Ordinary recovery asks whether the data came back. Forensic work asks whether you can prove, months later and under challenge, that nothing changed. Write-blocked imaging, hashed verification and a documented chain of custody — and the artefacts that answer the question are rarely the files themselves.
$ bdr image /dev/sdb → Device: Seized laptop HDD (1 TB) → Status: WRITE-BLOCKED — evidential image → Case: civil dispute · ref 2026-014 $ bdr engineer-working → Image hash: SHA-256 checked · confirmed against source → Deleted files: 4,210 recovered → Artifacts: metadata and timestamps kept intact $ bdr verify → ✓ documents — fully recovered → ✓ deleted items — carved and dated → ✓ findings — pulled back whole
The commonest way evidence is spoiled is someone checking what is on the device before handing it over. Booting the machine, opening files or plugging the drive in all change timestamps and can trigger writes. If a device may become evidence, stop using it and pass it on as it is.
Forensic work costs more and takes longer than ordinary recovery. It is worth it when the answer may be challenged.
Technically the overlap with ordinary recovery is large. The difference is everything around it.
The source is read behind a hardware write blocker that physically refuses write commands, so it can be copied completely while remaining provably unaltered. A cryptographic hash — typically SHA-256 — is computed across source and image and re-verified at each stage, so any change of a single bit is demonstrable. Every step is logged, exhibits are recorded and signed, and the work follows ACPO principles for digital evidence.
What that buys is the ability to answer the question that actually matters months later: can you show the material analysed is identical to what was seized, and that nothing you did altered it.
The revealing material is usually not the files themselves.
Registry records showing which external devices were attached, their serial numbers, and when — often the central question in a departing-employee case.
Records of what was opened and from where, surviving long after the file itself has gone.
Evidence of which folders were browsed, including on external media no longer present.
Creation, modification and access times distinguished, and cross-checked against file system journals that are harder to alter convincingly.
Files, fragments and database records recoverable long after deletion, with their original context.
Priced differently from recovery, and for a reason.
Forensic investigation starts from £800 +VAT and is quoted after a scoping discussion, because the work depends on what you need established rather than on the device. It carries a 50% deposit and is not offered on a no-fix-no-fee basis — the analysis has value whatever it concludes, including when it establishes that nothing improper occurred, which is a result our clients often need just as much.
Reports are written to be read by non-technical people, with the technical detail available beneath. Full write-ups: an ex-employee investigation.
Send the device in for its free assessment and tell us briefly what’s at issue; an engineer reviews it and confirms your exact quote in writing before anything starts.
Getting your data back begins with getting the device to us. Pack it up safely, pop your contact details inside, and send it over — once we’ve run the free diagnostic, we’ll confirm your exact price in writing before any work starts.
Posting it? A tracked, insured service is what we’d recommend. Rather drop it in? You’re welcome Monday to Friday, 9am to 5:30pm — just package the device up as above first.
Want a bit more detail first? Fill in the form with more about your issue and an engineer will review it and send you a custom quote.
We’ll be in touch shortly. If it’s urgent, call 01865 593000.
What people most often ask about forensic data recovery.
That the process is provable, not just the result. The source is read behind a write blocker, hashed to demonstrate the copy is bit-identical, and every step logged so an independent party could repeat it and reach the same conclusion — following ACPO principles for digital evidence.
Often. USB device records, link files, jump lists, shellbags and file system timestamps together show which devices were attached, when, and what was accessed around that time. What can be established depends on the system and on how much has happened since.
No — that is the commonest way evidence is compromised. Booting it, opening files or connecting the drive changes timestamps and can trigger writes. Preserve it as it is and let the imaging happen behind a write blocker.
It is prepared to that standard — hashed images, documented chain of custody, ACPO-compliant handling and a report written for a non-technical reader. Whether a matter reaches court is your decision; the work is done so that it can.
That is a legitimate and often valuable outcome, and it is why this work is not no-fix-no-fee. Establishing that nothing improper occurred is frequently exactly what a client needs, and the analysis costs the same to perform.
From £800 plus VAT, quoted after a scoping discussion, with a 50% deposit. Pricing follows what needs establishing rather than the device involved.
A free assessment, a forensic write-blocked image, deleted-data recovery and a clear written report. Talk to us in confidence today.