Home » Blogs » What Does “Defensible” Actually Mean in Digital Forensics? – Podcast Recap Blog
What Does “Defensible” Actually Mean in Digital Forensics?
July 21, 2026

If you work in eDiscovery, you’ve said the word “defensible” more times than you can count. It shows up in every proposal, every declaration, every conversation with opposing counsel. And according to Steve Davis, VP of Forensics and Investigations at Purpose Legal, it’s also one of the most misunderstood terms in the industry.

In the latest episode of In Discovery Mode, Steve Davis joins Matt Rasmussen to unpack what defensibility actually requires now that phones, not laptops or email, are where most of the relevant data lives.

The old math doesn’t work the same way anymore

For years, defensibility had a clean answer: image the whole device bit by bit, generate a hash value, and you had mathematical proof of exactly what you collected, before and after. Steve points out that the underlying assumption, that everything is provable in absolute terms, has broken down as data has exploded from gigabytes to terabytes and petabytes.

Structured data, like a text message thread or an app database, doesn’t hash the same way a static image does. As Matt explains it, if you hash a phone’s text message database and then someone sends a new text five minutes later, that hash changes. The old “one hash proves it all” model doesn’t hold up on a device that’s constantly changing.

That doesn’t mean the standard gets lower. It means the process has to do more work: reliable, repeatable chain of custody, tool validation, and documentation that can survive a challenge from a regulator or opposing counsel.

Full device imaging isn’t automatically the safer choice

There’s a common assumption that collecting everything is the conservative, defensible move, and that targeted collection is the risky shortcut. Steve and Matt push back on that directly.

Every phone collected in full brings privacy exposure with it. Photos, banking apps, location history, none of it necessarily relevant to the matter, all of it now sitting under a party’s custody and control. Matt’s read: if a custodian says they never discussed a matter over email, no one takes that at face value, they still run search terms against the account. Phones deserve the same rigor, not a blanket “collect it all and sort later” approach that creates more privacy risk and more cost without actually making the collection more defensible.

The tweezer or the sledgehammer

Steve frames the decision as choosing between a tweezer and a sledgehammer, and says you can’t choose the right tool until you’ve answered three questions: what type of data are you actually looking for, where does it live (on the device, synced to the cloud, synced again to a second device), and only then, which tool fits the job.

Matt walks through the same framework from the legal team’s side: understand the data type you need, understand where it resides, then decide on the collection method. Sometimes that’s a full file system dump. Sometimes, as he puts it, a small property dispute over a tree line only needs a screenshot. Most matters land somewhere in between, and that’s where a targeted, defensible approach earns its keep.

Phones are now a required part of federal investigations

One of the more striking data points in the episode: Matt says that in conversations with DOJ, the answer is now 100 percent, phones are required in federal investigations. That shift changes what “we didn’t think to look at the phone” costs a legal team. It also raises the stakes on device preservation.

Steve and Matt both flag a scenario that comes up more than people expect: an employee leaves, their phone gets a Post it note and gets set in a storeroom instead of properly preserved, and 30 or 45 days later, MDM disables access and the device is locked. What used to be a shrug and an apology to opposing counsel can now look like spoliation.

The takeaway

Defensibility isn’t a checkbox and it isn’t a synonym for “collected everything.” It’s a repeatable, documented, validated process that can answer hard questions after the fact, not just at the time of collection. As Steve puts it, most of the work is in the preparation, understanding where data lives, who the custodians are, and what timeframe matters, before you ever decide which tool to use.

Watch the full episode of In Discovery Mode for the complete conversation, including Steve’s take on empirical tool testing and why “collect it all” can actually work against you in front of a judge.

About Our Guest, Steve Davis
For the past 30+ years, Steve Davis has performed and supervised hundreds of investigations on behalf of governmental agencies, corporations and law firms involving civil and criminal matters. Steve is a Licensed Private Investigator in the State of Texas and the VP of Forensics & Investigations for Purpose Legal. He has testified on behalf of his clients on over 50 occasions relating to investigative findings on causation, damages and forensics.

About Purpose Legal
Purpose Legal is a global legal services and technology provider built for high-stakes, data-intensive matters where accuracy, speed, and defensibility are of paramount importance. Through its PurposeXi™ platform, the company combines purpose-built AI with deep litigation, review, and forensic proficiency to deliver expert-validated intelligence that legal teams can trust. We pair powerful technology with experienced practitioners who ensure insight turns into action. Founded in 2007, Purpose Legal is a leader in eDiscovery, digital forensics, document review, flexible legal staffing, and legal technology services. In 2025, it was recognized for the third time as one of the Inc. 5000’s fastest-growing private companies in America. Our diverse team of experienced, talented, and motivated professionals is our greatest asset. We assist multinational corporations, law firms, and government entities through best-in-breed software, powerful AI tools, creative managed services solutions, and deep industry knowledge. Learn more at www.purposelegal.io.