Skip to content
Calcrivo

Forensic Evidence Storage Calculator

Size a forensic evidence store across images, working copies, derived artefacts, offsite retention and monthly cost.

Inputs

devices
GB
×
copies
%

Carved files, indexes, timelines, reports

years
currency/TB/month

Capacity to Provision

480.9TB

Compressed Images

105.9TB

Working Copies

60.0TB

Derived Artefacts

26.5TB

Annual Growth

104.1TB/year

Monthly Storage Cost

$8,656

Annual Storage Cost

$103,871

Step by step

  1. Values used

    Devices acquired per year = 120 devices; Average device capacity = 512 GB; Image compression ratio = 1.70 ×; Working copies kept per case = 1 copies; Derived artefacts as a share of the image = 25 %; Retention period = 3 years; Keep a second offsite copy = Yes; Storage cost per TB per month = 18 currency/TB/month

  2. Forensic Evidence Storage

    provisionedCapacity = (retainedImages + derivedArtefacts + liveWorkingCopies) × copyCount × 1.25 headroom, where retainedImages = devices × capacity ÷ compression × retentionYears.

  3. Recurring cost

    monthlyCost = provisionedTB × costPerTBPerMonth

  4. Capacity to Provision

    = 480.9 TB

  5. Compressed Images

    = 105.9 TB

  6. Working Copies

    = 60.0 TB

  7. Derived Artefacts

    = 26.5 TB

  8. Annual Growth

    = 104.1 TB/year

  9. Monthly Storage Cost

    = 8,656

How it works

Evidence at rest is never just the image. Each case holds a compressed acquisition kept for the full retention period, one or more uncompressed working copies mounted while the case is live, and derived artefacts — carved files, search indexes, timelines — that typically add a quarter of the image again. Only the images and artefacts accumulate over the retention window; working copies are released when a case closes, so they are counted for one year of active load. Forensic storage grows monotonically for as long as the retention policy says, and an array that fills mid-acquisition corrupts the one copy you were legally required to preserve.

Formulas

Forensic Evidence Storage

provisionedCapacity = (retainedImages + derivedArtefacts + liveWorkingCopies) × copyCount × 1.25 headroom, where retainedImages = devices × capacity ÷ compression × retentionYears.

compression
Image compression ratio, typically 1.5–2.2 for E01
workingCopies
Uncompressed copies mounted for analysis
derivedPct
Carved files, indexes and timelines as a share of the image
1.25
25% free-space headroom so the array never runs full

Recurring cost

monthlyCost = provisionedTB × costPerTBPerMonth

provisionedTB
Capacity actually bought, including headroom and the offsite copy

Frequently Asked Questions

How is Forensic Evidence Storage calculated?

provisionedCapacity = (retainedImages + derivedArtefacts + liveWorkingCopies) × copyCount × 1.25 headroom, where retainedImages = devices × capacity ÷ compression × retentionYears. Evidence at rest is never just the image. Each case holds a compressed acquisition kept for the full retention period, one or more uncompressed working copies mounted while the case is live, and derived artefacts — carved files, search indexes, timelines — that typically add a quarter of the image again. Only the images and artefacts accumulate over the retention window; working copies are released when a case closes, so they are counted for one year of active load.

Why does Forensic Evidence Storage matter?

Forensic storage grows monotonically for as long as the retention policy says, and an array that fills mid-acquisition corrupts the one copy you were legally required to preserve.

What values do I need to enter?

This calculator takes 8 inputs: Devices acquired per year, Average device capacity, Image compression ratio, Working copies kept per case, Derived artefacts as a share of the image, Retention period, Keep a second offsite copy, Storage cost per TB per month. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.

Should working copies be compressed too?

Usually not. Analysis tools random-read the image constantly, and decompressing on every read is slow enough to dominate the case timeline. Keep the archive compressed and the active working copy raw.

What drives the offsite copy?

Chain-of-custody and disaster-recovery obligations. If the only copy of an acquisition lives on one array, a controller failure destroys evidence, so most labs treat 2× as a floor and price it in from the start.

You might also need