Call us — 01483 901310
Mon–Fri · 9am–5:30pm · No fix, no fee
Start a free diagnostic →
/ home / services / forensic
Specialist recovery · forensic

Forensic data recovery, to evidential standard.

When a claim, dispute or investigation hangs on what a drive or computer contains — deleted files among it, the ones people assume are long gone — the data has to be lifted off without altering it. We capture a forensic, hash-verified image and recover whatever’s called for.

From £800 + VAT
Hash-verified capture
Expert findings report
~ casework-001 — live RECOVERED
$ bdr image /dev/sdb
 Device: Seized laptop HDD (1 TB)
 Status: WRITE-BLOCKED — evidential image
 Case: civil dispute · ref 2026-014

$ bdr engineer-working
 Image hash: SHA-256 checked · confirmed against source
 Deleted files: 4,210 recovered
 Artifacts: metadata and timestamps kept intact

$ bdr verify
 ✓ documents — fully recovered
 ✓ deleted items — carved and dated
 ✓ findings — pulled back whole
!

Might it be evidence? Then don’t touch the device.

The moment a computer or drive might be needed as evidence, the one thing that matters is not using it. Switch it on, open a file, run a recovery tool, and you rewrite the very data and timestamps at issue — potentially rendering findings inadmissible. Power it off, leave it untouched, and bring it in: we image it write-blocked first, work only on that copy, and recover what’s needed.

// when you need evidence

When the evidence matters.

There are moments when the contents of a device carry legal or commercial weight, and must be taken off it without a single change — that’s what forensic recovery is for. The situations below are the ones that reach us most.

// evidence we recover

What we can retrieve.

Working from a forensic image of a drive or computer, we recover and document evidence across a wide range — data the user swore was long deleted very much included. We report what’s actually there, plainly and without spin.

Deleted filesDocumentsSpreadsheetsEmailsBrowser historySearch historyImages & photosDeleted photosFile metadataTimestampsSystem logsLogin activityUSB historyRecently openedRecycle binHidden filesWiped-data tracesCloud sync traces

Hard drives and SSDs; servers and NAS; USB drives, memory cards and external units; and the computers, laptops and workstations themselves.

// how the recovery runs

How forensic recovery works.

In forensic work, integrity counts as much as recovery: the point is to prove what comes back is exactly what was found. So we image behind a write blocker, do the recovering and analysis on that copy alone, and lay the findings out clearly.

01

Free assessment and scope

Talk us through what’s in dispute and what you’re trying to establish; before any work, we settle the scope and say plainly what’s achievable.

02

Take a write-blocked image

Through a hardware write blocker — which lets nothing alter a single byte of the original — a bit-for-bit forensic image is captured, then checked against the source by cryptographic hash (MD5 and SHA-256): the fingerprint proving the evidence is untouched.

03

Recover deleted and hidden data

On the verified image alone, deleted files and fragments are carved back, and hidden or overwritten data and the system artefacts — registry hives, prefetch, LNK files, journals, the $MFT — are surfaced wherever they’ve survived.

04

Analyse and build a timeline

Timestamps and metadata — event logs, the $UsnJrnl change journal, the $MFT — are drawn together into one timeline that shows what took place and when, factually and in a way any other examiner could repeat.

05

Report the findings.

What was found is set out as an interactive browser listing, in plain English fit for HR, solicitors or court.

06

Secure handling and return

Throughout, confidentiality is maintained; the data is held securely and either returned or retained exactly as you instruct.

// what we recover from

Recovered, dated, documented.

Off a write-blocked, hash-verified image we forensically recover from servers, computers, laptops and drives — bringing back deleted evidence and documenting the findings so they hold up to scrutiny.

Write-blocked
original never altered
Hash-verified
SHA-256 integrity
Custody
documented throughout
Deleted data
recovered + dated
Plain report
solicitor & court ready
25 yrs
Recovering data
// get a custom quote

Request a written quote

Tell us what happened and we’ll get back to you, usually within a working day.

Prefer to call? 01483 901310 · Mon–Fri 9am–5:30pm

// pricing

Straightforward, per-case pricing.

No hidden charges and no hard sell — a free assessment and a written quote before any work begins.

Forensic data recovery
From £800 + VAT
Basic forensic recovery is a fixed £800 + VAT after a free assessment. The cost depends on how many devices, the scope, and whether a written report or expert testimony is needed.
  • Free assessment and scope
  • Written quote before any work begins
// jobs off the bench

Evidence recovered, cases supported.

