Structured Data and Database Discovery
Forensic analysis and defensible extraction from enterprise databases, ERP systems, CRM platforms, and financial applications. Schema-aware methodology that preserves context, relationships, and meaning.
What This Solves
Your opposing party runs SAP. The relevant data is not in a folder or an email thread. It lives across dozens of tables, linked by foreign keys, filtered by application logic, and displayed to users through views that assemble records on the fly. A simple export of those tables gives you raw field values with no context. The numbers don't make sense without the schema, and the schema doesn't make sense without knowing which stored procedures assembled the report your client relied on.
This is the problem structured data discovery addresses. When litigation involves an ERP system, a financial database, a healthcare record platform, or a custom CRM, collecting the relevant data requires understanding the system before writing a single query. GDF's forensic analysts work directly with your database team, application vendors, and technical stakeholders to extract exactly what the matter requires, in a form reviewers can actually use, with a methodology that survives challenge.
Why Databases Cannot Be Treated Like Files
The Sedona Conference has addressed structured data handling directly, noting that databases present unique challenges that standard document collection workflows do not resolve. A single "document" in an ERP system may span ten tables. A sales transaction record in Oracle, for example, pulls from the customer master, the item catalog, the pricing engine, the warehouse allocation tables, and the accounts receivable ledger before any report is generated. Export the raw tables without that context and you have data, but not information.
Several other problems make database discovery genuinely different from file or email collection:
- Field labels in one system may have completely different meaning in another deployment of the same software, because implementations customize field names and repurpose columns.
- Deleted records often leave artifacts in audit tables, change logs, or transaction journals, but those artifacts are only accessible if you know to look for them.
- Calculated fields, derived values, and report summaries exist only at query time. They cannot be "collected" as a static file; the query logic must be preserved and reproduced.
- Multi-tenant and multi-company configurations mean that data from different business units shares tables but is separated only by a company code or tenant identifier, which must be scoped correctly in every extraction query.
GDF's database forensics practice is built around these realities. Every engagement begins with understanding the system architecture, not with running queries.
Enterprise Systems We Support
GDF has performed structured data analysis and forensic extraction from a wide range of enterprise platforms. Each requires a different approach based on its data model, access controls, and application logic.
- Oracle E-Business Suite and Oracle Database: Financial ledgers, supply chain modules, HR records, and custom application schemas. GDF handles multi-org configurations and identifies relevant audit trail tables including FND_LOGINS and audit change tracking.
- SAP ERP (ECC, S/4HANA): Complex table structures including BKPF/BSEG for financial postings, VBAK/VBAP for sales orders, and change document tables (CDHDR/CDPOS) that record field-level modifications with timestamps and user IDs.
- Salesforce: Object-level data including standard and custom objects, field history tracking tables, and the audit trail that logs administrative changes. GDF collects via the Salesforce API with metadata preservation, not manual CSV export.
- NetSuite: Saved search outputs, transaction records across multiple subsidiaries, and the audit trail log that captures who changed what and when across the entire tenant.
- Workday: HR, payroll, and financial data with full awareness of effective dating and supervisory organization structures that affect how records relate to each other.
- PeopleSoft (Oracle): HR and financial modules with component-level audit logging, effective-dated rows, and the PeopleTools architecture that separates application data from system configuration.
- Epic and Cerner (healthcare): Electronic health record data, audit logs, access history, medication administration records, and the clinical documentation that supports medical malpractice, employment, and regulatory matters.
- Custom SQL databases: Microsoft SQL Server, PostgreSQL, MySQL, and other relational platforms, including legacy applications built on proprietary schemas with limited documentation.
GDF's Structured Data Analysis Process
Schema Analysis and System Documentation
GDF's analysts map the relevant database schema: table structures, primary and foreign key relationships, index definitions, views, stored procedures, and triggers. This phase produces a written schema summary that documents what data exists, how it is organized, and what queries will be needed to extract it in meaningful form. For systems with poor documentation, GDF conducts direct schema exploration and records findings before any extraction begins.
