Compare and coverage

What each product does, and how we stand next to the leaders.

What every product in the range delivers, every file system, format and device the engine handles, then a source-checked comparison with the products a laboratory would otherwise buy, in both families. Their side is their own published page, read in September 2026; ours is measured on the build. Where they are ahead, it says so, in the same type size as where we are.

What each product does

Eight products, each built for its job.

Every list below is generated from the catalogue the products are built from, so a card cannot name a workspace the build does not contain. The products are not alternatives to each other: a recovery lab buys the jobs it does, and each product is complete for its own.

RecoverYantra

RecoverYantra Suite

The complete recovery range in one application

Built for Recovery labs, service providers and IT departments that handle every category of case and cannot choose their tools in advance.

19 things it does

  • Recover files from disks, cards and images
  • Ransomware triage and recovery
  • Database row extraction
  • Mailbox recovery (Outlook PST/OST, mbox, Maildir)
  • Image a failing drive
  • Phone acquisition and data recovery
  • CCTV and DVR footage
  • Image a drive over the network
  • Bootable rescue USB
  • Cloud account recovery
  • Repair broken video
  • Secure erase and certificate
  • Detect every connected device, with a report
  • Drone flight log and video telemetry recovery
  • RAID and storage-pool reassembly
  • Chip-off and rig-dump reconstruction
  • Industrial robot and controller incident data
  • Vehicle data recovery
  • Browse the index and extract ticked files and folders
Licence key, sold by the driveExplore Suite
RecoverYantra

RecoverYantra Imager

Check the drive, copy it safely, take the files you need

Built for Technicians and IT staff who image drives and phones before recovery or examination, anyone deciding whether a drive is worth sending to a lab, and anyone who needs one file or folder back without a full recovery.

4 things it does

  • Image a failing drive
  • Create a phone image
  • Detect every connected device, with a report
  • Browse the index and extract ticked files and folders
Free for everyone, no licence keyExplore Imager
RecoverYantra

RecoverYantra Mobile

Get the data off the phone

Built for Data-recovery labs and shops handling phones - locked, dead or with the owner's consent - that need the files off, not a report.

3 things it does

  • Phone acquisition and data recovery
  • Create a phone image
  • Detect every connected device, with a report
Licence key, sold by the driveExplore Mobile
RecoverYantra

RecoverYantra Wipe

Drive sanitisation with verification and certificate

Built for IT teams and organisations that must retire storage with a record proving it was cleared.

1 things it does

  • Secure erase and certificate
Licence key, sold by the driveExplore Wipe
SakshyaYantra

SakshyaYantra Examiner

The computer-forensics bench

Built for Computer-forensics examiners and digital-forensics laboratories - the bench a lab would otherwise run on EnCase, FTK or X-Ways.

24 things it does

  • Recover files from disks, cards and images
  • Database row extraction
  • Mailbox recovery (Outlook PST/OST, mbox, Maildir)
  • Image a failing drive
  • Forensic examination and reporting
  • Detect every connected device, with a report
  • Drone flight log and video telemetry recovery
  • RAID and storage-pool reassembly
  • Chip-off and rig-dump reconstruction
  • Industrial robot and controller incident data
  • Vehicle data recovery
  • Case hub: cases, versions and locks
  • Ask the case (AI observations after a sealed reading)
  • Cross-case lookup
  • Known-file hash sets
  • Foreign image and dump ingest
  • Indexed keyword search
  • Link analysis
  • Memory (RAM) analysis
  • Steganalysis
  • Timeline across artefacts
  • Evidence viewer
  • YARA scanning
  • Browse the index and extract ticked files and folders
Licence key, sold by the driveExplore Examiner
SakshyaYantra

SakshyaYantra Media

Video and image evidence, examined

Built for CCTV and video examiners, image-authenticity analysts and forensic media laboratories - the work a lab would otherwise take to Amped.

