The bench is open for new cases · Mon–Fri, 9am–5:30pm Need it fast? Ring 0800 6890668
EDR Exeter Data Recovery 0800 6890668 Start my case
EDR / Evidence & investigations / Digital forensic investigations

Digital forensics · investigations across Devon

Digital forensics for Exeter. Recovered carefully, proven properly.

When a dispute is coming, how you handle the data matters as much as what it says. So nothing here is examined before it's imaged, every step goes in the log, and reports are written for a second expert — or a judge — to check line by line. Independent, discreet, and honest about exactly what this lab is and isn't.

Reports to CPR 35 / CrimPR 19 Custody chain logged throughout Confidential & even-handed

A quiet word, in confidence
0800 6890668

Four rules that never bend.

1 — Change nothingOriginal media that may end up before a court is never altered by us: it goes behind a write blocker and is imaged before examination starts.
2 — Touch it only if qualifiedIf original data must be accessed at all, whoever does it has to be competent — and able to explain to a court what they did and why it was necessary.
3 — Leave an audit trailEverything done to the exhibit is documented in enough detail that an independent examiner could repeat it and reach the same result.
4 — One person carries the caseResponsibility for the whole investigation — and for keeping to these four principles — rests with one named examiner.

What lands on this bench.

Not sure? Ring us →
What's wrongWhat the examination findsWhat's returned
One computer that could decide a disputeWrite-blocked imaging first, then artefact, file and timeline analysis on the copyPlain-English findings, in writing
A departed employee suspected of copying dataUSB history, cloud and webmail traces, deletions and wiper activity, put in sequenceMaterial your HR team and lawyers can act on
Deleted files that matter legallyProof of existence, timing and fate — recovered under forensic conditionsThe files, plus the when and the how
A locked volume you're lawfully entitled to openPassware attacks the encryption where a credential can be establishedOpened contents and a documented method
A matter heading for a hearingThe same analysis, reported to the CPR Part 35 standard, or to CrimPR Part 19A court-compliant expert report
Footage held on a DVR or CCTV systemRecovered with the continuity chain kept whole — the CCTV pages cover itPlayable video plus its continuity record
Posting it to us: kit and media reach our intake lab by tracked, insured post, with the return postage on us — or ring first and we settle the safest route for the job together. There's more on the contact page.

The job, stage by stage.

See the casebook →
01

Talked through in confidence, quoted in writing Free

Each new instruction starts with a confidential conversation — what has happened, which devices and accounts matter, and what the evidence needs to prove. You then receive a single written quote, fixed before any examination begins, and that opening scoping work costs nothing.

Scoped discreetlyOne price, set in writingExact question pinned down
02

Image before anything

Every exhibit is duplicated through a hardware write-blocker before anyone opens a file. The original is evidence, and browsing it is how evidence dies.

Write-blocked captureOriginal media untouched
03

Examine the copy

Analysis happens on the image, in tools like OSForensics: file activity, system artefacts, deleted data, timelines. Each action goes into the log as it's taken, not afterwards.

OSForensics analysisEvery step logged
04

Report without spin

Findings come back in plain language, addressed to the question you asked, with the technical detail underneath. If the answer isn't the one you hoped for, you still get it.

Answer in plain wordsTechnical detail appended
05

Captured, documented, court-ready

You receive everything: report, exhibits and the files behind them, plus the hashes, the continuity record and our working notes. If a tribunal or another expert wants to test it later, they can walk the whole trail step by step.

Report plus exhibitsHashes kept, continuity intactBuilt to survive scrutiny

Rules the bench works by

  • Our duty in court work is to the court — whichever side instructs us, and whoever pays, the conclusions stay the same.
  • The Forensic Science Regulator's Code — it has had statutory force since 2 October 2023, and Version 2 has been in effect since 2 October 2025 — governs forensic work for criminal justice in England and Wales; matters that are civil, employment or insurance fall outside its enforcement, and we'll tell you plainly which category yours is.
  • Phones and tablets get refused — half-handled evidence is worse than none, so we decline rather than dabble.
  • Discretion is structural — cases run under reference numbers, not names, and findings reach the instructing party alone.

