Material leaving by mailbox or cloud account is recorded twice, once by the machine and once by the service, and a sound investigation reads both sides. Rules, attachment history and sign-in patterns come out of the tenancy; browser and sync traces come off the device; the two are lined up into one dated account of what went where. For insurers, brokers and professional firms in the city centre, and the advisers acting for them.
◇ Scope first, then work. The free diagnostic comes at the start and the written scope follows it; forensic fees are paid in full before an examination begins. No fix, no fee all jobs except electronic and mechanical failures, chip level work, DVR and Forensic jobs. Full pricing is on the data recovery cost page.
Each has an innocent explanation. Together they make a pattern worth looking at.
A mailbox being used to move material behaves in ways you can recognise. Attachments grow while the recipients narrow to a single private address. A rule appears, sending selected mail outward without anybody watching. The search history looks like hunting — customers, project names, price lists — rather than the day's work. Access drifts into evenings and weekends. The mail platform notes all of it, and each item is retrieved and given its date during the examination.
The device supplies the other side of it. Browser traces record accounts being created and signed into at Dropbox, OneDrive and Google Drive from a company machine. Sync-client logs and folder layouts reveal the directories that had been set to mirror upward, and from what date. The residue of an upload — cached pages, confirmations, recent-file lists — sits on the image long after somebody has cleared the browsing history. A private account appearing on work hardware in a final month is seldom there for nothing.
Microsoft 365 and Google Workspace keep evidence of their own, and it often decides the matter. Message movement, sharing and downloads are recorded in Purview audit logs and eDiscovery exports. Mail and files are held under Google Vault. Every share and bulk download appears in the SharePoint and OneDrive logs with an account and an hour beside it. Dropbox keeps version histories and recoverable deletions. A mailbox that has been deleted can frequently be brought back out of retention or backup — but only for a while, which is the argument for ringing early.
The finding that persuades is the one that agrees with itself. A 2.1 GB download is logged by the tenancy at 21:14. The same files appear in a private sync folder on the device two minutes afterwards. Browser history closes the circle. Service evidence and machine evidence are assembled into a single run of events, disagreements between them are flagged rather than smoothed over, and everything — mailbox export, audit extract, the image itself — is hashed before an account is suspended or a licence taken back.
The method behind all of it is at the forensic recovery hub. Logins and server records carry on at insider threat forensics, the employer casework at employee data theft, and holding material at legal hold and chain of custody. Costs are on the prices page.
Service records and machine traces, read against each other and presented as one sequence.
What went to private addresses, at what size, on which days.
Forwarding and deletion rules, when they were made and what they caught.
Sign-in hours and places, with the clusters outside working time marked.
Accounts, sync folders and upload leftovers on the work machine.
Sharing, download and export events out of M365 and Workspace logs.
Messages and whole mailboxes brought back from retention and backup.
Each instruction opens with the free diagnostic, which takes 2 working days from the day a device reaches the bench. Forensic casework itself falls outside no fix, no fee. The full forensic investigation with report is £800 + VAT, payable 100% upfront. The less expensive Forensic binary image and deleted-file extraction service, without the report, is £400 + VAT. Any Forensic work required will be payable upfront. A scope covering several accounts, or a whole tenancy, is quoted in writing after the free diagnostic. Both figures also appear on the prices page, and no money is taken until a written scope has been agreed.
Mailbox and cloud work runs on company tenancies and on company devices, or on a solicitor's written instruction. Three footings open the door and there is no fourth: kit the company itself owns; a written instruction from solicitors, an insurer or the court; or a device that is genuinely the client's, which in a family matter means their own machine or one owned jointly. We do not hack. Live communications are not intercepted. Where a client has no right to look inside a device, neither have we.
Cloud material is often preserved by export rather than by parcel. Call 0800 689 0668 and we will work through what can be captured remotely and what has to travel. Devices reach our Cambridge location by tracked, insured post or over the counter, with custody logged from the signature.
Is the drive still bolted inside a laptop, desktop, MacBook, iMac, server or CCTV / DVR recorder? The hard drive or SSD needs to come out first, and only the bare drive travels — taking drives out of machines is not something we do here. Storage soldered to a motherboard (Apple Silicon Macs, one or two very thin laptops) is the single thing beyond us: if it will not come out, it cannot come in.
↓ Print the shipping & booking-in form (PDF)
Mark the parcel for the attention of Cambridge Data Recovery. From Norwich it is about an hour and twenty down the A11, then two minutes off the A14 at Junction 32 — or next working day by tracked post. You hear from us as soon as it is booked onto the bench.
Unsure what to put in the box? Ring 0800 689 0668 before you seal it, or run the free online diagnostic.
Retention windows close on their own schedule rather than yours — ring the freephone first.