19 things it does

  • Image a failing drive
  • CCTV and DVR footage
  • Forensic examination and reporting
  • Detect every connected device, with a report
  • Image and video authenticity examination
  • Case hub: cases, versions and locks
  • Ask the case (AI observations after a sealed reading)
  • Cross-case lookup
  • Evidence export and the draft S.63(4) certificate
  • Footage intake, decode and conversion
  • Media gallery triage
  • Location data
  • Foreign image and dump ingest
  • Media enhancement lab, chain shown
  • Number-plate assistance
  • Recorder registry and intake
  • Redaction under review
  • Frame-exact video review
  • Evidence viewer
Licence key, sold by the driveExplore Media
SakshyaYantra

SakshyaYantra Mobile

Acquire the phone as evidence

Built for Examiners and forensic laboratories acquiring mobile evidence, from a police unit to an enterprise investigation.

10 things it does

  • Phone acquisition and data recovery
  • Create a phone image
  • Forensic examination and reporting
  • Detect every connected device, with a report
  • Case hub: cases, versions and locks
  • Ask the case (AI observations after a sealed reading)
  • Cross-case lookup
  • Foreign image and dump ingest
  • Steganalysis
  • Evidence viewer
Licence key, sold by the driveExplore Mobile
SakshyaYantra

SakshyaYantra Enterprise

Evidence, from the disk to the courtroom

Built for Examiners, investigators, incident response teams and forensic laboratories - from a single case to an organisation-wide estate.

39 things it does

  • Recover files from disks, cards and images
  • Database row extraction
  • Mailbox recovery (Outlook PST/OST, mbox, Maildir)
  • Image a failing drive
  • Phone acquisition and data recovery
  • Create a phone image
  • CCTV and DVR footage
  • Image a drive over the network
  • Cloud account recovery
  • Forensic examination and reporting
  • Detect every connected device, with a report
  • Drone flight log and video telemetry recovery
  • RAID and storage-pool reassembly
  • Chip-off and rig-dump reconstruction
  • Industrial robot and controller incident data
  • Vehicle data recovery
  • Image and video authenticity examination
  • Case hub: cases, versions and locks
  • Ask the case (AI observations after a sealed reading)
  • Cross-case lookup
  • Evidence export and the draft S.63(4) certificate
  • Footage intake, decode and conversion
  • Media gallery triage
  • Location data
  • Known-file hash sets
  • Foreign image and dump ingest
  • Indexed keyword search
  • Link analysis
  • Media enhancement lab, chain shown
  • Memory (RAM) analysis
  • Number-plate assistance
  • Recorder registry and intake
  • Redaction under review
  • Frame-exact video review
  • Steganalysis
  • Timeline across artefacts
  • Evidence viewer
  • YARA scanning
  • Browse the index and extract ticked files and folders
Licence key, sold by the driveExplore Enterprise
Where we are ahead

The advantages, each with its basis.

A claim with no basis is advertising. Each card names the test, the module or the document a reader can check.

Byte-exact where it can be checked, flagged where it cannot

A recovered file whose format the engine can check is identical to the original or it is flagged with the reason. A deleted file whose space was reused is flagged instead of handed back under the right name with the wrong bytes, a video or archive that will not open is graded as such, and a format with no signature in the database is returned marked unverified rather than judged.

Basis. Measured at 100 percent recall and precision, byte-exact, on our own test corpora: a 20-file base set, a 23-file stress set and 6 real media files. Those are small synthetic and specimen sets, not a guarantee for every drive. A content, media and archive check is applied to every recovered file whose format it can judge. In our source-checked comparison, neither recovery leader's page describes a content check.

Two families from one engine, one executable

Eight products are built from one tested core. The recovery products ship as a single standard-library Windows executable with no runtime and no packages to install, so a bench with no internet and no administrator on call still runs them.

Basis. One catalogue defines every product, and each build is verified in a clean environment to contain only its own workspaces. The recovery products carry no third-party runtime at all — a single Windows executable.

The Imager is free for everyone

Checking a drive with a feasibility verdict, imaging it to raw or E01, browsing its index and taking the files you tick, and ingesting a dump a chip-off or JTAG rig produced: no key, no gate, no use spent, ever.

