24/7 Emergency Response: 1-800-868-8189
eDiscovery

Remote Acquisition Across Cloud, Mobile and Computer Endpoints

The center of gravity in modern discovery has moved off physical media entirely. Cloud tenants, personal cloud accounts, custodian laptops and mobile devices now hold the majority of responsive material for most matters, and reaching them well requires authenticated remote acquisition that respects rate limits, preserves provenance for authentication challenge, and does not require shipping devices or making an ops trip to the custodian for most scenarios.

What Remote Acquisition Actually Delivers

What You Get What It Means in Practice
Custodian-scoped acquisition against the sources that matter Not bulk tenant exports or wholesale device images (which typically over-collect by an order of magnitude and produce populations that are legally and practically indefensible), but scoped collection against the specific custodians, accounts, devices and content the matter requires.
No shipping devices, no ops trip to the custodian for most scenarios Cloud tenants and personal cloud accounts collect through authenticated APIs. Computers collect agent-based (a small collector run by the custodian or deployed by client IT) or agentless (through the client’s existing management tooling like Intune or Jamf). Mobile devices collect through an agent shipped to the custodian, or through MDM-authorized extraction where the client’s MDM supports it.
Provenance and integrity records for every collected item Hash manifest, API-transaction log or agent-execution log, source-side event correlation where available, and chain-of-custody documentation from the first acquisition call through delivery into review.
Throughput that matches the timeline Queueing, batch handling, retry logic and rate-limit-aware pacing so a large collection completes on schedule rather than timing out on the first source-side backoff.
Native fidelity where the review requires it Emails collected with their full MIME structure, documents collected in native format with metadata preserved, chat collected with reply threading and thread structure intact, mobile content collected with the on-device application-layer artifacts intact, and computer content collected with the specific browser, application and filesystem artifacts the matter requires.
Cross-border-aware collection Where custodians, tenants, personal accounts or devices span jurisdictions with data-localization or blocking-statute considerations, collection is designed to respect those constraints from the first API call.
Cost predictability Collection scoped in the ECA carries a cost estimate the matter can plan against; scope changes carry a change-order record so the client is not surprised.

Sources We Remotely Acquire From

Enterprise cloud tenants (authenticated API)

Platform What We Collect
Microsoft 365 Exchange mailboxes (in-place and delegated), SharePoint sites, OneDrive stores, Teams chat and channels, and the specific compliance-boundary integrations that reach into these workloads.
Google Workspace Gmail, Drive, shared drives, Chat, Meet recordings, and the specific Vault-scoped and Vault-adjacent collection paths.
Slack Workspaces, channels (public and private), DMs, threads, integrations and attached files, with full thread and reply-structure preservation.
Microsoft Teams Team, channel and one-on-one chat, meeting recordings and transcripts, and the SharePoint-backed file storage.
Zoom Meeting recordings, chat transcripts, and the specific compliance-boundary integrations available under the enterprise plans.
Notion, Confluence, Jira Knowledge-management and project-management platforms, scoped to the specific spaces and projects the ECA identifies.
Salesforce, HubSpot and comparable CRMs Object-scoped extraction for the specific accounts, opportunities and activities the matter requires.
Dropbox, Box and comparable file-sync platforms Custodian-scoped and site-scoped collection with full metadata preservation.
Corporate SaaS platforms broadly Where the platform exposes an authenticated API suitable for scoped acquisition, we can typically stand collection up against it inside the ECA window.

Personal cloud accounts (authenticated, custodian-consent-based)

Account Type When It Matters
Personal Gmail and Google Drive Individually-held content in BYOD, HNW estate and internal-review matters.
iCloud iOS device backups, iCloud Drive content, iMessage backups and the specific Apple-service artifacts the matter requires.
WhatsApp cloud backups Google Drive-backed on Android, iCloud-backed on iOS. For messaging content that lives outside the enterprise MDM boundary.
Personal Dropbox, personal OneDrive and comparable individual file-sync accounts Where the custodian’s BYOD posture puts responsive material outside the corporate tenant.

Computers (Windows, macOS, Linux)

Acquisition Method How It Works When to Use
Agent-based A small collector deployed by client IT or run by the custodian under written instruction. Targeted collection of specific content the matter requires (email databases, working documents, browser artifacts, application data, or full logical images where warranted).
Agentless Through the client’s existing management tooling (Microsoft Intune, Jamf Pro, other MDM/UEM platforms). Where the tooling supports the required content classes and the client prefers not to deploy a separate agent.

Both approaches preserve full provenance and chain of custody, so the choice is driven by client preference and IT posture rather than by evidentiary constraint.

Mobile devices (iOS and Android)

Acquisition Method How It Works Typical Scenario
Custodian-consent-based An agent shipped to the custodian, executed under written instruction and returned once the collection is complete. Hostile-witness or fragile-relationship matters; cross-border custodians; matters where an ops trip to the custodian is not viable.
MDM-authorized Through the client’s MDM (Intune, Jamf, Workspace ONE, etc.) where the MDM supports the required content classes. Broad corporate matters with cooperative custodians on managed corporate devices.
Mixed A combination of consent-based and MDM-authorized acquisition scoped per custodian. Matters spanning both patterns (some custodians on managed devices, some on BYOD or unmanaged).

