A departing employee, a laptop handed back suspiciously empty, and a business that needs to know what happened before it was wiped. Forensic recovery is data recovery with the burden of proof attached — and for our Staines and Surrey clients it's some of the most important work we do.
Free diagnostic on every forensic job. One fixed quote in writing before any work begins.
No fix, no fee all jobs except electronic and mechanical failures, chip level work, DVR and Forensic jobs. Full pricing is on the data recovery cost page.
Every forensic job starts by matching the symptoms to the fault — these twelve cover almost everything that reaches the bench.
Our single most frequent instruction — the wipe itself, the tool that ran it and the activity leading up to it can usually all be pieced back together.
Windows quietly logs every USB device it meets and when; set against file-access records, that reveals what may have walked out the door.
Webmail sends and uploads to Dropbox, Google Drive or WeTransfer all leave their fingerprints in histories, logs and leftover file fragments.
Documents and emails that were deleted en masse are carved back out and presented under a defensible, hash-verified method.
The file system, USN journal and logs are read together to establish when a file was genuinely created, opened or altered.
Pinning down which confidential material was accessed, copied or taken — and under whose account it happened.
Company equipment examined to evidence standard under company policy, commonly on the instruction of solicitors.
Footage and device data that a claim or case turns on, recovered forensically.
Impartial, fully documented findings prepared for internal HR procedures, insurers and tribunals.
Undertaken to whatever directions the parties' legal teams have agreed between them.
Traces of CCleaner, BleachBit and similar wipers — establishing what ran, when, and what survived the pass.
OneDrive, Google Drive and Dropbox sync logs and remnants showing what left via a personal cloud account.
Employers bring us this story constantly. An employee copies company data off their work laptop — onto a USB stick, a personal email account or a cloud drive — then wipes or resets the machine before handing it back, hoping to erase the trail. The employer is left with a laptop that looks empty and a strong suspicion that something walked out with the person. This is exactly what forensic recovery exists for. Even after a reset or a wiping tool has run, a great deal survives: which wiping tool was used and precisely when, which USB devices were connected in those final weeks and what was opened just before they were, what was uploaded to webmail or cloud services, and deleted files carved back off the drive. All of those traces are assembled into a detailed forensic report, written in plain English, that you can actually act on.
Our forensic bench runs OSForensics, the PassMark investigation suite, for the heavy lifting: recovering deleted files, indexing and searching the entire drive, reconstructing a minute-by-minute activity timeline from file-system timestamps and the Windows USN journal, and pulling the artefacts that matter — connected-USB history, browser and download history, webmail traces, wireless networks and recent-file lists. Alongside it we run Passware Kit Forensic to open any password-protected or encrypted files and BitLocker volumes standing in the way, where doing so is lawful. Every step happens on a hardware write-blocked, hash-verified image of the original, so the source media is never altered and any party can prove the copy is exact.
Most of our forensic instructions fall into a handful of recurring types, and each has its own dedicated guide: employee data theft, where a leaver takes files on the way out; matrimonial and divorce matters handled lawfully through solicitors; partnership and shareholder disputes over company records and access; and intellectual-property theft, where designs, source code or client lists are copied. Whichever fits your situation, the underlying method is the same — a write-blocked image, a documented timeline, and a report built to stand up.
Procedure at every step is what turns recovery into forensics: each original goes behind a write-blocker from first contact, every image is verified by cryptographic hash (MD5, SHA-1, SHA-256), custody is documented from your hands into ours, and the reporting separates clear findings from a technical appendix so it holds up in a tribunal or court. Directions agreed between solicitors are ones we'll gladly work to. The firm limit, put plainly: lawful basis first — your own devices, company equipment under company policy, or matters instructed through solicitors and insurers. Covert access to another person's private device is never on offer, however strong the suspicion; when a legitimate route exists, that's the one we take.
What separates forensic work from ordinary recovery is that the output is evidence — so the tooling and the procedure carry equal weight:
The investigation suite at the centre of our forensic bench: deleted files recovered, the whole drive indexed and searchable, and artefacts extracted from hundreds of file formats with OCR on top.
Timestamps, the USN change journal and system logs are woven into a minute-by-minute account of file and system activity — what happened, and precisely when it happened.
Every data-theft case rests on this: which external devices connected, at what times, and what was being accessed around those moments.
Where the law allows, password-protected files, encrypted archives and BitLocker volumes blocking the evidence are opened.
From first contact each original sits behind a write-blocker and is imaged to a copy verified by hash (MD5, SHA-1, SHA-256) — any party can prove it exact.
Custody is documented from your hands into ours, and the report arrives in two parts — plain-English findings plus a technical appendix — written to survive a tribunal or court.
We'll state the boundary up front: there must be a lawful basis for forensic work — your own devices, company equipment examined under company policy, or matters instructed through solicitors and insurers. Covert access to another person's private device is something we never provide.
Before anything goes in the post, the drive has to come out of your computer — we work on the bare drive only. Not sure how? Ring us on 0800 689 0668, or any local PC repair shop will take it out for a small fee.
With a forensic case, the device must stay exactly as it was found — powered off, with nobody logging in, 'having a look' or re-imaging it, because each of those actions tramples recoverable evidence. Write down the relevant dates and names. Take the drive out and send it clearly labelled; where the complete device itself is the evidence, ring us first on 0800 689 0668 and we'll arrange handling under a documented chain of custody.
Most customers post their media to us tracked and insured.
Sending a drive from a computer, laptop, MacBook, iMac, CCTV / DVR or server? Please remove the internal hard drive or SSD and send us just the drive — we don't provide an internal drive-removal service. We don't recover storage soldered to a motherboard (e.g. Apple Silicon Macs and some thin laptops) — only drives that can be removed and sent to us.
↓ Print the booking-in & shipping form (PDF)
Mark the package for the attention of Guildford Data Recovery and we'll call you as soon as we diagnose your media.
Not sure what to send? Call 0800 689 0668 first or use the free online diagnostic.
Free diagnostic, fixed quote, no fix no fee — start now or call the freephone.