Stakeholder Interviews and Scope Definition
Technical interviews with database administrators, application owners, and business users establish what data fields are relevant, how users actually interact with the system, and which reports or outputs were relied upon in the transactions at issue. This step is critical: the people who use the system daily know things about field semantics, data entry conventions, and workflow that no documentation captures.
Query Design and Validation
GDF drafts targeted extraction queries with date range filters, custodian or user scoping, and record type parameters tied to the matter's scope. Each query is tested against a non-production copy or a limited subset of data before full execution. The query logic is documented in writing and reviewed with counsel, because the methodology itself may be subject to challenge and must be explainable in deposition or declaration.
Reproducible Extraction with Chain of Custody
The extraction is executed with full logging: timestamp of execution, database version, query text, row counts, and hash values of the exported output files. All extraction activity is performed under least-privilege read-only access to avoid any modification of the source data. Chain-of-custody documentation is generated at the time of extraction and maintained through delivery.
Normalization into Reviewer-Friendly Output
Raw table exports are normalized into human-readable formats with column headers that match the application's user-facing field labels, not cryptic internal column names. Coded values are decoded using the system's reference tables. Related records from multiple tables are joined into a single output that reviewers can understand without a database administrator present. GDF delivers outputs in Excel, CSV, PDF, load-file format for review platforms, or any format specified by counsel.
Expert Documentation and Reporting
GDF produces a written methodology report documenting the schema analysis, query design decisions, validation steps, and extraction results. This report supports meet-and-confer discussions under Rule 26(f), responds to opposing party challenges, and provides the foundation for expert declaration or testimony if the collection methodology is disputed.
Defensibility and Chain of Custody
Courts have scrutinized database extraction methodology in discovery disputes. The producing party must be able to explain, with specificity, what data was collected, how the queries were constructed, what filtering criteria were applied, and whether the output accurately represents what the system contains. GDF's structured data engagements are designed to answer each of those questions in writing, before a challenge arises.
Every extraction includes: read-only database access with session logging; hash verification of output files at time of extraction; a signed chain-of-custody log recording every analyst who touched the data; and a query log that can be rerun to produce an identical output, confirming reproducibility. When damages calculations or financial analyses depend on database records, GDF's approach also documents the mathematical relationship between the raw data and any derived figures so that opposing experts can audit the work.
What GDF Delivers
- Schema analysis report with table relationship diagrams
- Written extraction methodology document, suitable for disclosure to opposing counsel
- Normalized data exports in review-ready format with decoded field labels
- Full query log with timestamps, row counts, and hash values
- Chain-of-custody documentation covering the entire extraction process
- Expert declaration or affidavit on collection methodology, if required
- Deposition and trial testimony on database analysis findings
Last reviewed and updated: April 2026
ERP and Financial Systems
- Oracle E-Business Suite
- SAP ECC and S/4HANA
- NetSuite multi-subsidiary
- Custom accounting databases
CRM and HR Platforms
- Salesforce (API collection)
- Workday HR and payroll
- PeopleSoft HCM
- Custom CRM schemas
Healthcare Record Systems
- Epic EHR
- Cerner (Oracle Health)
- Audit access logs
- Medication administration records
Custom and Legacy Databases
- Microsoft SQL Server
- PostgreSQL and MySQL
- Oracle Database (direct)
- Undocumented legacy schemas
Database Discovery Consultation
All consultations are strictly confidential. GDF's structured data team handles complex extraction under tight litigation timelines nationwide.
Related Services
Data Discovery and Source Mapping
Identify every repository holding potentially relevant data before collection begins, including shadow databases, regional tenants, and enterprise application data stores.
Learn MoreCloud and SaaS Collections
Direct-source collection from Microsoft 365, Google Workspace, Salesforce, Slack, and other cloud platforms with full metadata preservation and chain of custody.
Learn MoreEarly Case Intelligence and Culling
Analytics, deduplication, and communications mapping to reduce review volume and focus attorney attention on the records that actually matter.
Learn MoreRelevant Data Living in a Database?
GDF's structured data team combines database expertise with forensic methodology to extract, normalize, and deliver what the matter requires. Contact us to discuss your database discovery needs.