A few recent forensic recoveries, described only in the vaguest terms and kept strictly confidential.

// CASE 2026-039recovered
Company laptopDeparted employeeDeleted files

Files deleted before an employee moved on, recovered for a dispute.

The laptop was imaged behind a write blocker; we recovered the deleted documents plus a record of USB transfers, and wrote the findings up for the client’s solicitor.

// CASE 2026-032recovered
Desktop PCCivil claimTimeline

When exactly were the files changed? — a contract dispute.

Out of system logs and file metadata we built a factual timeline of access and edits, presented in a clear written report.

// CASE 2026-025recovered
External driveInsurance claimWiped

A drive wiped before an insurance investigation.

Traces of deleted data were recovered, and we confirmed what had gone and when, backing the insurer’s review.

// getting it to us

Two easy steps.

Send the device in for its free assessment and tell us briefly what’s at issue; an engineer reviews it and confirms your exact quote in writing before anything starts.

1

Send us your device

Getting your data back begins with getting the device to us. Pack it up safely, pop your contact details inside, and send it over — once we’ve run the free diagnostic, we’ll confirm your exact price in writing before any work starts.

How to pack it
  • Box the device up in a small, sturdy carton or a padded envelope.
  • You can leave out caddies, cables and power supplies — none of them are needed for the recovery.
  • Pop your details inside — name, address, phone and email, on a slip of paper or via our shipping form — and seal it up.
Post toGuildford Data Recovery
Building 2, Ground Floor, Guildford Business Park
Guildford GU2 8XH
Shipping formPDF · print & include with your devicePDF ↓

Posting it? A tracked, insured service is what we’d recommend. Rather drop it in? You’re welcome Monday to Friday, 9am to 5:30pm — just package the device up as above first.

2

Need more information?

Want a bit more detail first? Fill in the form with more about your issue and an engineer will review it and send you a custom quote.

An engineer reviews every enquiry personally — we usually reply within 30 minutes during the day. Prefer to call? 01483 901310.

Thanks — your message is in.

We’ll be in touch shortly. If it’s urgent, call 01483 901310.

// questions

Forensic recovery — your questions.

What people most often ask about forensic data recovery.

It means pulling data off a computer or drive in a way that keeps it sound as evidence. The original is never touched; the work is done on a bit-for-bit image captured through a write blocker and confirmed by cryptographic hash, and every step is written up so the results stand for HR, solicitors or a court.

They usually can. Until something overwrites them, deleted files and fragments tend to remain on the drive, and we recover them along with their timestamps and metadata. Since everything happens on a forensic image, the original device is left unchanged.

Because software run on the original writes to it, altering the timestamps and metadata that are themselves the evidence, and it can overwrite deleted data before anyone captures it — enough, forensically, to render findings inadmissible. We image behind a write blocker first and touch only the verified copy.

You will — a clear written report explaining what was found and how, in plain English suited to court, HR processes or solicitors. Where expert witness support is called for, we can talk that through.

Wholly. These matters are handled securely and discreetly, an NDA is no problem, and the findings reach nobody but you, or whoever you direct us to.

Only ones you’re entitled to have examined — your own or your organisation’s, or where you hold proper authority or a court order. We check that before we begin, and we won’t touch a device someone has no right to have examined.

Hard drives and SSDs, servers and NAS, USB drives, memory cards, external drives, and computers, laptops and workstations. Storage media and computers are our forensic remit — mobile phones we don’t handle.

Frequently. When a file was made, changed or deleted shows up across the file-system timestamps ($MFT created/modified/accessed), the $UsnJrnl change journal, event logs and other artefacts — and backdating gives itself away where those records contradict one another. We line them up into a timeline and report it plainly.

The first assessment costs nothing; from there it’s priced per case. A basic forensic recovery is a fixed £800 + VAT, moving with the number of devices, the scope, and whether you need a written report or expert testimony — and you get that quote in writing before any work.

Placed between the evidence drive and everything else, a write blocker allows reads while physically barring every write, so imaging can’t change the original — and hashing the image proves it matches the source. That’s what makes a forensic recovery defensible.

// need evidence?

Need it recovered? Let’s do it properly.

A free assessment, a forensic write-blocked image, deleted-data recovery and a clear written report. Talk to us in confidence today.