Recovery and forensic examination use overlapping equipment and produce very different things. One returns your files; the other proves nothing was altered along the way. If findings might be challenged — a tribunal, a court, a disciplinary hearing — that difference decides whether you have evidence or an assertion.
$ mdr image /dev/sdb → Device: Seized laptop HDD (1 TB) → Status: WRITE-BLOCKED — evidential image → Case: civil dispute · ref 2026-014 $ mdr engineer-working → Image hash: SHA-256 checked · confirmed against source → Deleted files: 4,210 recovered → Artifacts: metadata and timestamps kept intact $ mdr verify → ✓ documents — fully recovered → ✓ deleted items — carved and dated → ✓ findings — pulled back whole
Booting the machine, opening files or plugging the drive in changes timestamps and can trigger writes. That is the commonest way material is undermined before anyone has examined it properly — and it is usually done with good intentions.
They use overlapping equipment and produce very different things, and the choice cannot easily be made retrospectively.
Recovery returns your files. Nobody asks how, the process is not documented for scrutiny, and it is the right and cheaper answer for the overwhelming majority of situations.
Forensic work additionally proves that nothing changed. The source is read behind a hardware write blocker, hashed with SHA-256 so the copy can be shown to be bit-identical, and every step logged so an independent examiner could repeat it and reach the same result — following ACPO principles for digital evidence. If findings might be challenged in a tribunal, a court or a disciplinary hearing, that documentation is the difference between evidence and an assertion.
Windows and macOS record activity extensively, often long after the files themselves have gone.
The part that makes findings defensible rather than merely correct.
What was received, from whom, in what condition, sealed and referenced.
The source is read through hardware that physically prevents writes, so the original cannot be altered even accidentally.
SHA-256 computed at imaging and re-verified at each stage, demonstrating the working copy is identical to the source throughout.
Tools, versions, parameters and findings recorded so another examiner could repeat the work independently.
Findings set out in plain language for solicitors, HR or a tribunal, with the technical detail available as appendices rather than in the way.
One of the three exceptions here, for a reason worth explaining.
Forensic work starts from £800 +VAT, quoted after scoping, with a 50% deposit. Unlike most of our work it sits outside no fix, no fee — because establishing that nothing improper happened is a legitimate and valuable result, and the examination costs the same either way. A finding of nothing is still a finding, and often the one a client most wanted.
NDAs are standard, work runs through a single named contact, all data remains in the UK, and material is handled without examination beyond what the instruction requires.
Send the device in for its free assessment and tell us briefly what’s at issue; an engineer reviews it and confirms your exact quote in writing before anything starts.
Nothing can begin until the device is on the bench, which makes this the only step that needs anything from you. Pack it properly, put your details in with it, and send it over. What follows is a free diagnostic and a written figure, in that order.
Posting it? Use something tracked and insured — whatever is on the drive is worth considerably more than the postage. Bringing it in? Weekdays, 9am to 5:30pm, and it still wants packing as above for the journey.
Tell us what the device is, what it is doing, and anything already tried — an engineer will come back with a realistic view of the odds and a price band, before you commit to posting anything.
We’ll be in touch shortly. If it’s urgent, call 0161 871 0788.
What people most often ask about forensic data recovery.
Recovery returns your files. Forensic work additionally proves nothing changed — write-blocked imaging, SHA-256 hashing to show the copy is bit-identical, and a documented chain of custody following ACPO principles, so findings can be tested.
Often. USB device records, link files, jump lists, shellbags and file system timestamps together show what was attached and accessed and when — frequently including material that has since been deleted.
No, and this is where most evidence is compromised. Booting the machine or opening files changes timestamps and can trigger writes. If it might become evidence, preserve it exactly as it is.
That is what it is written for. Findings are set out in plain language for solicitors, HR or a tribunal, with technical detail in appendices for anyone who needs to test it.
That is a legitimate result and frequently the one the client hoped for. It is why forensic work is not offered on a no-fix-no-fee basis — establishing that nothing improper occurred takes the same examination as establishing that it did.
From £800 plus VAT, quoted after scoping, with a 50% deposit. Scope, media count and the questions being asked all affect it.
A free assessment, a forensic write-blocked image, deleted-data recovery and a clear written report. Talk to us in confidence today.