A blue screen demanding a 48-digit key you've never seen, standing between you and a drive that holds everything. We recover BitLocker-locked drives for homes and businesses across Staines and Surrey — finding keys, decrypting estates of drives, and rescuing failing disks through their encryption.
Free diagnostic on every bitlocker job. One fixed quote in writing before any work begins.
No fix, no fee all jobs except electronic and mechanical failures, chip level work, DVR and Forensic jobs. Full pricing is on the free diagnostic page.
Every bitlocker job starts by matching the symptoms to the fault — these twelve cover almost everything that reaches the bench.
A hardware, firmware or update change tripped BitLocker into recovery mode — the data is intact, the key just needs finding or recovering.
The key was escrowed somewhere (a Microsoft or work account, a file, a printout) or can be recovered from the TPM or a memory image.
Where a password protects the volume, accelerated recovery can often retrieve it — fast if it's weak, honest odds if it's strong.
A new motherboard, TPM clear, BIOS update or Secure Boot change invalidates the seal and forces the recovery key.
A reinstall can strand an encrypted data partition — recoverable with the key or through key recovery.
The compound case: a dying encrypted drive, imaged gently in its locked state before any decryption is attempted.
Encrypted removable media locked the same way — opened with the key, password or forensic recovery.
Bulk decryption of encrypted drives from leavers and retired machines against escrowed keys.
BitLocker locks when a drive leaves its original machine — expected behaviour, recoverable with the key.
Damaged encryption headers on an otherwise healthy drive — reconstructed before decryption.
A firmware update that clears or reseals the TPM forces the recovery key — retrieved from escrow or the TPM state.
A dual-boot install or GRUB/bootloader update trips BitLocker into recovery — the key is recovered and the volume decrypted.
BitLocker recovery is really two disciplines. The first is tracking down keys people never realised they had: BitLocker rarely switches on without escrowing a recovery key somewhere — a Microsoft account, an organisation's Azure AD or Active Directory, an exported file or a printout. Modern Windows laptops enable device encryption silently and stash the key the first time you sign in, so the answer to most lockouts is a methodical hunt through every account the machine has ever touched. The second discipline is the hard one: a drive that's failing and encrypted at the same time.
For business drives and lawful investigations we run Passware Kit Forensic, the industry-standard decryption suite. It doesn't break BitLocker — properly implemented AES encryption without the key is designed to be unbreakable, and anyone claiming otherwise is misleading you. What Passware does is recover the key: pulling it from a captured memory image or hibernation file, extracting it from the TPM, or mounting GPU-accelerated dictionary and brute-force attacks against the password where one guards the volume. We decrypt BitLocker and BitLocker To Go, and the same suite handles FileVault, VeraCrypt, TrueCrypt and LUKS if you have those too. Businesses regularly send us estates of ex-staff and retired-machine drives to decrypt in bulk against escrowed keys.
The compound case is the one we see most from businesses: a BitLocker drive that's also failing — bad sectors sitting in encrypted space, a laptop crashed into recovery-key purgatory because the disk beneath it is sick. Order of operations is everything. The drive is imaged gently in its encrypted state on hardware imagers first, and only then is the stable image decrypted with the recovered key — never the other way round. Every unlock attempt on a failing encrypted drive is an expensive read that spends its remaining life, which is exactly why the honest advice is to stop and send it in.
BitLocker work is key recovery and careful imaging — not code-breaking. The bench reflects that:
The industry-standard decryption suite — recovers BitLocker keys from memory images, hibernation files, the TPM, or the password via accelerated attack. It recovers the key; it does not break the AES.
Where a machine can be run, the live encryption key is captured from RAM or the hibernation file — often the fastest route into a locked volume.
NVIDIA and AMD GPUs and rainbow tables drive dictionary and brute-force attacks against BitLocker passwords at tens of thousands of guesses per second.
Failing encrypted drives are imaged in their locked state through write-blockers first — the original is never altered, and decryption runs on the copy.
Methodical recovery of keys escrowed to Microsoft accounts, Azure AD / Active Directory, exported files and printouts — where most lockouts are actually solved.
The same suite opens BitLocker To Go, FileVault, VeraCrypt, TrueCrypt and LUKS volumes, plus 400+ password-protected file types.
Properly implemented BitLocker is unbreakable without the key — reputable recovery means recovering the key, not cracking the encryption. We use Passware Kit Forensic and tell you honestly what's achievable.
Sending a BitLocker drive for decryption? Include every scrap of key material you hold — the 48-digit recovery key, the Microsoft or work account it may be escrowed to, any exported key files or PINs. The more you can supply, the faster and cheaper the decryption. For a drive removed from a machine, an anti-static bag or foil wrap is fine.
Most customers post or courier their media to us.
Sending a drive from a computer, laptop, MacBook, iMac, CCTV / DVR or server? Please remove the internal hard drive or SSD and send us just the drive — we don't provide an internal drive-removal service. We don't recover storage soldered to a motherboard (e.g. Apple Silicon Macs and some thin laptops) — only drives that can be removed and sent to us.
↓ Print the booking-in & shipping form (PDF)
Mark the package for the attention of Guildford Data Recovery and we'll call you as soon as we diagnose your media.
Not sure what to send? Call 0800 689 0668 first or use the free online diagnostic.
Free diagnostic, fixed quote, no fix no fee — start now or call the freephone.