A failed case-file server or a fee-earner’s dead laptop is rarely just a storage problem — how the device is handled in the first hour decides whether what comes back can be relied on later. Practices and chambers across Greater Manchester send us both kinds of job: straightforward recovery where speed is what matters, and forensically sound acquisition where it may be tested. Worked in-house, under NDA, with custody logged where it counts.
Matter files, practice databases and departing-employee machines — NDA as standard, one named contact, custody records where findings may be challenged, and nothing leaving the UK.
Starting the machine to see what is on it writes to the disk and moves timestamps before anyone has examined anything. That single action is the commonest way otherwise sound material is put beyond use. Leave it as it is and tell us at the first call.
The choice is difficult to make retrospectively, and it changes how the device is handled from the moment it arrives.
Recovery returns the files. Nobody asks how, the process is not documented for scrutiny, and for the overwhelming majority of matters it is the right and cheaper answer.
Forensic examination additionally proves that nothing changed — write-blocked acquisition, SHA-256 hashing so the copy can be shown bit-identical, and every step logged so an independent examiner could repeat it and reach the same result, following ACPO principles. Where findings may be tested in a tribunal, in court or at a disciplinary hearing, that documentation is the difference between evidence and an assertion.
If there is any prospect of the second, say so at the first call. Booting a machine or opening a file to check changes timestamps, and it is the commonest way material is undermined before anyone has examined it.
The four things practices actually send us.
The arrangement a practice needs before it can send anything at all.
NDAs are signed as standard and confidentiality is assumed rather than negotiated. Work runs through one named contact, data remains in the UK, and nothing is subcontracted to another laboratory.
Where material is privileged, tell us at the outset. We do not read what we recover — verification means confirming files open and the structure matches what you described, not examining content — and on privileged matters we will take your instruction on how you would prefer that verification handled, including not sampling documents at all if you would rather.
For departing-employee and disclosure matters in particular.
Windows and macOS record activity extensively, and much of it survives the deletion of the files themselves. USB device history shows which drives were attached and when. Link files, jump lists and shellbags show what was opened and which folders were browsed. Deleted material frequently recovers from unallocated space with its original timestamps intact, and those combine into an ordered account of what happened.
What can be established varies with the system and with how much has happened since — which is the argument for preserving the machine promptly rather than after a few weeks of continued use. Forensic work is from £800 +VAT after scoping, with a 50% deposit, and it sits outside no-fix-no-fee because establishing that nothing improper occurred is a result with real value.
Get in touch for a free diagnostic and written quote — NDA in place, work kept in-house, custody logged wherever it's called for.