Basis. The Imager needs no key and spends no use, and drive imaging, index browsing, file-level extraction and chip-off/JTAG dump ingest all ship in it. Neither R-Studio nor UFS Explorer publishes a free imaging edition with extraction.

Breadth of sources in one product

22 file systems by name, RAID 0/1/3/4/5/6/1E and nested 10/50/60 with automatic parameters, RAID-Z and Synology SHR, five virtual-disk formats, E01, Ex01 and AFF4 containers, recorder disks camera by camera, drone logs, phones, mailboxes, database rows and chip-off dumps, in the same application.

Basis. Every file system, RAID level, virtual-disk and evidence-container format listed here is implemented and tested in the product, and the coverage tables on this page are generated from that same engine — not a claim written by hand.

Court-defensible by construction

A hash-chained audit trail that names the first altered line, read-only measured before and after a job, the examiner's reading sealed before any model answers, the frame pack as the only unit that leaves the machine, and a draft certificate under Section 63(4) of the Bharatiya Sakshya Adhiniyam 2023.

Basis. The hash-chained audit trail, the read-only measurement taken before and after a job and the examiner's reading sealed before any model answers are all in the product and tested. In our comparison, none of EnCase, FTK, AXIOM or X-Ways documents a sealed prior reading or an S.63(4) certificate.

Offline, machine-bound licensing, sold by the drive

A key is signed offline for one machine code and one product. A use is one drive or image, however many files come off it, and the same source is free for ever after. No account, no activation server, no update check.

Basis. Licensing is offline and bound to one machine code. Our tests prove that no product opens a connection back to us, and that a key opens only the one product it was sold for.

Outbound connections blocked by default

Every product refuses public-internet connections at the socket layer, from bundled libraries as well as our own code. Loopback and the local network are allowed. The exceptions are named and operator-controlled: a model provider only after the operator turns it on, and cloud collection from the organisation's own tenant under a stated authority; specific public destinations can be allow-listed, off by default.

Basis. Outbound public-internet connections are refused at the socket layer, from bundled libraries as well as our own code, with loopback and the local network still allowed. The policy is covered by our own adversarial test round and a regression test; no third-party audit report exists yet.

The limits are stated, in the product and here

A drive that will not read says which link in the chain is broken. A locked phone with no public vector says which method would reach it. This site carries a section on where the category leaders are ahead of us, in the same type size as the rest.

Basis. A drive that will not read names the broken link in the chain; a locked phone with no public route names the method that would reach it. Our comparison reproduces where the category leaders are ahead of us, and /llms.txt lists what the products will not do.

Coverage in detail

File systems, formats and artefacts

The tables below list what the engine reads. Where a route to the data does not exist, it is stated here rather than discovered after purchase.

File systems

WindowsNTFS (compressed files and alternate data streams included), exFAT, FAT12/16/32, ReFS (names, folders and contents)
Linux and Unixext2/3/4, XFS, F2FS, Btrfs (single device), ZFS (single vdev, RAID-Z1/2/3), UFS, JFS, ReiserFS, LVM2, ISO 9660, UDF
VMware and OS/2VMFS (ESXi datastores), HPFS. Novell NSS is identified but not read file by file
AppleAPFS (compressed files included), HFS+
VolumesMBR and GPT partitions, Storage Spaces, LDM, spare-copy fallback (backup boot sectors, $MFTMirr, backup superblocks)

File types carved

Photos and RAWJPEG, PNG, GIF, BMP, TIFF, HEIC, WEBP, and camera RAW (CR2, CR3, NEF, ARW, DNG, RAF, RW2, ORF)
VideoMP4, MOV, HEVC, MKV, AVI, FLV, WEBM (sized from the index, never the mdat header)
AudioMP3, AAC, FLAC, WAV, OGG, CAF, AU (frame-chain validated)
DocumentsPDF, DOCX, XLSX, PPTX, ODT, ODS, ODP, RTF
Archives and moreZIP (streamed writers included), RAR, 7Z, GZIP, SQLite, plus signatures you teach it from a sample
Text and keysNotes, source, PEM keys and wallet phrases that have no magic number

