Forensic Data Recovery in York

Some recoveries only have to work; a forensic recovery also has to be believed. For solicitors around the Minster quarter, HR teams at Clifton Moor and Monks Cross, and technology firms out at Heslington, we produce evidence from computers and storage that is imaged once, verified by hash, and reported so a tribunal can follow every step.

Method before speed. The free assessment and a written scope come first; forensic fees are settled in full before any examination starts. No fix, no fee all jobs except electronic and mechanical failures, chip level work, DVR and Forensic jobs. Full pricing is on the data recovery cost page.

What makes a recovery forensic

Not the tools — the record. Ordinary recovery asks only whether the files came back; forensic recovery must also show how, because one day someone whose job is doubt will read the answer. So the order of work never changes here: the device is imaged behind a hardware write-blocker into E01 evidence files, the image is verified by SHA-256, the original is sealed and logged, and every question after that is put to the copy. Findings are numbered, dated, and tied to the artefact that supports them.

The practice is arranged below in three groups. Detection and evidence recovery covers finding what happened on a machine or in a cloud account. Legal and chain of custody covers keeping what you find usable. Insider investigation covers the instructions themselves — leavers, partners, IP and family matters — where those first two disciplines get applied to a named dispute.

// group one · detection & evidence recovery

Detection & evidence recovery

Four services that establish what happened: deleted material and its timeline, removable-media movement, email and cloud exits, and the deep image of the workstation itself.

// group three · insider investigation

Insider investigation

Where the question is a person rather than a device: credential misuse and server-side evidence, then the four case files we are instructed on most.

// how every instruction runs

The method behind all eleven pages

Whichever page brought you here, the same six disciplines sit underneath the work.

Write-blocked acquisition

Hardware write-blockers stand between every original drive and the bench; nothing we run can alter the exhibit.

E01 evidence imaging

Each device is captured into E01 evidence files — a container the wider forensic profession can open, verify and re-examine.

SHA-256 verification

Acquisition and working copies are hashed and re-hashed, so any later change to the evidence would announce itself.

OSForensics analysis

Indexing, artefact harvesting, deleted-file recovery and timeline assembly run in OSForensics against the image, never the original.

Passware for protected files

Password-protected documents, archives and encrypted volumes are opened with Passware where a lawful right to them exists.

A custody record without gaps

Every handover, seal and storage movement is logged from signature at our Leeds location to the return of the exhibit.

// fees and footing

Forensic fees, and the lawful basis we require

What forensic work costs

The free diagnostic that opens every case is completed within 2 working days of arrival; forensic casework itself is not a no fix, no fee service. The full forensic investigation with report is £800 + VAT, payable 100% upfront. The less expensive Forensic binary image and deleted-file extraction service, without the report, is £400 + VAT. Any Forensic work required will be payable upfront. CCTV / DVR, BitLocker and ransomware cases are Forensic-classed and payable upfront on the same terms. Both figures are itemised on our prices page, and the written scope is agreed before payment is taken.

Who we can act for

Most instructions arrive from employers, HR teams and solicitors; private matters are taken on the same footing. Instructions are accepted on three footings only: equipment the company itself owns; the instruction of a solicitor, insurer or court; or devices that are genuinely the client's own — including jointly owned machines in matrimonial matters. We do not hack, we do not intercept live communications, and we do not examine a device the instructing client has no right to examine.

// getting your device to us

Sending it in — easier than you'd think

Exhibits are not ordinary parcels: call 0800 689 0668 to plan packaging, paperwork and timing, then send tracked next-day from anywhere in North Yorkshire — or hand-deliver to our Leeds location, where the custody record opens at the signature.

Is the drive still inside a computer, laptop, MacBook, iMac, CCTV / DVR or server? Take the hard drive or SSD out first and post the bare drive on its own — removing drives from machines isn't a service we offer. Storage that's soldered to a motherboard (Apple Silicon Macs, certain slim laptops) is the one thing we can't work on: if it doesn't come out, it can't come in.

  • Bubble wrap and a sturdy box or padded envelope will do nicely — cables, caddies and power bricks can stay at home.
  • Print off the booking-in & shipping form (PDF), add your name, number and a line or two on what happened, and tuck it in the parcel.
  • Royal Mail Special Delivery keeps it tracked and insured the whole way; your own courier does the same job if you'd sooner book one. There's no collection service at this end.
  • Happier handing it over in person? Reception at the address here takes drop-offs, Mon–Fri 9:00am–5:30pm.
// where your device is headed

Leeds Data Recovery

17th Floor, The Pinnacle
Albion Street
Leeds, LS1 5AA

↓ Print the booking-in & shipping form (PDF)

Address the parcel for the attention of Leeds Data Recovery — about 40 minutes from York via the A64 and A1(M), or next working day by tracked post. You'll hear from us the moment it's booked onto the bench.

Not certain what to pack? Ring 0800 689 0668 first, or run the free online diagnostic.

// forensic recovery — the questions that open most calls

Before you instruct us

The free diagnostic comes first and is completed within 2 working days. The full forensic investigation with report is £800 + VAT, payable 100% upfront. The less expensive Forensic binary image and deleted-file extraction service, without the report, is £400 + VAT. Any Forensic work required will be payable upfront. CCTV / DVR, BitLocker and ransomware cases are Forensic-classed and payable upfront on the same terms. Every figure is confirmed in a written scope before payment.
No examiner honestly can — admission is always the court's or tribunal's decision. What we control is the method: originals untouched behind write-blockers, E01 images verified by SHA-256, a custody record without gaps, and reporting prepared to evidential standards with the workings disclosed so the other side's expert can test every step.
Employers on equipment the business owns; solicitors, insurers and courts by written instruction; and private clients on devices that are genuinely their own — including jointly owned machines in matrimonial matters. We do not hack, we do not intercept live communications, and we do not examine a device the client has no right to examine.
Handsets themselves sit outside this bench, but the phone's shadow on a computer is squarely inside it: iTunes and Finder backups, synced photo libraries, WhatsApp Desktop caches and cloud exports obtained through lawful routes all carry recoverable message and photo evidence, and they are examined here routinely.
Ring the freephone before anything moves — exhibits do not travel like repair jobs. We agree the packaging and paperwork, you send tracked next-day or bring it to our Leeds location on Albion Street, and the custody record opens the moment it is signed for.

Evidence first. Everything else follows.

Free assessment, written scope, verified images — ring the freephone and put the question to the machine.