An ordinary recovery is judged on whether the files come back. A forensic one is judged, months afterwards, on whether the account of how they came back stands up to somebody paid to doubt it. So the device is copied once, the hashes are written down, and the findings are put in language a tribunal can follow — for insurance and legal offices in the city centre, for HR teams at food and agricultural firms across mid-Norfolk, and for engineers in the offshore wind supply chain working out of Great Yarmouth.
◇ Scope first, then work. The free diagnostic comes at the start and the written scope follows it; forensic fees are paid in full before an examination begins. No fix, no fee all jobs except electronic and mechanical failures, chip level work, DVR and Forensic jobs. Full pricing is on the data recovery cost page.
Any competent engineer can lift files off a failing disk. What forensic work adds is the part that survives an argument: an account, written at the time, of how those files were obtained. The order never changes here. The drive is read through a hardware write-blocker and copied into E01 evidence files. That copy is checked by SHA-256 against what it came from. The exhibit is sealed, labelled and entered in the custody file, and from then on the questions go to the copy. Each finding is numbered, dated and pointed at the trace it rests on. That discipline is the whole of what digital forensics offers over a straight recovery.
The pages below fall under three headings. Detection and evidence recovery is the finding work: what took place on a machine, on a card, or inside a cloud tenancy. Legal and chain of custody is the keeping work: preservation, hashing, storage, and a file that will bear being read closely. Insider investigation is where those first two are aimed at a named dispute and a set of dates.
Four services pointed at what actually happened: material that was deleted and when it went, files moving onto sticks and cards, exits through a mailbox or a cloud account, and the whole machine taken down in one capture.
Evidence is only ever worth what its handling can demonstrate, which makes preservation, hashing, storage and the custody file a job in their own right. Locked and wiped machines belong with workstation deep imaging: BitLocker and FileVault devices copied while their keys can still be reached, and erase runs picked up and given dates.
Where the subject is a person rather than a box: logins put to the wrong use, the records a server keeps, and then the four instructions that reach us most often.
Whichever page brought you in, the work underneath it looks like this.
A hardware write-blocker stands between exhibit and bench, so nothing done at this end can reach the drive it came from.
Drives are copied into E01 files, a format other examiners can open, check and work through again for themselves.
SHA-256 is computed when the copy is made and repeated later; an image that has moved cannot pass quietly.
Indexing, artefact extraction, recovery of deleted material and timeline building all happen against the copy.
Locked documents, sealed archives and whole encrypted volumes come open under Passware, but only where the client holds a right to what is inside.
Signatures, seals and movements are written down, from arrival at our Cambridge location through to the exhibit going home.
Each instruction opens with the free diagnostic, which takes 2 working days from the day a device reaches the bench. Forensic casework itself falls outside no fix, no fee. The full forensic investigation with report is £800 + VAT, payable 100% upfront. The less expensive Forensic binary image and deleted-file extraction service, without the report, is £400 + VAT. Any Forensic work required will be payable upfront. CCTV / DVR, BitLocker and ransomware cases are Forensic-classed and payable upfront on the same terms. Both figures also appear on the prices page, and no money is taken until a written scope has been agreed.
Employers, HR departments and solicitors send in most of this work; a private client is taken on the same footing. Three footings open the door and there is no fourth: kit the company itself owns; a written instruction from solicitors, an insurer or the court; or a device that is genuinely the client's, which in a family matter means their own machine or one owned jointly. We do not hack. Live communications are not intercepted. Where a client has no right to look inside a device, neither have we.
An exhibit is not an ordinary parcel. Ring 0800 689 0668 before it moves and we will settle packaging, paperwork and timing between us. Collection is not offered, so it comes by tracked, insured post, or over the counter at reception at our Cambridge location, where the custody file opens at the signature.
Is the drive still bolted inside a laptop, desktop, MacBook, iMac, server or CCTV / DVR recorder? The hard drive or SSD needs to come out first, and only the bare drive travels — taking drives out of machines is not something we do here. Storage soldered to a motherboard (Apple Silicon Macs, one or two very thin laptops) is the single thing beyond us: if it will not come out, it cannot come in.
↓ Print the shipping & booking-in form (PDF)
Mark the parcel for the attention of Cambridge Data Recovery. From Norwich it is about an hour and twenty down the A11, then two minutes off the A14 at Junction 32 — or next working day by tracked post. You hear from us as soon as it is booked onto the bench.
Unsure what to put in the box? Ring 0800 689 0668 before you seal it, or run the free online diagnostic.
Free diagnostic, a scope in writing, images that verify. Ring the freephone and we will say what the machine can and cannot settle.