Magnet AXIOM
A digital forensics platform consolidating evidence from phones, computers, cloud accounts and vehicles into one searchable case file, including a machine learning layer that classifies and flags communications content.
Magnet Forensics (Waterloo, Ontario) Supplier's own site ↗
Magnet AXIOM is a digital forensics platform used to recover, analyse and report on evidence pulled from phones, computers, cloud accounts, vehicles and IoT devices, bringing all of it into a single case file. It is made by Magnet Forensics, based in Waterloo, Ontario, and founded in 2011 by Jad Saliba, a former police officer who built the original tool because the job needed one.
It belongs on a catalogue of policing AI because of one specific component rather than the platform as a whole. Most of AXIOM is conventional forensic software: parsing file systems, carving deleted files, decrypting disks. The AI element is Magnet.AI, a machine learning layer that reads communications content and flags material of investigative interest — introduced for contextual chat analysis and marketed as an industry first when it launched.
HOW THE COMPANY DESCRIBES IT
Magnet Forensics positions AXIOM around consolidation and speed. Its material describes examining evidence from mobile, cloud, computer and vehicle sources in one case file, using analytical tools to surface case-relevant artefacts automatically. The company states its software is used by more than 4,000 customers in over 100 countries, and that its purpose is to help investigators fight crime, protect assets and guard national security.
The platform is split into two applications. AXIOM Process acquires and parses data, recovering material from zip archives and deleted files and sorting it by type. AXIOM Examine presents what Process found for review in a case database, searchable by date range, keyword and other filters.
Its distinguishing design choice is what the company calls an artefact-first approach: prioritising the material investigators actually want — chats, images, browser history, location data — over a raw file system view. A Connections feature draws a graphical map showing how artefacts relate to one another across devices.
Magnet's own framing of the problem is worth recording because it is accurate: a senior product manager described investigators previously having to toggle between different tools with different report formats to correlate artefacts manually, risking missed evidence and missed connections.
WHERE IT SITS IN POLICE USE
Deployments recorded on this site's tracker are listed below. The Czech Police names Magnet AXIOM among the tools it classifies as applying machine learning technologies, in its own freedom-of-information disclosure — one of the few instances where a force has publicly stated which of its forensic tools it considers AI.
Magnet Forensics reports that roughly 65% of its customers are public sector and about 60% North American. It sits alongside rather than in place of extraction hardware: many labs image a phone with one tool and analyse it in AXIOM, and the company sells its own acquisition products, Graykey for device access and Verakey for consent-based extraction, into the same workflow.
THE CASE FOR IT
The underlying problem is real and growing. Digital evidence features in a large and rising share of investigations, and the volume on a single modern phone can exceed what an examiner can review manually within any reasonable time. Practitioner accounts of AXIOM consistently praise its filtering as the thing that makes large datasets tractable — one reviewer describing recursive filtering as what pares a trove of data down to the material that matters.
The consolidation argument is also sound. Correlating artefacts across a phone, a laptop and a cloud account by hand is error-prone, and a single case file with a visual map of relationships between artefacts reduces a genuine source of missed evidence.
Reporting quality matters more than it sounds. The ability to produce a portable case file that presents evidence coherently to lawyers and courts is a practical benefit in a field where the alternative is a set of incompatible exports.
THE CASE AGAINST
The core tension in mobile forensics is not specific to this product but is sharpened by it: an extraction captures everything, and analysis tools make everything searchable. A phone examined in connection with one offence yields years of messages, photographs, location history and cloud account contents belonging to the device owner and to everyone who ever messaged them. The artefact-first design that makes AXIOM effective is precisely what makes the whole of a person's digital life immediately legible.
Cloud access extends this further. The platform can be used to log into cloud-based accounts and retrieve deleted data and location history, which reaches material that is not on the seized device at all. The civil liberties research project AFSC Investigate lists Magnet Forensics on that basis.
The AI component carries a distinct risk that the conventional forensics does not. Magnet.AI classifies conversations and flags them as potentially relevant — for instance as indicative of a particular category of offending. A machine judgement about what a conversation means is a different kind of claim from recovering a deleted file, and it is the kind of claim that needs to be testable in court. No independent evaluation of Magnet.AI's classification accuracy was identified in this research.
There is also an evidential dependency question. Where a tool's output is presented as evidence, the reliability of the tool becomes material to the case, and commercial forensic software is generally not open to independent inspection.
WHAT IS NOT ESTABLISHED
No independent accuracy evaluation of Magnet.AI's chat classification was found. Its error rate, and whether performance varies by language or context, is undocumented publicly.
Whether UK forces use the Magnet.AI component specifically, as opposed to AXIOM's conventional forensic functions, is not established by any source reviewed. Naming the platform does not establish which features are enabled.
How forces constrain the scope of an AXIOM examination — whether analysis is limited to material relevant to the offence under investigation, or whether the full extraction is searchable — is not documented in the deployments reviewed, and is the question that most determines how intrusive the tool is in practice.
No published data was found on how often digital forensic examinations using this or comparable platforms produce evidence that changes a case outcome.
Where this is deployed
Full tracker →Sources
- Magnet Forensics — Magnet AXIOM product page (vendor)
- Police1 — how AXIOM Process and AXIOM Examine work, with Magnet product management comment
- Police1 — Magnet Forensics release announcing Magnet.AI chat analysis
- Police1 — Magnet Forensics company profile and customer scale
- AFSC Investigate — critical company profile, cloud account access and deleted data
- Software Advice — practitioner reviews comparing AXIOM filtering with other tools
- Policie CR — freedom-of-information disclosure naming Magnet AXIOM among its machine learning tools