Some recoveries only have to work; a forensic recovery also has to be believed. For solicitors around the Minster quarter, HR teams at Clifton Moor and Monks Cross, and technology firms out at Heslington, we produce evidence from computers and storage that is imaged once, verified by hash, and reported so a tribunal can follow every step.
◇ Method before speed. The free assessment and a written scope come first; forensic fees are settled in full before any examination starts. No fix, no fee all jobs except electronic and mechanical failures, chip level work, DVR and Forensic jobs. Full pricing is on the data recovery cost page.
Not the tools — the record. Ordinary recovery asks only whether the files came back; forensic recovery must also show how, because one day someone whose job is doubt will read the answer. So the order of work never changes here: the device is imaged behind a hardware write-blocker into E01 evidence files, the image is verified by SHA-256, the original is sealed and logged, and every question after that is put to the copy. Findings are numbered, dated, and tied to the artefact that supports them.
The practice is arranged below in three groups. Detection and evidence recovery covers finding what happened on a machine or in a cloud account. Legal and chain of custody covers keeping what you find usable. Insider investigation covers the instructions themselves — leavers, partners, IP and family matters — where those first two disciplines get applied to a named dispute.
Four services that establish what happened: deleted material and its timeline, removable-media movement, email and cloud exits, and the deep image of the workstation itself.
Evidence is only worth what its handling can prove. Preservation, hashing, storage and custody records are a service in their own right — and encrypted or wiped devices are handled within workstation deep imaging: BitLocker and FileVault machines captured before keys change, secure-erase runs detected and dated.
Where the question is a person rather than a device: credential misuse and server-side evidence, then the four case files we are instructed on most.
Whichever page brought you here, the same six disciplines sit underneath the work.
Hardware write-blockers stand between every original drive and the bench; nothing we run can alter the exhibit.
Each device is captured into E01 evidence files — a container the wider forensic profession can open, verify and re-examine.
Acquisition and working copies are hashed and re-hashed, so any later change to the evidence would announce itself.
Indexing, artefact harvesting, deleted-file recovery and timeline assembly run in OSForensics against the image, never the original.
Password-protected documents, archives and encrypted volumes are opened with Passware where a lawful right to them exists.
Every handover, seal and storage movement is logged from signature at our Leeds location to the return of the exhibit.
The free diagnostic that opens every case is completed within 2 working days of arrival; forensic casework itself is not a no fix, no fee service. The full forensic investigation with report is £800 + VAT, payable 100% upfront. The less expensive Forensic binary image and deleted-file extraction service, without the report, is £400 + VAT. Any Forensic work required will be payable upfront. CCTV / DVR, BitLocker and ransomware cases are Forensic-classed and payable upfront on the same terms. Both figures are itemised on our prices page, and the written scope is agreed before payment is taken.
Most instructions arrive from employers, HR teams and solicitors; private matters are taken on the same footing. Instructions are accepted on three footings only: equipment the company itself owns; the instruction of a solicitor, insurer or court; or devices that are genuinely the client's own — including jointly owned machines in matrimonial matters. We do not hack, we do not intercept live communications, and we do not examine a device the instructing client has no right to examine.
Exhibits are not ordinary parcels: call 0800 689 0668 to plan packaging, paperwork and timing, then send tracked next-day from anywhere in North Yorkshire — or hand-deliver to our Leeds location, where the custody record opens at the signature.
Is the drive still inside a computer, laptop, MacBook, iMac, CCTV / DVR or server? Take the hard drive or SSD out first and post the bare drive on its own — removing drives from machines isn't a service we offer. Storage that's soldered to a motherboard (Apple Silicon Macs, certain slim laptops) is the one thing we can't work on: if it doesn't come out, it can't come in.
↓ Print the booking-in & shipping form (PDF)
Address the parcel for the attention of Leeds Data Recovery — about 40 minutes from York via the A64 and A1(M), or next working day by tracked post. You'll hear from us the moment it's booked onto the bench.
Not certain what to pack? Ring 0800 689 0668 first, or run the free online diagnostic.
Free assessment, written scope, verified images — ring the freephone and put the question to the machine.