Storage, arrays and virtual

RAID0, 1, 4, 5, 6, 1E, nested 10, 50, 60, JBOD, RAID-Z, with automatic parameter detection and DDF or vendor controller metadata where present
NASSynology SHR, QNAP and other Linux-md and LVM arrays
Virtual disksVMDK (VMware), VHD and VHDX (Hyper-V), VDI (VirtualBox), QCOW2 (QEMU)
Images and containersdd, img, iso, E01, Ex01 and AFF4 read; raw and E01 written, hashed on read and verified after write

Encryption opened, with the credential

WindowsBitLocker (password and recovery key), AES-XTS
LinuxLUKS1 and LUKS2 (PBKDF2 and Argon2id keyslots)
AppleFileVault 2, APFS encryption
Cross-platformVeraCrypt
The limitCorrectly implemented AES-256 with a key you do not have cannot be broken by anyone, and the product says so

Databases and mail

RelationalMySQL / InnoDB, MariaDB, SQL Server (MDF), PostgreSQL, Oracle, Access, SQLite (deleted rows via WAL included)
NoSQL and modernMongoDB (BSON), Redis (RDB), and other document and key-value stores
MailOutlook PST and OST (healthy read, then salvage of a damaged store), Exchange EDB at table level, mbox, Maildir, EML

Devices and sources

DrivesHDD, SSD, NVMe, USB, external, SD and microSD. Every device the operating system can see is listed, with the reason when it cannot be read
PhonesAndroid and iOS: the file system, logical and, where a public method reaches the device, physical, with deleted SQLite records
RecordersCCTV and DVR (Hikvision and Dahua tables, otherwise inferred cameras)
ChipsA dump a chip-off or JTAG rig produced, reconstructed into a mountable image

Forensic artefacts

WindowsRecycle Bin, USN journal, prefetch, registry, LNK, event logs, jump lists, ShellBags, AmCache, SRUM
macOSplists, DS_Store, FSEvents
BrowsersChrome and Firefox history and downloads
MemoryProcesses, sockets, modules, handles and injected code from a RAM capture
Data recovery

The recovery family next to the recovery leaders.

RecoverYantra (Suite, Imager, Mobile and Wipe) against R-Studio and UFS Explorer Professional, recovery tools only. On the classic core the three are peers; the family is on its own in what happens around the recovery.

We do it, they do not or only partlyBoth, or both partlyThey are ahead
vs R-StudioRecovery software
9 we lead5 match2 they lead
vs UFS Explorer ProfessionalRecovery software
10 we lead6 match0 they lead

Counted from the 16 capabilities in the table below. Where a leader is ahead it is amber, kept in at the same weight.