How Remote Acquisition Actually Works

  1. Authenticated access arranged through the appropriate path for each source: tenant administrator for enterprise cloud, custodian consent for personal cloud accounts, client IT for computer agent deployment or MDM-based acquisition, and shipped-agent or MDM path for mobile devices. Permission scopes are documented and revocable at the end of the engagement.
  2. Scoped acquisition plan anchored on the ECA output: which custodians, which sources, which content types, which date ranges, which specific tenants, accounts, computers or devices.
  3. Coordinated collection execution across the in-scope sources concurrently, with the platform’s queueing and retry logic handling source-side rate limits, transient errors and the throughput profile of each source class.
  4. Provenance capture for every collected item: hash, timestamp, source path or device identifier, source-side unique identifier, API-transaction or agent-execution record, and source-side event correlation where available.
  5. Chain-of-custody documentation from acquisition through processing and into review, structured to survive authentication challenge for both API-collected and agent-collected content.
  6. Delivery into the review environment, whether that is our in-house CompleteDiscovery workspace, a Relativity, Reveal or Nuix instance for enterprise-scale matters, or a client-managed review environment.

Our In-House Remote Acquisition Platform

Remote acquisition is where our in-house platform earns its keep. eCloudDiscovery is the collection product our team built and operates for exactly this work: authenticated remote acquisition across cloud tenants (Microsoft 365, Google Workspace, Slack and comparable platforms), personal cloud accounts (Gmail, iCloud, WhatsApp cloud backups, personal Google Drive and Dropbox), computers (Windows, macOS, Linux, agent-based or agentless via the client’s existing management tooling), and mobile devices (via an agent shipped to the custodian or through MDM-authorized extraction, depending on the scenario), with the queueing, batch handling, retry logic and provenance-preservation features that survive throwing a real production workload at them. For larger matters, the collected populations move into Relativity, Reveal or Nuix for hosted review; smaller matters and rapid-turn projects run through review on CompleteDiscovery.

Cross-Border and Bilingual Collections

Our Miami practice runs a substantial share of matters that reach across the South Florida gateway to Latin America. Cross-border collection carries specific technical and legal wrinkles: tenants hosted in the receiving jurisdiction rather than the US, data-localization frameworks that shape what can leave the jurisdiction and how, blocking statutes that require coordination with local counsel, and content in Spanish and Portuguese that has to be preserved with its source-language integrity intact through processing and review.

Remote acquisition is particularly valuable in this posture. Shipping laptops or mobile devices across international borders introduces customs, data-transfer and evidentiary complications that many matters cannot absorb, and an ops trip to each LATAM site is often infeasible on the matter’s timeline. Authenticated remote acquisition against LATAM-hosted tenants, agent-based remote acquisition of in-country computers, and shipped-agent mobile acquisition performed on-device at the custodian’s location produce the collection without moving devices across the border. Local-counsel coordination on the applicable data-transfer framework runs concurrently, and source-language content is preserved verbatim so the review team is working with the original evidence rather than a translation.

Where Our Miami Remote-Acquisition Practice Runs Deepest

Cross-border matters (US parent + LATAM subsidiary)

The most common shape of a cross-border collection for our Miami practice: US-headquartered holding company with operating subsidiaries in Colombia, Brazil, Mexico, Venezuela, the Dominican Republic or Chile. Collection scoped and executed across all in-scope tenants concurrently, with bilingual preservation and local-counsel coordination.

Financial services, banking and MSB matters

Cross-border correspondent-banking matters, MSB regulatory examinations that overlap with active litigation, and financial-services matters where the collection reaches into compliance-critical systems.

Construction, maritime and land-use matters

Project-management platforms (Procore, Autodesk, PlanGrid), engineering-team SharePoint patterns, and the specific messaging and communication patterns construction and engineering teams actually use.

Fintech, crypto and digital-asset matters

The Miami digital-asset cluster relies heavily on Slack, Notion, Discord, Telegram and specialized trading and compliance platforms. Collection scoped to the specific platforms in play for each matter.

Corporate internal-review and regulatory matters

Scoped collection for internal reviews and regulatory examinations, where the internal audience needs the record but the scope has to stay narrow to avoid unnecessary exposure.

Standards and Standing

Methodology anchored on the EDRM, the Sedona Conference principles, ISO/IEC 27037 guidelines for identification, collection, acquisition and preservation of digital evidence, NIST SP 800-101 for mobile device forensics, and the specific platform-vendor guidance for defensible collection from each source class. Collectors hold digital-forensics credentials (SANS GCFE, GCFA), eDiscovery credentials (Relativity RCA/RCU, ACEDS CEDS) and, for cross-border matters, working relationships with Latin American local counsel on the applicable data-transfer frameworks. Records are structured for authentication under Fla. Stat. § 90.901 and Federal Rules of Evidence 902(13) and 902(14).

Last updated: September 4, 2026

Collect Well, Or Collect Twice

Remote acquisition done well produces a defensible record on the timeline the matter needs, without shipping devices or making an ops trip for most scenarios. Done badly, it produces a population that has to be re-collected under worse conditions, often after the source-side retention window has already closed some of the material.

Remote Acquisition Built for Real Production Workloads

Cloud tenants, personal cloud accounts, computers and mobile devices. Scoped acquisition, provenance preservation, cross-border awareness and enough throughput to complete on schedule, without shipping devices for most scenarios.