related Services
Data Discovery and Source Mapping
Before cloud collections begin, GDF maps the full data landscape: tenants, workspaces, SaaS platforms, and shadow IT systems that may be in scope for the matter.
Learn MoreLegal Holds and Preservation
GDF pairs cloud collections with preservation-in-place configurations that protect data from deletion between the hold date and the collection date.
Learn MoreMobile Device Forensics
When cloud collection is not sufficient for mobile data, GDF's forensics team performs physical device acquisitions for iOS and Android platforms under full chain of custody.
Learn MoreCollect Cloud ESI the Right Way
GDF's eCloudDiscovery platform delivers forensically sound, authenticated, directly sourced collections from every major cloud platform. Contact us to begin your engagement.