CapabilityRecoverYantraThe recovery familyR-StudioRecovery softwareUFS Explorer ProfessionalRecovery software
Browse the index first; recover only what is tickedYessaving stated in numbersYespreviewer before recoveryYesbrowse, preview, copy
Recovery chance shown before extractionYesallocation table and first bytesYesestimation documentedNot found
File systems read by name and folderYes22: NTFS, FAT12, FAT16, FAT32, exFAT, ext2, ext3, ext4, HFS+, APFS, F2FS, XFS, Btrfs, ZFS, ReFS, UFS, ISO 9660, UDF, JFS, ReiserFS, HPFS, VMFSYesa wide list on its pageYeswidest list on its page; adds Novell NSS, which we identify but do not read
RAID reconstruction with automatic parametersYes0/1/4/5/6/1E, 10/50/60, JBOD, RAID-Z, SHR, DDF metadataYesadds hardware controllersYesadds SHR, RAID-F1
Virtual disksYesVMDK, VHD, VHDX, VDI, QCOW2PartialQCOW2 not listedYesadds Parallels, DMG, sparsebundle
Encrypted volumes, with the credentialYesBitLocker, LUKS1/2, FileVault 2Partialno LUKS on the pageYeswidest list: adds VeraCrypt, TrueCrypt, eCryptFS
Imaging a failing drive: skip map, multi-pass, resumeYesPartialTechnician editionYes
Feasibility verdict before imaging, as a PDF reportYesNot foundNot found
Every named file content-checked before it is called recoveredYesNot foundNot found
Phones: direct pull over ADB and AFC, deleted messages and contactsYesRecoverYantra MobileNot foundNot found
Mailbox recovery and PST salvage, database rows, the ransomware routeYesNot foundNot found
CCTV recorder disks, camera by cameraYesHikvision and Dahua tablesNot foundPartialseparate product
Secure erase with a verified certificateYesRecoverYantra WipePartialwipe, no certificate describedNot found
Recovery over a networkPartiallocal network onlyYesinternet tooNot found
Bootable rescue environmentPartialwrites a supplied image; own ISO built, not yet signedYesEmergency editionNot found
Custom file signaturesYeslearned from a sample fileYesNot found
LicensingOffline key bound to one machine, sold by uses; the Imager is freeActivation key through the vendor's portal; from USD 49.99Hardware dongle or software key; perpetual; from USD 699.95
Browse the index first; recover only what is ticked
RecoverYantra YesR-Studio YesUFS Explorer Professional Yes
Recovery chance shown before extraction
RecoverYantra YesR-Studio YesUFS Explorer Professional Not found
File systems read by name and folder
RecoverYantra YesR-Studio YesUFS Explorer Professional Yes
RAID reconstruction with automatic parameters
RecoverYantra YesR-Studio YesUFS Explorer Professional Yes
Virtual disks
RecoverYantra YesR-Studio PartialUFS Explorer Professional Yes
Encrypted volumes, with the credential
RecoverYantra YesR-Studio PartialUFS Explorer Professional Yes
Imaging a failing drive: skip map, multi-pass, resume
RecoverYantra YesR-Studio PartialUFS Explorer Professional Yes
Feasibility verdict before imaging, as a PDF report
RecoverYantra YesR-Studio Not foundUFS Explorer Professional Not found
Every named file content-checked before it is called recovered
RecoverYantra YesR-Studio Not foundUFS Explorer Professional Not found
Phones: direct pull over ADB and AFC, deleted messages and contacts
RecoverYantra YesR-Studio Not foundUFS Explorer Professional Not found
Mailbox recovery and PST salvage, database rows, the ransomware route
RecoverYantra YesR-Studio Not foundUFS Explorer Professional Not found
CCTV recorder disks, camera by camera
RecoverYantra YesR-Studio Not foundUFS Explorer Professional Partial
Secure erase with a verified certificate
RecoverYantra YesR-Studio PartialUFS Explorer Professional Not found
Recovery over a network
RecoverYantra PartialR-Studio YesUFS Explorer Professional Not found
Bootable rescue environment
RecoverYantra PartialR-Studio YesUFS Explorer Professional Not found
Custom file signatures
RecoverYantra YesR-Studio YesUFS Explorer Professional Not found
Licensing
RecoverYantra Offline key bound to one machine, sold by uses; the Imager is freeR-Studio Activation key through the vendor's portal; from USD 49.99UFS Explorer Professional Hardware dongle or software key; perpetual; from USD 699.95
R-Studio. The affordable professional recovery tool with full RAID and recovery over the internet. File and volume level; no feasibility verdict, no content check, no phones, no mailboxes, no database rows, no recorder view.
UFS Explorer Professional. The widest file-system and encryption list of the three. Recovery only; video recorders are a separate product, and phones, mailboxes, database rows and erasure are not on its page.

Where R-Studio and UFS Explorer are ahead

  • File-system breadth. UFS Explorer reads VMFS, JFS, ReiserFS and Novell volumes and opens VeraCrypt, TrueCrypt and eCryptFS containers; we do not.
  • Recovery over the internet. R-Studio documents recovery across the internet with NAT traversal; our network imaging is the local network only.
  • A Windows PE emergency edition. R-Studio Emergency ships on both Linux and Windows PE; our bootable acquisition ISO is published and proven in a virtual machine, but is Linux only, not WinPE.
  • Years in the field. Both products have been sold for over a decade; the browse-first interface and the feasibility verdict reached our build in 7.8.10.66 and 7.8.10.68.

