Two things usually matter about a file that has gone: what it was, and how it went. A disk normally keeps enough to answer both. Bin records, journal entries and volume snapshots between them show what a machine held, how it was used, and at what hour — and by what method — something was taken off it. For Norfolk employers, solicitors and private clients with a removal in dispute.
◇ Scope first, then work. The free diagnostic comes at the start and the written scope follows it; forensic fees are paid in full before an examination begins. No fix, no fee all jobs except electronic and mechanical failures, chip level work, DVR and Forensic jobs. Full pricing is on the data recovery cost page.
The work suits any matter where what went, and the hour it went, carries weight.
Removal comes in grades and each leaves its own mark. Send a file to the recycle bin and a small record is created alongside it, holding the path it came from, its size, and the instant it went; that record commonly outlives the emptying of the bin. Delete permanently and the bin is skipped, but all that is surrendered is the entry in the index — the contents sit where they are until something else needs the space. Which grade applied, and when, is normally the first thing established, and it frequently says something about intention.
A timeline is nothing more than recorded events arranged in sequence from sources that check each other. The $MFT carries creation, modification and access times for every file. $UsnJrnl logs the operations themselves as they occur: made, renamed, removed. $LogFile supplies fine detail around the minutes in question. Event logs supply the account that was signed in and what it opened or altered beforehand. Set against the date a file was created, the hour it disappeared answers the question worth asking: housekeeping, or timing?
A workstation holds more than one version of its own past. Volume Shadow Copies, made for restore points and backups, keep earlier states of the disk, including files that went afterwards and drafts from before an edit. Set a snapshot beside the live volume and what disappeared between two dates shows plainly. That is often the tidiest exhibit a removal case can offer: there on the 3rd, absent on the 10th, with the journal timing the removal at the 7th.
Wiping software is not a quiet visitor. Detection starts from what the tools themselves leave: installer records and prefetch entries carrying the program's name, the times it ran, the signature overwriting leaves across the disk, and the noticeable absence of traces that should be present. A wipe destroys content and creates evidence in the same pass — the utility, the hour, the account behind it, and whatever it did not reach. Runs that were partial or interrupted are common, and what survives one is recovered as usual.
The imaging and custody discipline underneath this page is set out at the forensic recovery hub. Removals involving sticks and cards continue on USB device forensics, and whole-machine capture on workstation deep imaging. Costs are on the prices page.
Every source is read against the others, and the timeline rests on where they agree.
Original path, size and the instant of removal, outliving an emptied bin.
Creation, modification and access times for live and deleted alike.
Files made, renamed and removed, taken one operation at a time.
The account signed in around each removal, from the system's own logs.
Earlier states of the disk, holding what has disappeared since.
Which utility ran, the hour, the account, and what it left behind.
Each instruction opens with the free diagnostic, which takes 2 working days from the day a device reaches the bench. Forensic casework itself falls outside no fix, no fee. The full forensic investigation with report is £800 + VAT, payable 100% upfront. The less expensive Forensic binary image and deleted-file extraction service, without the report, is £400 + VAT. Any Forensic work required will be payable upfront. Both figures also appear on the prices page, and no money is taken until a written scope has been agreed.
Removal work runs on company machines, on devices of your own, or under a solicitor's instruction. Three footings open the door and there is no fourth: kit the company itself owns; a written instruction from solicitors, an insurer or the court; or a device that is genuinely the client's, which in a family matter means their own machine or one owned jointly. We do not hack. Live communications are not intercepted. Where a client has no right to look inside a device, neither have we.
Ordinary use costs a removal case a little every day, so withdraw the machine and call 0800 689 0668. Collection is not offered: it reaches our Cambridge location by tracked, insured post or over the counter, and joins the custody file at the signature.
Is the drive still bolted inside a laptop, desktop, MacBook, iMac, server or CCTV / DVR recorder? The hard drive or SSD needs to come out first, and only the bare drive travels — taking drives out of machines is not something we do here. Storage soldered to a motherboard (Apple Silicon Macs, one or two very thin laptops) is the single thing beyond us: if it will not come out, it cannot come in.
↓ Print the shipping & booking-in form (PDF)
Mark the parcel for the attention of Cambridge Data Recovery. From Norwich it is about an hour and twenty down the A11, then two minutes off the A14 at Junction 32 — or next working day by tracked post. You hear from us as soon as it is booked onto the bench.
Unsure what to put in the box? Ring 0800 689 0668 before you seal it, or run the free online diagnostic.
Take the machine out of use, ring the freephone, and let the sequence do the talking.