Call us — 01865 593000
Mon–Fri · 9am–5:30pm · No fix, no fee
Start a free diagnostic →
/ home / services / forensic
Specialist recovery · forensics

Forensic recovery, where the process has to hold up.

Ordinary recovery asks whether the data came back. Forensic work asks whether you can prove, months later and under challenge, that nothing changed. Write-blocked imaging, hashed verification and a documented chain of custody — and the artefacts that answer the question are rarely the files themselves.

From £800 + VAT
Hash-verified capture
Expert findings report
~ casework-001 — live RECOVERED
$ bdr image /dev/sdb
 Device: Seized laptop HDD (1 TB)
 Status: WRITE-BLOCKED — evidential image
 Case: civil dispute · ref 2026-014

$ bdr engineer-working
 Image hash: SHA-256 checked · confirmed against source
 Deleted files: 4,210 recovered
 Artifacts: metadata and timestamps kept intact

$ bdr verify
 ✓ documents — fully recovered
 ✓ deleted items — carved and dated
 ✓ findings — pulled back whole
!

Don’t look at it first.

The commonest way evidence is spoiled is someone checking what is on the device before handing it over. Booting the machine, opening files or plugging the drive in all change timestamps and can trigger writes. If a device may become evidence, stop using it and pass it on as it is.

// when you need evidence

Recovery, or something that has to hold up.

Forensic work costs more and takes longer than ordinary recovery. It is worth it when the answer may be challenged.

// how it differs

Proving the process, not just the data.

Technically the overlap with ordinary recovery is large. The difference is everything around it.

The source is read behind a hardware write blocker that physically refuses write commands, so it can be copied completely while remaining provably unaltered. A cryptographic hash — typically SHA-256 — is computed across source and image and re-verified at each stage, so any change of a single bit is demonstrable. Every step is logged, exhibits are recorded and signed, and the work follows ACPO principles for digital evidence.

What that buys is the ability to answer the question that actually matters months later: can you show the material analysed is identical to what was seized, and that nothing you did altered it.

// what analysis finds

Artefacts that outlive deletion.

The revealing material is usually not the files themselves.

01

USB device history

Registry records showing which external devices were attached, their serial numbers, and when — often the central question in a departing-employee case.

02

Link files and jump lists

Records of what was opened and from where, surviving long after the file itself has gone.

03

Shellbags and folder access

Evidence of which folders were browsed, including on external media no longer present.

04

Timestamps in detail

Creation, modification and access times distinguished, and cross-checked against file system journals that are harder to alter convincingly.

05

Deleted material in unallocated space

Files, fragments and database records recoverable long after deletion, with their original context.

// pricing

Quoted after scoping, with a deposit.

Priced differently from recovery, and for a reason.

Forensic investigation starts from £800 +VAT and is quoted after a scoping discussion, because the work depends on what you need established rather than on the device. It carries a 50% deposit and is not offered on a no-fix-no-fee basis — the analysis has value whatever it concludes, including when it establishes that nothing improper occurred, which is a result our clients often need just as much.

Reports are written to be read by non-technical people, with the technical detail available beneath. Full write-ups: an ex-employee investigation.

// getting it to us

Two easy steps.

Send the device in for its free assessment and tell us briefly what’s at issue; an engineer reviews it and confirms your exact quote in writing before anything starts.

1

Send us your device

Getting your data back begins with getting the device to us. Pack it up safely, pop your contact details inside, and send it over — once we’ve run the free diagnostic, we’ll confirm your exact price in writing before any work starts.

How to pack it
  • Box the device up in a small, sturdy carton or a padded envelope.
  • You can leave out caddies, cables and power supplies — none of them are needed for the recovery.
  • Pop your details inside — name, address, phone and email, on a slip of paper or via our shipping form — and seal it up.
Post toOxford Data Recovery
John Eccles House, Oxford Science Park
Oxford OX2
Shipping formPDF · print & include with your devicePDF ↓

Posting it? A tracked, insured service is what we’d recommend. Rather drop it in? You’re welcome Monday to Friday, 9am to 5:30pm — just package the device up as above first.

2

Need more information?

Want a bit more detail first? Fill in the form with more about your issue and an engineer will review it and send you a custom quote.

An engineer reviews every enquiry personally — we usually reply within 30 minutes during the day. Prefer to call? 01865 593000.

Thanks — your message is in.

We’ll be in touch shortly. If it’s urgent, call 01865 593000.

// questions

Forensic recovery — your questions.

What people most often ask about forensic data recovery.

That the process is provable, not just the result. The source is read behind a write blocker, hashed to demonstrate the copy is bit-identical, and every step logged so an independent party could repeat it and reach the same conclusion — following ACPO principles for digital evidence.

Often. USB device records, link files, jump lists, shellbags and file system timestamps together show which devices were attached, when, and what was accessed around that time. What can be established depends on the system and on how much has happened since.

No — that is the commonest way evidence is compromised. Booting it, opening files or connecting the drive changes timestamps and can trigger writes. Preserve it as it is and let the imaging happen behind a write blocker.

It is prepared to that standard — hashed images, documented chain of custody, ACPO-compliant handling and a report written for a non-technical reader. Whether a matter reaches court is your decision; the work is done so that it can.

That is a legitimate and often valuable outcome, and it is why this work is not no-fix-no-fee. Establishing that nothing improper occurred is frequently exactly what a client needs, and the analysis costs the same to perform.

From £800 plus VAT, quoted after a scoping discussion, with a 50% deposit. Pricing follows what needs establishing rather than the device involved.

// need evidence?

Need it recovered? Let’s do it properly.

A free assessment, a forensic write-blocked image, deleted-data recovery and a clear written report. Talk to us in confidence today.