RecoverYantra Wipe is measured against a standard, not a rival

Wipe is a sanitisation tool, so it is not put in a competitor matrix. It erases a drive to NIST SP 800-88 Clear and then proves it: the recovery engine reads the drive back and finds nothing, and a signed certificate records the drive serial, the pattern written and the read-back verification. No software reaches the standard’s Destroy level; that needs physical destruction, and the certificate says so.

Digital forensics

The forensic family next to the platforms and Amped.

SakshyaYantra (the Forensic Suite and the Mobile Workbench) against the forensic platforms (EnCase, AXIOM, FTK) and the video-forensic standard (Amped). Amped is a video-only line, so it reads "Not found" on the platform rows and the platforms read "Not found" on the video rows; that is honest, not a slight.

We do it, they do not or only partlyBoth, or both partlyThey are ahead
vs OpenText EnCaseForensic platform
12 we lead10 match1 they lead
vs Magnet AXIOMForensic platform
11 we lead10 match2 they lead
vs Exterro FTKForensic platform
13 we lead9 match1 they lead
vs AmpedVideo forensics
18 we lead4 match1 they lead

Counted from the 23 capabilities in the table below. Where a leader is ahead it is amber, kept in at the same weight.

Acquisition

Getting the evidence off the device, intact.

CapabilitySakshyaYantraThe forensic familyOpenText EnCaseForensic platformMagnet AXIOMForensic platformExterro FTKForensic platformAmpedVideo forensics
Write-blocked imaging with hashingYesYesYesYesNot found
Evidence containers (E01, Ex01, AFF4, raw)Yesreads Ex01 and AFF4; writes E01 and rawYesE01 is theirsYesYesNot found
Damaged-media imaging (retry, skip map)YesPartialPartialPartialNot found
Mobile acquisition (logical to full file system)YesMobile Workbench: public methods in-house, licensed seam for the frontierPartialadd-onYesPartialNot found
Fleet and live acquisition of a machine in usePartiallocal network onlyPartialEndpoint InvestigatorYesAXIOM CyberPartialFTK ConnectNot found
Write-blocked imaging with hashing
SakshyaYantra YesOpenText EnCase YesMagnet AXIOM YesExterro FTK YesAmped Not found
Evidence containers (E01, Ex01, AFF4, raw)
SakshyaYantra YesOpenText EnCase YesMagnet AXIOM YesExterro FTK YesAmped Not found
Damaged-media imaging (retry, skip map)
SakshyaYantra YesOpenText EnCase PartialMagnet AXIOM PartialExterro FTK PartialAmped Not found
Mobile acquisition (logical to full file system)
SakshyaYantra YesOpenText EnCase PartialMagnet AXIOM YesExterro FTK PartialAmped Not found
Fleet and live acquisition of a machine in use
SakshyaYantra PartialOpenText EnCase PartialMagnet AXIOM YesExterro FTK PartialAmped Not found

Examination and analysis

What you can find once it is acquired.

CapabilitySakshyaYantraThe forensic familyOpenText EnCaseForensic platformMagnet AXIOMForensic platformExterro FTKForensic platformAmpedVideo forensics
Windows / macOS / Linux artefactsYesYesYesYesNot found
Memory (RAM) analysisYesYesYesPartialNot found
Combined timeline across artefactsYesYesYesTimelineYesNot found
Full-text index and searchYesfull-text half bounded by a stated budgetYesYesYesvery fastNot found
Encrypted volume decryptionYesBitLocker, LUKS, FileVault, VeraCryptYesYesYesPRTKNot found
Known-file hash sets (NSRL / KFF)YesYesYesYesKFFNot found
Windows / macOS / Linux artefacts
SakshyaYantra YesOpenText EnCase YesMagnet AXIOM YesExterro FTK YesAmped Not found
Memory (RAM) analysis
SakshyaYantra YesOpenText EnCase YesMagnet AXIOM YesExterro FTK PartialAmped Not found
Combined timeline across artefacts
SakshyaYantra YesOpenText EnCase YesMagnet AXIOM YesExterro FTK YesAmped Not found
Full-text index and search
SakshyaYantra YesOpenText EnCase YesMagnet AXIOM YesExterro FTK YesAmped Not found
Encrypted volume decryption
SakshyaYantra YesOpenText EnCase YesMagnet AXIOM YesExterro FTK YesAmped Not found
Known-file hash sets (NSRL / KFF)
SakshyaYantra YesOpenText EnCase YesMagnet AXIOM YesExterro FTK YesAmped Not found

