The bench is open for new cases · Mon–Fri, 9am–5:30pm Need it fast? Ring 0800 6890668
EDR Exeter Data Recovery 0800 6890668 Start my case
EDR / Evidence & investigations / Digital evidence & forensics

Investigations & evidence · forensically sound recovery

Forensic data recovery, Exeter. Recovery that survives the other side's expert.

Ordinary recovery asks one thing: did the files come back? Forensic recovery adds two more: is the original provably unchanged, and could another examiner repeat the work? Write blockers, hash checks and notes made as the job runs answer those — live, not in hindsight.

Reports to CPR 35 / CrimPR 19 Custody chain logged throughout Confidential & even-handed

A quiet word, in confidence
0800 6890668

What separates a copy from an exhibit.

The write blockerHardware between exhibit and workstation that lets data out but physically refuses to let anything in. Rule number one of evidence handling, cast in silicon.
E01 and raw imagesComplete sector-level duplicates — usually Expert Witness Format, which carries its checksums and metadata internally, or plain dd where the instruction calls for it.
MD5 & SHA-256 hashingFingerprints computed at acquisition and verified on completion. Identical values prove a faithful copy — and any examiner anywhere can rerun the calculation.
Exhibit continuityNumbered items, sealed storage, movement logging and notes made in the moment — precisely the records opposing counsel asks for first.

The problems this service answers.

Not sure? Ring us →
What's wrongWhat the examination findsWhat's returned
Files deleted, innocently or otherwiseProof they existed, when they vanished, and what portion can returnRecovered data with the method documented
A drive attacked with wiping softwareThe tool's identity, its run window, and everything it missedThe survivors, and their locations
BitLocker or another encrypted volumePassware decryption where a lawful key or password can be establishedAccessible contents plus a recorded method
An exhibit that is also a failing driveThe same careful imaging any failing drive gets here, wrapped in the full evidential processData back, continuity never broken
Disagreement about when something happenedTimestamps and file-system artefacts, interpreted together with their limits statedAn honest event sequence, caveats included
Posting it to us: kit and media reach our intake lab by tracked, insured post, with the return postage on us — or ring first and we settle the safest route for the job together. There's more on the contact page.

The job, stage by stage.

See the casebook →
01

Talked through in confidence, quoted in writing Free

Each new instruction starts with a confidential conversation — what has happened, which devices and accounts matter, and what the evidence needs to prove. You then receive a single written quote, fixed before any examination begins, and that opening scoping work costs nothing.

Scoped discreetlyOne price, set in writingExact question pinned down
02

The blocker comes first

The exhibit touches nothing except a hardware write blocker, through which a bit-for-bit copy is taken — E01 with its built-in checksums, or raw format on request.

Hardware write-blockersSector-level E01 / raw
03

Hash twice, trust once

MD5 and SHA-256 values are computed during acquisition and recomputed against the completed image. Matching sums are mathematical proof the copy equals the source.

MD5 alongside SHA-256Verified prior to analysis
04

Everything happens on the image

Deleted, damaged or encrypted material is recovered from the image under a continuous audit trail; where you hold lawful authority and credentials can be established, Passware opens locked volumes.

Deleted data recoveredPassware for locked volumes
05

Captured, documented, court-ready

You receive everything: report, exhibits and the files behind them, plus the hashes, the continuity record and our working notes. If a tribunal or another expert wants to test it later, they can walk the whole trail step by step.

Report plus exhibitsHashes kept, continuity intactBuilt to survive scrutiny

Rules the bench works by

  • E01 audits itself — checksums and metadata live inside the image file, so tampering after the fact announces itself.
  • An unverified hash proves nothing — the value only counts once recomputed against the finished image and matched.
  • Contemporaneous notes or no notes — documentation reconstructed later is the first thread an opposing expert pulls.
  • Failing hardware doesn't excuse shortcuts — a dying drive still goes through the blocker, still gets imaged and hashed, just more gently.

Where the statutory line sits: in England and Wales, forensic work for criminal investigations and criminal proceedings falls under the Forensic Science Regulator's Code — statutory from 2 October 2023, with version two applying from 2 October 2025. Civil, employment and insurance instructions fall outside its enforcement. Our process is identical either side of that line — and we'll tell you which side your matter is on.

Fresh from the casebook.

EX · EDR-2026-2527VERIFIED ✓

A wiped laptop, and the quarter-hour that decided it

An employee on their way out ran a wiping tool the evening before the laptop went back. The image gave up the tool's own logs, exactly when it ran and which files it missed — and from there the whole sequence of events fell into place.

Chronology verifiedReport inside 8 days

Before it leaves your hands.

Do

  • Power down; don't be tempted to check it
  • Keep a list of who's handled it and when
  • Retain cables, docks and any known passwords
  • Flag early if this may go legal

Steer clear

  • Let anyone 'have a quick look' beforehand
  • Run recovery tools on the original drive
  • Break seals or open the enclosure
  • Delay — artefacts fade and space gets reused

Asked in private, answered plainly.

What makes digital evidence admissible?

Briefly: data nobody has altered, a competent examiner, an audit trail a stranger could repeat, and relevance. Imaging via write-blockers, hashes and contemporaneous notes show the first three rather than merely assert them.

What's a write-blocker for?

Hardware that lets a drive be read while making writes physically impossible, so the original leaves exactly as it came in — and demonstrably so.

Can you unlock an encrypted drive?

Yes — provided whoever instructs us has lawful authority and there's a realistic route to the password or key. Passware does that work, always run against the image, with the method written up. Where no key exists, strong encryption simply stays shut — and we say so early on.

How is forensic work different from ordinary recovery?

The technique overlaps a great deal; the difference is evidential weight. Forensic work adds write-blocking, hashing, a continuous exhibit trail and notes made at the time — so what we find stands up when someone is being paid to attack it.

Evidence fades fast. Don't hang about.

Recorders overwrite on a loop, evidence weakens, time limits pass. Open a case early — the first look is free and confidential.

0800 6890668