A returned laptop has one forensic moment, and it falls between hand-back and rebuild. Captured in that window — read through a write-blocker, into E01 evidence files, checked by SHA-256 — it will keep answering questions for years. Put back into service, it answers fewer with every passing week. For employers in Norfolk the rule is simple enough: the questions will keep, the image will not.
◇ Scope first, then work. The free diagnostic comes at the start and the written scope follows it; forensic fees are paid in full before an examination begins. No fix, no fee all jobs except electronic and mechanical failures, chip level work, DVR and Forensic jobs. Full pricing is on the data recovery cost page.
One of these is enough to put a machine on the list, well ahead of the rebuild queue.
The arithmetic is lopsided. Taking an image today — the disk read behind a write-blocker into E01 evidence files and checked by SHA-256 — costs a fraction of what that same evidence is worth once there is a dispute to spend it on, and the hardware goes back into service afterwards, because the evidence no longer depends on it. Leave the image untaken, hand the laptop on, and each day of a new user's work sits over the top of the last user's traces. Firms that capture leavers' machines as a habit are never left explaining a hole.
Considerably more than the documents. Browsing history, cache and cookies put research and uploads back together. Drafts and copies nobody ever deliberately saved sit in the temporary files. Pieces of whatever was in memory — a document left open, a chat window, now and again a credential — survive in the pagefile and the hibernation file. Slack and Teams keep local caches that give back conversations since deleted out of the apps. Which networks the machine was on, and at what hour, comes from the VPN and connection logs. A rebuild takes all of it away; a capture keeps it.
Encryption repays early attention. Where a device is protected by BitLocker or FileVault it should be imaged while its keys are still in escrow and its passwords still known — ahead of the leaver's account being closed, the directory being tidied, or a rebuild clearing the TPM. On a Windows volume that is live and unlocked there is a second route: Volume Shadow Copies pulled from the running system, which step around the encryption question because the volume is open while you are holding it. Encrypted-volume work is Forensic-classed and, as with everything on this page, payable upfront once the scope is agreed.
A claim of wiping is tested rather than accepted. Erase utilities and boot tools — DBAN among them — leave evidence of their own: boot records, signatures belonging to the tool, the pattern an overwrite leaves behind, and timing that can be pinned against everything else going on that week. Runs that were interrupted or only partial happen often and leave whole regions recoverable, and a hardware erase command can be read against the drive's own logs. Where the wipe really did finish, the report says so and gives the date, since wiping a drive deliberately as proceedings approach is a finding all by itself.
Custody and verification are described at the forensic recovery hub. What removal evidence looks like on a copy belongs to deleted-file forensics, and the duty to preserve to legal hold and chain of custody. Costs are on the prices page.
Taken once, verified, and there for whatever the dispute asks afterwards.
The disk entire, in the container other examiners can open and check.
SHA-256 showing the image, and every copy taken from it, unaltered.
History, cache and cookies rebuilding research and uploads.
Pagefile and hibernation contents: documents, chats, credentials.
Local Slack and Teams stores, deleted conversations brought back.
VPN and network traces putting the machine on networks at set hours.
Each instruction opens with the free diagnostic, which takes 2 working days from the day a device reaches the bench. Forensic casework itself falls outside no fix, no fee. The full forensic investigation with report is £800 + VAT, payable 100% upfront. The less expensive Forensic binary image and deleted-file extraction service, without the report, is £400 + VAT. Any Forensic work required will be payable upfront. BitLocker and other encrypted-volume work is Forensic-classed and payable upfront on the same terms. Both figures also appear on the prices page, and no money is taken until a written scope has been agreed.
Imaging runs on company-owned machines, on hardware of your own, or under a solicitor's instruction. Three footings open the door and there is no fourth: kit the company itself owns; a written instruction from solicitors, an insurer or the court; or a device that is genuinely the client's, which in a family matter means their own machine or one owned jointly. We do not hack. Live communications are not intercepted. Where a client has no right to look inside a device, neither have we.
Tell us the machine count and where you stand on encryption when you call 0800 689 0668, and the capture is scoped in writing. Collection is not offered: drives come by tracked, insured post or over the counter at our Cambridge location, and custody is logged at the signature.
Is the drive still bolted inside a laptop, desktop, MacBook, iMac, server or CCTV / DVR recorder? The hard drive or SSD needs to come out first, and only the bare drive travels — taking drives out of machines is not something we do here. Storage soldered to a motherboard (Apple Silicon Macs, one or two very thin laptops) is the single thing beyond us: if it will not come out, it cannot come in.
↓ Print the shipping & booking-in form (PDF)
Mark the parcel for the attention of Cambridge Data Recovery. From Norwich it is about an hour and twenty down the A11, then two minutes off the A14 at Junction 32 — or next working day by tracked post. You hear from us as soon as it is booked onto the bench.
Unsure what to put in the box? Ring 0800 689 0668 before you seal it, or run the free online diagnostic.
One capture holds every answer the machine has left in it — ring the freephone.