The Excluded Evidence Problem Semantics 21 Is Exposing

A Completed Import Is Not Complete Visibility

Since when was missed evidence not an investigator’s responsibility?

That question is uncomfortable because it cuts through the assumption many review workflows quietly rely on. If the import completed, the evidence must be visible. If the queue populated, the dataset must be accounted for. If the tool says processing is finished, the investigator must be seeing everything they need to see.

But that does not mean every file is in front of the investigator.

Difficult media can fall out of view before review even begins. Corrupt files, damaged material and unsupported formats may be skipped, excluded or recorded somewhere other than the working review environment.

The investigator sees the queue and believes the case is visible. In reality, the tool may only be showing the material it was able to process cleanly.


Get The Latest DFIR News

The monthly Forensic Focus newsletter, plus webinar invitations and occasional research surveys.

Unsubscribe or change what you receive at any time. We respect your privacy: read our privacy policy.


That is the blind spot.

The files have not disappeared from the dataset. They have disappeared from the investigator’s view, and if investigators cannot see them, they cannot assess them, explain them or account for them with confidence.

The Blind Spot Is Not the File. It Is the Assumption

In digital investigations, visibility is not a nice-to-have. It is the foundation of review.

The hard question is not whether a platform processed the case. The hard question is whether investigators are seeing the full dataset or only the portion the platform has chosen to show them. That distinction matters.

A tool can appear organised and still leave material out of view. A review queue can look complete while excluded files sit elsewhere. A media count can reassure a team without proving that every file remains visible, accountable and available for assessment.

That is where risk enters the workflow. Not because every excluded file will be important, but because nobody should have to assume it is not.

Blind spots left unchecked become blind spots accepted.

Completeness Has to Be Tested

Investigators are expected to account for their work. The same standard should apply to the systems supporting that work.

When the defence asks whether all media was visible, reviewed and accounted for, what will you say?

The answer should not depend on trust in a platform summary. It should be proven through verification.

The tool count should reconcile with the JSON export. Failed files should not vanish into a log. Excluded media should not sit outside the investigator’s working view. Unsupported and damaged material should remain visible, accountable and available for assessment.

If the review environment cannot show what happened to the files it failed to process cleanly, it is asking investigators to carry uncertainty they should not have to carry.

The Tool That Keeps the Whole Case in View

S21 VisionX supports investigator-led visual evidence review at scale.

It helps investigators prioritise, group and assess visual material with greater clarity and control, while keeping professional judgement with trained users. It is offline, intelligence-led and built for serious investigative environments where volume, sensitivity and review burden matter.

S21 VisionX keeps all media within the investigation – visible, accountable and available for review.

That includes material that is corrupt, damaged or difficult to process. Even where content cannot be fully reviewed, the file remains part of the case view, helping investigators understand what exists, what has failed and what still needs assessment.

That distinction matters because the goal is not simply to complete an import. The goal is to give investigators a review environment they can interrogate, verify and rely on.

Completeness should not be assumed. It should be tested.

Interested in Checking Your Current Workflow? Worried Your Current Tool Is Missing Data?

See where your blind spots are.

Start with a simple comparison: check whether your tool is importing the same number of files as your JSON export.

If the numbers do not match, ask why.

Click here to email Semantics 21 and express your interest in S21 VisionX.

Leave a Comment