Video forensics

The recorder, the picture, and whether it can be trusted: Amped's ground.

CapabilitySakshyaYantraThe forensic familyOpenText EnCaseForensic platformMagnet AXIOMForensic platformExterro FTKForensic platformAmpedVideo forensics
Recorder / DVR footage recovery and conversionYesNot foundPartialseparate productNot foundYesDVRConv and Engine
Enhancement with the chain shown, and measurementYes145 registered operationsNot foundNot foundNot foundYesFIVE, 140-plus filters
Authenticity, tamper and camera identificationPartial50 registered analysis tools, no measured pristine-media reference rate yetNot foundNot foundNot foundYesAuthenticate, 40-plus
Number-plate assistanceYesdeterministic HSRP workflowNot foundNot foundNot foundYesDeepPlate, trained models
Three times never merged (PTS, overlay, case)YesNot foundNot foundNot foundPartialoverlay
Frame pack as the evidence-transfer unitYesNot foundNot foundNot foundNot found
Recorder / DVR footage recovery and conversion
SakshyaYantra YesOpenText EnCase Not foundMagnet AXIOM PartialExterro FTK Not foundAmped Yes
Enhancement with the chain shown, and measurement
SakshyaYantra YesOpenText EnCase Not foundMagnet AXIOM Not foundExterro FTK Not foundAmped Yes
Authenticity, tamper and camera identification
SakshyaYantra PartialOpenText EnCase Not foundMagnet AXIOM Not foundExterro FTK Not foundAmped Yes
Number-plate assistance
SakshyaYantra YesOpenText EnCase Not foundMagnet AXIOM Not foundExterro FTK Not foundAmped Yes
Three times never merged (PTS, overlay, case)
SakshyaYantra YesOpenText EnCase Not foundMagnet AXIOM Not foundExterro FTK Not foundAmped Partial
Frame pack as the evidence-transfer unit
SakshyaYantra YesOpenText EnCase Not foundMagnet AXIOM Not foundExterro FTK Not foundAmped Not found

Evidence handling and reporting

What survives scrutiny afterwards.

CapabilitySakshyaYantraThe forensic familyOpenText EnCaseForensic platformMagnet AXIOMForensic platformExterro FTKForensic platformAmpedVideo forensics
Chain-of-custody reportsYesYesYesYesYesvideo reports
Hash-chained tamper-evident audit trailYesPartialloggingPartialPartialPartialproject
Per-item hash AND source offset in the reportYesPartialPartialPartialPartial
Examiner's reading sealed before any AI answerYesNot foundNot foundNot foundNot found
Draft S.63(4) BSA 2023 evidence certificateYesNot foundNot foundNot foundNot found
Case scale: distributed processing, multi-examiner reviewPartialone workstation, advisory lockYesYesMagnet ReviewYesFTK CentralNot found
LicensingOffline key bound to one machine, sold by usesTerm licensingSubscriptionNot stated on the pagePerpetual or subscription, per product
Chain-of-custody reports
SakshyaYantra YesOpenText EnCase YesMagnet AXIOM YesExterro FTK YesAmped Yes
Hash-chained tamper-evident audit trail
SakshyaYantra YesOpenText EnCase PartialMagnet AXIOM PartialExterro FTK PartialAmped Partial
Per-item hash AND source offset in the report
SakshyaYantra YesOpenText EnCase PartialMagnet AXIOM PartialExterro FTK PartialAmped Partial
Examiner's reading sealed before any AI answer
SakshyaYantra YesOpenText EnCase Not foundMagnet AXIOM Not foundExterro FTK Not foundAmped Not found
Draft S.63(4) BSA 2023 evidence certificate
SakshyaYantra YesOpenText EnCase Not foundMagnet AXIOM Not foundExterro FTK Not foundAmped Not found
Case scale: distributed processing, multi-examiner review
SakshyaYantra PartialOpenText EnCase YesMagnet AXIOM YesExterro FTK YesAmped Not found
Licensing
SakshyaYantra Offline key bound to one machine, sold by usesOpenText EnCase Term licensingMagnet AXIOM SubscriptionExterro FTK Not stated on the pageAmped Perpetual or subscription, per product