The case for securing data privately, early: in December 2022 HMICFRS reported police digital-forensics queues of more than 25,000 devices awaiting examination; in June 2025 the Westminster Commission on Forensic Science found that, over a four-year span, England and Wales had seen more than 30,000 prosecutions fail for want of evidence — lost, missing or inadequate. Material preserved properly on day one never enters that queue.

Named tools, real jobs.

SystemWhat it handlesWhy we rate it
X-Ways ForensicsDeep examination of disk images — artefact review, activity records, deleted content, timelinesLean, fast, and suited to a lab our size using it thoroughly instead of superficially
OSForensicsSweeping, indexing and searching Windows installations and captured imagesBroad first-pass discovery: registry contents, recent-use traces, USB device history
PasswareOpening encrypted volumes when the instruction is lawful and a credential can be recoveredThe honest tool for encryption: it gets in or it doesn't, and we report which
Atola Insight ForensicForensic imaging, with hardware write protection and the hashing done in the same passAs the image is taken the acquisition log writes itself — an unbroken record from the outset
ACE Lab PC-3000 & Data ExtractorFirmware-level work on exhibits that are also failing drivesBeing half-dead doesn't stop a drive being evidence — it gets both disciplines at once

Straight about our standing

  • We do: run every case under the four ACPO/NPCC principles for handling digital evidence.
  • We do: image through write-blockers, hash each image with MD5 and SHA-256, and keep a custody record another examiner could audit.
  • We do: work with recognised tools — OSForensics for examination, Passware for lawful decryption — always on the image, never the exhibit.
  • We don't: claim UKAS or ISO accreditation, because we hold neither — and where court rules require credibility disclosure, that fact goes in first, in reports and in public.
  • We don't: examine phones or tablets, negotiate with ransomware crews, or soften conclusions for the side that pays.

The reason for the list: criminal procedure has, since 2019, required an expert to disclose anything that bears on their credibility — accreditation gaps included. Saying it plainly here isn't modesty; it's what keeps the evidence standing when someone attacks it.

Fresh from the casebook.

EX · EDR-2026-2521VERIFIED ✓

Where a Devon firm's project files went

One client was sure files had been stolen. The evidence pointed somewhere duller — a mis-set sync had stripped them from the shared drive, and most were recoverable. An honest answer ended the row faster than any accusation could have.

Dispute settledReport within 6 days

Before it leaves your hands.

Do

  • Stop using the machine — use changes it
  • List everyone who's handled it, with times
  • Keep leads, charger and passwords with the device
  • Call us before in-house IT starts investigating

Steer clear

  • Give IT first go at it — every click rewrites artefacts
  • Copy things off as a precaution
  • Confront a suspect before the data is preserved
  • Assume deletion means either destroyed or guilty

Asked in private, answered plainly.

What exactly is digital forensics?

Capturing, analysing and reporting electronic data in a way that survives scrutiny: the device is imaged before any examination, every action is logged, and the findings are written so another examiner could retrace them.

What's the typical price of a digital forensics investigation in the UK?

Every matter is priced on its own facts: a free scoping call, then a single written quote for imaging, analysis and reporting before work begins. Nothing runs on an hourly clock.

Can you take on mobile phones?

No. We work on drives, computers, storage media and CCTV equipment; handsets and tablets sit outside our scope. If a phone turns out to matter in your case, we'll tell you straight and point you towards a specialist.

Are you accredited for this?

We're an independent lab with neither UKAS nor ISO accreditation, and we say so plainly — our reports declare it too, as the rules require. Instead we offer a method you can inspect: write-blocker imaging, hash checks, a documented trail, reports to CPR 35 or CrimPR 19.

Evidence fades fast. Don't hang about.

Recorders overwrite on a loop, evidence weakens, time limits pass. Open a case early — the first look is free and confidential.

0800 6890668