Home / Forensic Recovery / IP & Confidential Document Theft

IP & Confidential Document Theft

A key employee leaves for a rival, or a competitor turns up holding your source code, designs, customer database or pricing. We prove what was taken and where it went — for businesses across Staines, Surrey and beyond, to a standard fit for an injunction. Free diagnostic, freephone advice.

Confidential and evidence-grade. A free diagnostic and a written scope come before any investigation begins.

// signs you may need this

Signs your intellectual property has walked

When a key employee leaves for a rival, or a competitor turns up holding your work, these are the signals that trade secrets may have left the building across Staines, Surrey and beyond.

A key employee resigning to join or start a competitor
Source code, CAD or design files copied before departure
A customer database, pricing or quotes taken to a rival
Confidential R&D, formulations or tender documents leaving
Mass downloads or heavy USB activity during the notice period
A competitor suddenly holding your designs or client list

Trade secrets that walk out the door

Intellectual-property theft is rarely dramatic — it is usually a trusted employee, in their last few weeks, quietly taking the things that make the business valuable: source code, CAD and engineering drawings, product formulations, the customer and pricing database, live tenders and R&D. Sometimes it is a competitor who has ended up with material that could only have come from you. Either way the questions are the same — what was taken, how did it leave, and can it be proved — and forensic examination of your own systems is how they are answered.

Proving what was taken — and where it went

We image the departing employee's laptop, workstation or the file server and reconstruct the exfiltration. USB storage history shows large volumes of design or code files being copied to an external drive; browser and client logs reveal uploads to a personal Dropbox, Google Drive or webmail account; print logs and file-access records show the confidential set being opened and output. Deleted files are carved back from the drive, and a keyword-led search across the whole image surfaces documents by name, project code or the confidentiality markings they carry.

Metadata that ties a file to your business

Proving a leak often comes down to lineage. Office documents, PDFs and CAD files carry embedded metadata — original author, company, revision history, creation and edit timestamps and internal identifiers — that can tie a document held by a competitor back to your business, and show that a 'new' file is really a descendant of yours. Matching that hidden data against your originals turns a suspicion of copying into something an expert can stand behind.

Evidence for an injunction or High Court claim

In IP cases speed matters: acting quickly can support a springboard or search-order application and stop the material being used before the trail goes cold. We preserve the devices immediately, work from write-blocked, hash-verified images with a documented chain of custody, and produce a report to expert-witness standard — findings and a technical appendix — suitable for an injunction or a High Court claim. Where a court has ordered imaging of a respondent's device, we execute that order precisely; we do not covertly access anyone's private device.

IP-theft cases are part of our forensic data recovery service; the hub explains the tools and procedure that make our findings court-ready.

// what the examination covers

What we search the image for

Working from a forensic image of your own systems, these are the strands that evidence an IP theft.

Bulk file copying

USB and cloud transfers of design, code or database files.

Document & code fingerprints

Filenames, project codes and confidentiality-marking keyword hits.

Metadata lineage

Authorship, revision history and IDs tying files back to you.

Webmail & file-sharing

Uploads and sends to personal or competitor accounts.

Deleted & hidden files

Carved from unallocated space and archive formats.

Access & print records

Who opened, exported or printed the confidential set.

Your systems, or a court-ordered image — nothing covert

We investigate your own company systems and equipment. Where a court has ordered the imaging of a respondent's device — for example under a search order — we execute it to the letter and preserve everything to evidential standard. What we do not do is covertly access a competitor's or an individual's private device; in IP litigation the lawful, court-backed route is also the one that wins, because evidence gathered improperly is worth nothing in front of a judge.

// getting your device to us

Post or courier your device — it's simple

IP cases turn on speed and preservation, so call 0800 689 0668 before touching the devices. We will agree what to image and how to keep it evidentially sound, and document the chain of custody from the moment it reaches our secure Guildford location.

Sending a drive from a computer, laptop, MacBook, iMac, CCTV / DVR or server? Please remove the internal hard drive or SSD and send us just the drive — we don't provide an internal drive-removal service. We don't recover storage soldered to a motherboard (e.g. Apple Silicon Macs and some thin laptops) — only drives that can be removed and sent to us.

  • Wrap the device in bubble wrap or a padded envelope — no need to include cables or power supplies.
  • Print and enclose the booking-in & shipping form (PDF) with your name, phone number and a brief description of what happened.
  • Send by Royal Mail Special Delivery or any tracked courier for full insurance in transit.
  • Prefer to hand it over in person? You can drop it in at reception at the address shown, Mon–Fri 9:00am–5:30pm.
// send your device to your nearest location

Guildford Data Recovery

Building 2, Ground Floor
Guildford Business Park
Guildford, GU2 8XH

↓ Print the booking-in & shipping form (PDF)

Mark the package for the attention of Guildford Data Recovery and we'll call you as soon as we diagnose your media.

Not sure what to send? Call 0800 689 0668 first or use the free online diagnostic.

// ip & document theft questions

Common questions

Often, yes. By imaging their work machine we can show large volumes of design or code files being copied to USB or cloud, opened or printed from the confidential set, and deleted afterwards — with dates and device details — building an evidenced picture of what left and how.
Frequently. Documents, PDFs and CAD files carry embedded metadata — author, company, revision history and identifiers — that can tie a competitor's file back to your originals and show it descends from your work, provided there is a lawful route to the material such as disclosure or a court order.
As fast as possible. Early preservation supports a springboard or search-order application and stops the material being used while the trail is fresh. Secure and stop using the relevant devices, and call us or your solicitor straight away so they can be imaged before anything changes.
Yes — write-blocked, hash-verified imaging, a documented chain of custody, an openly stated methodology and reporting to expert-witness standard with a technical appendix, suitable for an injunction or High Court claim and able to follow directions agreed between solicitors.
// part of our forensic service

Related forensic work

Protecting your trade secrets

Move fast — preserve the devices, then start a free diagnostic or call the freephone; early imaging protects an injunction.