OpenText EnCase

An established forensic platform; E01 is its format. EnScript automation, deep artefact work, memory, and Endpoint Investigator for off-VPN collection at fleet scale. Mobile is a separately licensed add-on; no video-forensic line.

Magnet AXIOM

Magnet.AI categorisation, Timeline and Connections, wide cloud and app artefact coverage, and the GrayKey ecosystem for locked handsets. DVR work and media authenticity are separate products.

Exterro FTK

Distributed processing over multi-terabyte sets, PRTK decryption, KFF known-file filtering and strong email handling. Built for scale; no video-forensic suite.

Amped

The video-forensic line: FIVE, Authenticate, Replay, DVRConv, Engine and DeepPlate. We implement the same functions as modules in one build and add the frame pack, the sealed reading and the S.63(4) certificate; Amped's breadth and field history are ahead, see below.

Also evaluated, and not in the table

Any set of columns is a choice, so here is what this one left out rather than hiding it.

  • Cellebrite and GrayKey. Locked and recent handsets. We run the public acquisition methods in-house and reach the modern frontier only through a licensed capability seam that our agreements fill.
  • X-Ways. A capable single-examiner platform tool with strong RAID and memory work in a tiny footprint. Left out of the columns to keep the table readable.
  • Autopsy. Free and open source, on The Sleuth Kit. The right answer for a lab with no budget; no video forensics, no physical recovery.

Where the forensic leaders are ahead

  • Case scale. FTK Central and Magnet Review distribute processing and let several examiners work one case; we run on one workstation with an advisory lock.
  • Modern locked handsets. A12-and-later iPhones before first unlock, and Android 10-and-later devices with file-based encryption before first unlock, have no public vector; GrayKey and Cellebrite lead here, and we reach that frontier only through the licensed seam.
  • Cloud sources. Ours is the organisation's own Microsoft 365 tenant; AXIOM and FTK document far wider cloud coverage.
  • AI-assisted categorisation of images at scale. Magnet.AI and Exterro's analytics are more mature than our optional, sealed-first observations.
  • Enhancement breadth and validation history. Amped FIVE ships 140-plus filters with years of field use; our lab registers 145 operations, each stating its assumptions and limits, but none has that field history. Authenticate's 40-plus methods, quantisation-table database and PRNU procedures rest on corpora we do not hold.
  • Recorder format breadth. Amped's DVRConv and Engine cover hundreds of proprietary recorder formats built up since the 2010s; ours is an Indian-priority registry with a standing intake programme.
  • Trained number-plate models. DeepPlate is trained per country across 15 countries; ours is a deterministic HSRP workflow with an optional local model pack.
  • Record in court, training and certification. EnCase, FTK, AXIOM and Amped have years of precedent and examiner certification programmes. The video and image forensics reached our build in 7.8.10.68, proven on the bench and on synthetic corpora; a real recorder end to end has not yet been exercised.

Compared by capability against each vendor’s own published material, read 15 and 16 September 2026 for the 7.8.10.68 release. Editions and versions vary and products change; confirm current specifications. The SakshyaYantra column reflects the tested build. All names and trademarks belong to their owners; this is a factual capability comparison, not an endorsement.

See it on your own data.

Approved partners run every product on their own bench; the Imager is free for everyone to check and image a drive. Bring the hard cases to our lab.