Call us — 0161 871 0788
Mon–Fri · 9am–5:30pm · No fix, no fee
Start a free diagnostic →
Forensics · how it works

Recovery returns the files. Forensics proves nothing changed.

They use overlapping equipment and produce very different things. If findings might be tested — a tribunal, a court, a disciplinary hearing, an insurance claim — that difference decides whether you have evidence or an assertion.

Write-blocked imaging
Hashed and verified
From £800 +VAT
// the short version

One proves the data. One proves the handling.

Technically the two overlap almost entirely. What separates them is that nothing may write to the original, everything is hashed so alteration would be demonstrable, and each step is logged well enough to repeat months later.

Hash
Proves integrity
ACPO
UK principles
Log
Every step
£800
From, +VAT
×The most common way evidence is spoiled is by someone looking at it first. Booting the machine, opening files to check, or plugging the drive in to see what is there all change timestamps and can trigger writes. If a device may become evidence, stop using it and hand it over as it is.
// three mechanisms

Write blocker, hash, log.

The technical basis for the claim that nothing was altered.

01

A hardware write blocker

Physical hardware between the evidence drive and the workstation that passes read commands through and refuses write commands at the interface level. Not a software setting that could be misconfigured — the drive cannot be written to even by accident.

02

Cryptographic hashing at acquisition

A SHA-256 hash is computed across the source during imaging and again across the resulting image. Matching values demonstrate the copy is bit-identical. Change a single bit and the hash changes completely, so any later alteration is detectable.

03

Re-verification at each stage

The hash is recalculated whenever the image is used. If it still matches the acquisition value, the working copy is provably unchanged since it was taken.

04

Contemporaneous logging

Tools, versions, parameters, timestamps and findings recorded as the work proceeds — so an independent examiner can repeat the process and reach the same result.

// chain of custody

Who held it, and when.

The administrative half, and the half that fails most often.

Chain of custody is a documented, unbroken record of who had the item from seizure to report: a signed exhibit record on receipt describing what arrived and in what condition, sealed storage with restricted access, and a logged entry for every movement or handling event.

It matters because the technical work can be flawless and still be undermined by a gap. If there is a period where nobody can say where the drive was or who could reach it, the opposing position is straightforward — and it is an argument about paperwork rather than about the findings.

In the UK this follows ACPO principles for digital evidence, which in practice mean: do not change the original; if you must, be competent to do so and explain why; keep a record another examiner could follow; and the person in charge is responsible for compliance.

// what can be established

More than most people expect.

Windows and macOS record activity extensively, and much survives deletion of the files themselves.

USB device history

Which removable devices were connected, when, and often what was copied — recorded in the registry and system logs regardless of whether the files remain.

Exfiltration

File access artefacts

Link files, jump lists and shellbags record what was opened and which folders were browsed, including material since deleted.

Activity

Deleted material with timestamps

Recovered from unallocated space with original creation and modification times intact, which is frequently what matters more than the content.

Timeline

A reconstructed sequence

File system, registry and log timestamps combined into an ordered account of what happened and when.

Narrative
// before you touch it

One instruction that decides everything.

And it is the one most often ignored, usually with good intentions.

Do not examine it first. Booting the machine changes timestamps across hundreds of files, may trigger updates, and can start writing before anyone has looked. Opening a document to check whether it is the right one alters its last-accessed time. Copying files off with a file manager creates no record of what was there.

If there is any prospect the material becomes evidence, preserve it exactly as it is and say so at the first call — it changes handling from the moment it arrives. Where a routine recovery later turns out to involve a dispute or a data breach, having imaged it properly at the outset costs nothing and keeps every option open.

Forensic work is from £800 +VAT after scoping, with a 50% deposit, and it sits outside no fix, no fee — because establishing that nothing improper occurred is a legitimate result and takes the same examination as establishing that it did.

// questions

Your questions, answered.

Recovery returns your files. Forensic work additionally proves nothing changed — write-blocked acquisition, SHA-256 hashing showing the copy is bit-identical, and a documented chain of custody following ACPO principles.

Hardware placed between the evidence drive and the workstation that passes read commands through and refuses writes at the interface level. Because it is physical rather than a software setting, the source cannot be altered even by accident.

A SHA-256 hash computed at acquisition and re-verified later demonstrates the working copy is bit-identical to the source. Changing a single bit changes the hash completely, so any alteration after acquisition is detectable.

An unbroken documented record of who held the item and when, from receipt to report. The technical work can be flawless and still be undermined by a gap where nobody can say where the drive was or who could reach it.

Often. USB device records, link files, jump lists, shellbags and file system timestamps combine to show what was attached and accessed and when — frequently including material that has since been deleted.

No, and this is where most evidence is compromised. Booting changes timestamps across hundreds of files and may trigger writes; opening a document alters its access time. Preserve it exactly as it is and say so when you call.