An employee leaves a Clifton Moor distributor or a Monks Cross head office, the laptop comes back, and within a month a familiar customer list is being worked by somebody else. The machine can usually settle what happened — provided it is preserved before anyone signs in. We examine it methodically and report what the record supports, no more and no less.
◇ Method before speed. The free assessment and a written scope come first; forensic fees are settled in full before any examination starts. No fix, no fee all jobs except electronic and mechanical failures, chip level work, DVR and Forensic jobs. Full pricing is on the data recovery cost page.
One of these alone is reason to take the device out of circulation, unused, until it has been imaged — whether the business sits in York, Malton or along the A64.
The strongest employee-theft cases are decided in the first hour, by restraint. Every sign-in writes new data over old, every helpful look around by IT re-dates the folders that matter, and a reissue to the next starter can end the question for good. So the procedure is short: power the machine down, label it, record who has held it, and let it do nothing until it has been imaged. The examination then runs against the verified copy, and the laptop itself sits sealed — available, unchanged, ready for the other side's expert to check.
Windows keeps better notes than most witnesses. The USBSTOR registry key lists every removable device the machine has seen, by maker, model and serial number; setupapi.dev.log dates the first connection of each. Link files and jump lists then show company files opened from a removable volume's drive letter; shellbags hold the directory layout that was browsed on it; and the NTFS change journal fixes each file operation to the minute across the weeks in question. Read together, in sequence, these artefacts move a case from suspicion to record.
A good proportion of copying happens in a browser instead. On the image we reconstruct webmail sessions with attachments addressed to personal accounts, auto-forwarding rules quietly applied to the mailbox, uploads through transfer sites, and sync clients pushing whole folders into a personal cloud account. Where the business runs Microsoft 365 or Google Workspace, the tenant's own audit records are collected alongside, so the device's story and the service's story can be compared line by line — and each corroborates the other.
The report assumes an audience of non-specialists advised by a specialist. Findings come first, numbered and dated, each traceable to the artefact behind it; the technical workings sit in an appendix; the exhibit schedule carries SHA-256 hashes for every image. Where the parties' solicitors agree directions, the examination keeps to them exactly. Nothing is claimed beyond what the record supports — which is precisely why the record tends to be believed.
How imaging and custody run case-wide is covered at the forensic recovery hub; the connection-history detail lives on the USB device forensics page, and preservation practice under legal hold & chain of custody. Fees are on our prices page.
Each item below is delivered as a numbered, dated finding tied to the artefact that supports it — a record a tribunal or court can rely on.
Imaged in time, a leaver's computer usually gives up all of these at once.
Make, model and serial of each device connected, with first and last seen dates.
Destination timestamps and journal entries placing files on the device at stated times.
Link files and jump lists tying named documents to the stick's drive letter.
Webmail sends, forwarding rules and personal cloud sync recorded on the machine.
After-hours patterns, repeated access and communications bearing on state of mind.
Imaging date and time against the departure date, verified by SHA-256.
The free diagnostic that opens every case is completed within 2 working days of arrival; forensic casework itself is not a no fix, no fee service. The full forensic investigation with report is £800 + VAT, payable 100% upfront. The less expensive Forensic binary image and deleted-file extraction service, without the report, is £400 + VAT. Any Forensic work required will be payable upfront. Both figures are itemised on our prices page, and the written scope is agreed before payment is taken.
Employee matters proceed on company-owned equipment, under HR oversight or a solicitor's instruction. Instructions are accepted on three footings only: equipment the company itself owns; the instruction of a solicitor, insurer or court; or devices that are genuinely the client's own — including jointly owned machines in matrimonial matters. We do not hack, we do not intercept live communications, and we do not examine a device the instructing client has no right to examine.
A machine that has become an exhibit should travel on agreed terms. Call 0800 689 0668 to settle packaging and paperwork; the custody record opens when the device is signed for at our Leeds location — next-day tracked from York, or by hand on Albion Street.
Is the drive still inside a computer, laptop, MacBook, iMac, CCTV / DVR or server? Take the hard drive or SSD out first and post the bare drive on its own — removing drives from machines isn't a service we offer. Storage that's soldered to a motherboard (Apple Silicon Macs, certain slim laptops) is the one thing we can't work on: if it doesn't come out, it can't come in.
↓ Print the booking-in & shipping form (PDF)
Address the parcel for the attention of Leeds Data Recovery — about 40 minutes from York via the A64 and A1(M), or next working day by tracked post. You'll hear from us the moment it's booked onto the bench.
Not certain what to pack? Ring 0800 689 0668 first, or run the free online diagnostic.
Power it down, ring the freephone, and let the image settle the question.