Call us — 0113 322 3083
Mon–Fri · 9am–5:30pm · No fix, no fee
Start a free diagnostic →
Service · forensic

Forensic recovery — evidence, not just data.

An employee leaves and hands back their laptop, but it appears to be completely wiped clean. There is a very specific question about when a file was actually created. A tribunal has requested that deleted emails be produced properly. Forensic work is essentially recovering data with a burden of proof applied: imaging that preserves evidence; documenting methods used; and producing results that can withstand the opposing party’s expert.

two decades’ experience
In-house, never outsourced
Only pay if we recover your data, on most jobs
// the discipline

What makes recovery forensic.

There are differences in how we handle each phase of the process: we use write-blocking methods to prevent alteration of the original media as soon as we receive it. We generate a cryptographic hash to verify that the image(s) are identical (which can be verified by anyone), thus proving the integrity of the copy. In addition to a documented chain of custody (from you to us to the final report), we analyse the images themselves, including recovering deleted files, reconstructing timelines based on file system metadata, tracing USB and external devices, identifying what was viewed, copied or destroyed and approximately when these events occurred. Our findings appear as a non-technical language-based report with supporting documentation (the technical appendix) which an opposing expert would examine, not simply read.

// grounds & ground rules

Lawful basis, always.

Forensic work must have a legal basis. This means using your own devices/systems, company property under company policy, or matters directed by lawyers and insurance companies. We regularly engage with legal teams (standard engagement letter, NDA and ICO registered) in respect of employment disputes, intellectual property theft investigations, fraud cases and data destruction claims. Our UK laboratory does not conduct covert surveillance on an individual’s private devices, including those of partners/family members etc. Simply “asking nicely” to access someone’s device will not make it legal. If we were to compromise on the laws for you, we would also compromise them about you.

// questions

Asked often, answered straight.

Often an abundance of information: which wipe/deletion software was used, and when; when the last USB drives were plugged in; what was sent via cloud or email services; if there are any password-protected/encrypted files (which can be opened using the Passware Kit forensic decryption suite where legally permitted, which will recover keys/passwords where a route exists, by searching hard drives and any memory capture, checking escrow locations or unlocking supported hardware-encrypted devices; however, it will not crack a cipher); also, much more frequently than you might think, recovery of previously deleted data. The laptop needs to immediately go into quarantine at this point: do not allow the IT department to re-image it or log in using “quick look” access.

They have been built to stand up, and include: hash-verified images; a documented record of the history of how an image was obtained and stored; clearly stated methodology for obtaining and storing data; and a report broken down into findings and a technical appendix. In addition, we are happy to follow directions that have been agreed by the solicitors of all involved parties. There is nothing an honest investigator can offer that guarantees a result. The evidence states what it states.

No. That is secret access to another person’s personal device. It is illegal under current laws and violates our own terms of service, regardless of the strength of the suspicion. If there is a legal way to do this (using your own devices; using jointly-owned business equipment; working through a lawyer), then we would be happy to discuss this with you.

0113 322 3083