A blue screen demanding a 48-digit key you've never seen, standing between you and a drive that holds everything. We recover BitLocker-locked drives for homes and businesses across Staines and Surrey — finding keys, decrypting estates of drives, and rescuing failing disks through their encryption.
Free diagnostic on every bitlocker job. One fixed quote in writing before any work begins.
No fix, no fee all jobs except electronic and mechanical failures, chip level work, DVR and Forensic jobs. Full pricing is on the data recovery cost page.
Every bitlocker job starts by matching the symptoms to the fault — these twelve cover almost everything that reaches the bench.
Some hardware, firmware or update change has tipped BitLocker into recovery mode — nothing is lost, the key simply has to be found or recovered.
Almost always the key was escrowed along the way — to a Microsoft or work account, a file or a printout — or it can be pulled from the TPM or a memory image.
A password-protected volume responds to accelerated recovery: quick when the password is weak, honestly-quoted odds when it's strong.
Swap the motherboard, clear the TPM, update the BIOS or touch Secure Boot and the seal breaks — Windows then demands the recovery key.
An encrypted data partition left stranded by a reinstall comes back with the key, or through key recovery when there isn't one.
The double-trouble case: a dying drive that's also encrypted gets imaged gently while still locked, before decryption is even discussed.
Sticks and externals lock exactly the same way — and open with the key, the password or forensic key recovery.
Leavers' machines and retired stock, decrypted in bulk against whatever keys the organisation escrowed.
Taking a drive out of its original machine is precisely what BitLocker is designed to notice — expected, and recoverable with the key.
Damaged encryption headers on a drive that's otherwise fine are rebuilt first, then the volume is decrypted.
A firmware update that clears or reseals the TPM forces the recovery key — retrieved from escrow or the TPM state.
A dual-boot install or GRUB/bootloader update trips BitLocker into recovery — the key is recovered and the volume decrypted.
Under the single label of 'BitLocker recovery' live two separate disciplines. The first is tracking down keys people never realised they had: BitLocker rarely switches on without escrowing a recovery key somewhere — a Microsoft account, an organisation's Azure AD or Active Directory, an exported file or a printout. Modern Windows laptops enable device encryption silently and stash the key the first time you sign in, so the answer to most lockouts is a methodical hunt through every account the machine has ever touched. The second discipline is the hard one: a drive that's failing and encrypted at the same time.
Business drives and lawful investigations go through Passware Kit Forensic, the decryption suite the industry standardises on. It doesn't break BitLocker — properly implemented AES encryption without the key is designed to be unbreakable, and anyone claiming otherwise is misleading you. What Passware does is recover the key: pulling it from a captured memory image or hibernation file, extracting it from the TPM, or mounting GPU-accelerated dictionary and brute-force attacks against the password where one guards the volume. BitLocker and BitLocker To Go are the staples, while the same suite opens FileVault, VeraCrypt, TrueCrypt and LUKS should you have those as well. Estates of leavers' and retired-machine drives arrive from businesses all the time for bulk decryption against escrowed keys.
The compound case is the one we see most from businesses: a BitLocker drive that's also failing — bad sectors sitting in encrypted space, a laptop crashed into recovery-key purgatory because the disk beneath it is sick. Order of operations is everything. The drive is imaged gently in its encrypted state on hardware imagers first, and only then is the stable image decrypted with the recovered key — never the other way round. Every unlock attempt on a failing encrypted drive is an expensive read that spends its remaining life, which is exactly why the honest advice is to stop and send it in.
There's no code-breaking in honest BitLocker work — it's key recovery plus careful imaging, and the bench is set up for exactly that:
The decryption suite the industry standardises on: BitLocker keys pulled from memory images, hibernation files or the TPM, or the password recovered by accelerated attack. What it recovers is the key — the AES itself is never broken.
If the machine still runs, the live encryption key can be lifted from RAM or the hibernation file — frequently the quickest way into a locked volume.
Banks of NVIDIA and AMD GPUs, backed by rainbow tables, throw tens of thousands of dictionary and brute-force guesses per second at a BitLocker password.
A failing encrypted drive is captured in its locked state behind a write-blocker before anything else; decryption then runs on that copy, never the original.
A patient, systematic hunt through Microsoft accounts, Azure AD / Active Directory, exported files and printouts — because that's where most lockouts actually end.
Beyond BitLocker and BitLocker To Go, the same suite opens FileVault, VeraCrypt, TrueCrypt and LUKS volumes, along with 400+ password-protected file types.
BitLocker done properly cannot be broken without its key — so reputable work means getting the key back, never 'cracking' the cipher. Passware Kit Forensic is our tool for it, and we're straight with you about what's achievable.
Posting a BitLocker drive in for decryption? Put every piece of key material you have in with it — the 48-digit recovery key, the Microsoft or work account it might be escrowed under, any exported key files or PINs. Each item you supply makes the decryption quicker and cheaper. A bare drive out of a machine travels fine in an anti-static bag or foil wrap.
Most customers post their media to us tracked and insured.
Sending a drive from a computer, laptop, MacBook, iMac, CCTV / DVR or server? Please remove the internal hard drive or SSD and send us just the drive — we don't provide an internal drive-removal service. We don't recover storage soldered to a motherboard (e.g. Apple Silicon Macs and some thin laptops) — only drives that can be removed and sent to us.
↓ Print the booking-in & shipping form (PDF)
Mark the package for the attention of Guildford Data Recovery and we'll call you as soon as we diagnose your media.
Not sure what to send? Call 0800 689 0668 first or use the free online diagnostic.
Free diagnostic, fixed quote, no fix no fee — start now or call the freephone.