Call us — 0113 322 3083
Mon–Fri · 9am–5:30pm · No fix, no fee
Start a free diagnostic →
Service · encryption & passwords

Encrypted, locked, or password-forgotten.

A drive asking for a password no-one knows. The BitLocker screen after an update. An encrypted external whose passphrase went with a previous member of staff. If there is a way into the key, and it is your drive or you have permission to look at it, then we can often find, or extract, the key. In cases where there isn’t a way into the key, we will tell you on day one (free) instead of selling you false hope. That transparency is all that our service is.

In-house, never outsourced
Owned or authorised devices only
Only pay if we recover your data, on most jobs
// the honest line

What this is — and what it isn’t.

Modern encryption (when done properly) cannot be broken. AES-256 will keep your data locked up as long as there is no access to the decryption key anywhere in the world: no one has the ability to recover the key or obtain an escrow of it; no one knows your password and no Trusted Platform Module (TPM) will issue it. If anyone tells you this isn’t true, they are trying to sell you something.

What we can do as far as unlocking is completely different and worthy of understanding. Almost all real-world “lockouts” have a path to the key other than brute force/cipher cracking, such as using information from the organisation or a third party (recovery key escrowed to an account/company directory). The key is visible and clear on the hard disk (not removed from the drive) where BitLocker had been stopped instead of totally disabled. The key may be reachable due to a previously discovered vulnerability in the hardware encryption. Or, the password is weak enough to be recovered. Our Passware Kit based toolset, in conjunction with all of our bench tools, is designed to search for and exploit all of these routes to your data. In practice that means searching the actual drive (an image of the drive, for an escrowed or clear key) and its hibernation file, plus a memory capture, if one was taken while the system was still running. We work from the drive alone: we don’t accept complete laptops or computers, so we don’t pull keys from a machine’s security chip.

There is a rigid rule tied to this work: it will be performed only on hardware you either personally own, or have legitimate authority to review. Law enforcement agencies, governmental organisations, and companies needing a valid business justification may use Passware’s product for their investigative (forensic/corporate) needs. Passware has to vet each of these requests, and we apply the same test. A locked device owned by you, or a company-owned device reviewed in accordance with that company’s policies: yes. Anyone else’s phone or account: no. See forensic recovery for exactly what this line is.

// bitlocker

BitLocker, with the recovery key.

The most common encrypted job, far and away. In fact, most BitLocker “lockout” situations are resolved with relative ease when the recovery key (wherever it may have been stored) is found, either via an individual’s Microsoft account if they used their own PC, or via Entra ID, Active Directory or some form of enterprise management platform if it was a work device, and BitLocker recovery will cover all of these options completely.

If the recovery key has never been stored anywhere, there is usually no way in from the drive alone. For volumes protected by TPM (Trusted Platform Module), the key is held by a chip on the computer’s motherboard, and getting it from there means working on the whole machine, which we don’t do: we only take the drive on its own, and we don’t accept complete laptops or computers. So without a recovery key, a password, or a key left in the clear by suspended protection, a BitLocker drive can’t be unlocked, and we will tell you so at the free diagnostic.

The same goes for Lenovo ThinkPad laptops and every other make: please take the drive out of the laptop and send it on its own, along with any recovery key or password you have.

// apple

T2 and Apple Silicon Macs.

All Mac computers that include a T2 security chip, and all Apple Silicon Macs, use it to encrypt their SSD storage, and that storage is soldered to the logic board, so it can’t be taken out and the data can only be unlocked by the machine itself. Older Mac models with a removable drive are different: take the drive out and send it to us, with your password or recovery key if FileVault is turned on. For T2 and Apple Silicon Macs, though, we can’t help: we only work on drives that have been removed and don’t accept complete Macs, so we can’t recover their data or remove a firmware password from them.

// encrypted drives

Hardware-encrypted external drives.

A lot of external hard drives have encryption that is done entirely in the physical device itself. Lockouts from forgotten passwords are pretty typical as well. We support the following types of cases:

  • Western Digital My Book (2021–2024, 4TB and 6TB) and My Passport (2014–2024) with built-in 256-bit AES: the encrypted data can be unlocked, decrypted, and the original protection password recovered.
  • Seagate/LaCie: password recovery on their hard drives from 2018–2022, including multi-account disks, using GPU acceleration.
  • Transcend portable SSDs from 2022 to 2025 using the SM2320 controller: recover password and unlock.

These cases are model and year specific; there is no one-size-fits-all solution. Each case has its own unique characteristics based on how the manufacturer implemented the encryption. We do not accept an unsupported model or year. At the diagnostic, we will tell you if we can help.

// forensic use

The forensic side, done lawfully.

The same abilities will provide for real examinations (such as an enterprise client reviewing their company device, or a case directed by a lawyer), and in those cases the rules are stricter, rather than looser. The device must either belong to, or have been authorised for review by, the directing party; the scope of the review must be defined in writing prior to beginning any review; and all items reviewed will follow a documented chain of custody (CoC) process using hash-verified images, thus assuring the results will withstand scrutiny. Forensic recovery explains how this occurs in practice and which requests we reject. Our encryption capability does not change this boundary: no ownership or authority, no work.

// questions

Asked often, answered straight.

No. If there is an escrow for your recovery key (such as in a Microsoft account, in a company’s Entra ID or Active Directory), we are generally able to recover it. We don’t work on the TPM chip in the computer itself, as we only take the drive on its own. Without any form of escrowed key and without any recoverable password, BitLocker is meant to be unbreakable. And so far, it has been. We will tell you which one this is at the time of our complimentary diagnostic.

Often, yes, if it is one of the supported models and years (WD My Book and My Passport, Seagate and LaCie disks from the supported ranges, and Transcend SM2320 SSDs), we can recover their original password. After you receive a quote, please bring or post your entire drive; we will confirm at the diagnostic whether yours falls within a recoverable range prior to any charge.

No. This is completed only on those devices which you own or are lawfully authorised to examine: your own drive; or a company drive as per your employer’s policy; or a matter that has been instructed by a lawyer. We never access anyone else’s smartphones, laptops or accounts, regardless of the reasons. This is both a legal requirement and our own company policy.

Completely. All devices remain in-house, in the hands of our own engineers, and are subject to a documented chain of custody, with an NDA for all business and forensic work (as part of our ICO registration ZC173784); nothing is sub-contracted.

0113 322 3083