The firm

About Forensic Five

Independent cybersecurity, site security, and backup review, delivered from St. Albert, Alberta

Who we are

A small firm that writes reports people can use

Forensic Five reviews internet-facing systems, physical sites, and backups for Canadian organizations that cannot justify a full-time security team, and should not have to buy a platform to get a straight answer.

Typical cyber work is a scoped review of a website, application, or server; a written report with prioritized findings; and a review call. Site security is a property walk: coverage, evidence, and whether the cameras themselves would pass a security review. Backup work is recoverability: what is copied, who can wipe it, and the last proven restore.

We do not require you to purchase hosting, cameras, software, or a monthly retainer to receive the report. Affiliated companies, if any, are not a condition of the engagement.

Confidentiality

Findings, scores, and client names are not used in marketing. We will execute your NDA before access is granted or testing begins.

Independence

Recommendations are not tied to a product we sell. If a control is “good enough,” we say so. If we did not test something, the report says that too.

Authorization

We only test systems you own or are authorized to have tested. Rules of engagement are written down. Production impact is agreed in advance.

People

Analysts

You will know who is on the engagement. Work is not handed to an anonymous queue.

Mathew Potter

Founder · Security Analyst

Mathew leads Forensic Five assessments and consulting. His background is Linux systems, networks, and application infrastructure, the stack most client websites and internal tools actually run on.

Prior work includes environments with formal control requirements in finance, government, and aerospace. That experience shows up in how reports are written: evidence, priority, and a clear statement of what was out of scope.

Thomas Bereckzy

Systems & Security Engineer

Thomas focuses on system design and the security of applications that handle financial or otherwise sensitive transactions. He reviews architecture and implementation, not only scanner output.

He is brought in when an assessment needs a second technical reader: scaling, identity, or how a system will behave once it is in production.

Discuss an engagement

We will tell you whether a cyber assessment, a site walk, a backup review, or a short consult is the right first step, including when we are not the right firm.