Does the absence of a message, call or application prove it wasn't there?¶
No. A negative result is meaningful only to the extent that the device, acquisition, parser, report and search had a fair opportunity to reveal the expected record.
Locate where absence could arise¶
The item may never have existed locally, may have been deleted or overwritten, or may reside in cloud or another device. Relevant storage might be inaccessible, not acquired, unsupported, excluded by report scope or hidden by filters. A search can also miss a number, username, internal ID or package name stored differently.
Define what should have been found¶
Identify which system would create the record, where and for how long it would persist, and whether that source was acquired and parsed. Check suitable identifier variants and related traces such as notifications, attachments, journals, participant devices and provider records. Then report the tested scope rather than asserting that nothing happened.
Key takeaway
Describe a negative finding by the sources and searches capable of detecting the expected artefact, including their limitations.