A leaver's laptop has one forensic moment: the interval between hand-back and reissue. Imaged then — write-blocked, into E01 evidence files, verified by SHA-256 — it can answer questions for years. Reused, it answers fewer every day. For York employers the rule is simple: the questions can wait; the image cannot.
◇ Method before speed. The free assessment and a written scope come first; forensic fees are settled in full before any examination starts. No fix, no fee all jobs except electronic and mechanical failures, chip level work, DVR and Forensic jobs. Full pricing is on the data recovery cost page.
Any of these puts a machine on the imaging list before it goes anywhere near the rebuild queue.
The economics are lopsided. A forensic image taken now — the full disk captured behind a write-blocker into E01 evidence files, verified by SHA-256 — costs a fraction of what the same evidence is worth once a dispute is live, and the machine can go back into service the day after, because the evidence now exists independently of it. Skip the image, reissue the laptop, and every day of the new user's work overwrites the old user's traces. Businesses that image leavers' machines as routine never have to explain a gap.
Far more than documents. Browser history, cache and cookies reconstruct research and uploads; temporary files hold drafts and copies that were never saved anywhere else; the pagefile and hibernation file carry fragments of whatever was in memory — open documents, chat windows, even credentials; Slack and Teams keep local caches from which conversations are recovered after they have been deleted from the apps; and VPN and connection logs place the machine on networks at times that matter. None of this survives a rebuild. All of it survives an image.
Encryption rewards early capture. A BitLocker or FileVault machine is imaged while the keys are still escrowed and the passwords still known — before the leaver's account is closed, the directory tidied, or the TPM cleared by a rebuild. On a live, unlocked Windows volume there is a further route: Volume Shadow Copies captured from the running system, which sidestep the encryption question entirely because the volume is open while you hold it. Encrypted-volume work is Forensic-classed and, like everything on this page, payable upfront once scoped.
Claims of wiping are tested, not taken. Secure-erase and boot-disk tools such as DBAN leave their own evidence — boot records, tool signatures, characteristic overwrite patterns, and timing that can be fixed against the surrounding events. Interrupted and partial runs are common, leaving whole regions recoverable; hardware secure-erase commands are checked against the drive's own records. Where a wipe genuinely completed, the report says so plainly — and dates it, because a deliberate wipe on the eve of proceedings is itself a finding.
The custody and verification discipline is at the forensic recovery hub. What deletion evidence looks like on the image is covered by deleted-file forensics; preservation duties by legal hold & chain of custody; fees by our prices page.
Taken once, verified, and available to every question the dispute produces afterwards.
The full disk in the container the forensic profession exchanges.
SHA-256 values proving the image, and every copy of it, unchanged.
History, cache and cookies reconstructing research and uploads.
Pagefile and hibernation content: documents, chats, credentials.
Slack and Teams local stores, with deleted conversations recovered.
VPN and network traces placing the machine at times and places.
The free diagnostic that opens every case is completed within 2 working days of arrival; forensic casework itself is not a no fix, no fee service. The full forensic investigation with report is £800 + VAT, payable 100% upfront. The less expensive Forensic binary image and deleted-file extraction service, without the report, is £400 + VAT. Any Forensic work required will be payable upfront. BitLocker and other encrypted-volume work is Forensic-classed and payable upfront on the same terms. Both figures are itemised on our prices page, and the written scope is agreed before payment is taken.
Imaging proceeds on company-owned machines, your own hardware, or a solicitor's instruction. Instructions are accepted on three footings only: equipment the company itself owns; the instruction of a solicitor, insurer or court; or devices that are genuinely the client's own — including jointly owned machines in matrimonial matters. We do not hack, we do not intercept live communications, and we do not examine a device the instructing client has no right to examine.
Give us the machine count and the encryption position when you call 0800 689 0668; imaging is then scoped in writing the same day. Devices travel tracked next-day or by hand to our Leeds location, and custody is recorded at the signature.
Is the drive still inside a computer, laptop, MacBook, iMac, CCTV / DVR or server? Take the hard drive or SSD out first and post the bare drive on its own — removing drives from machines isn't a service we offer. Storage that's soldered to a motherboard (Apple Silicon Macs, certain slim laptops) is the one thing we can't work on: if it doesn't come out, it can't come in.
↓ Print the booking-in & shipping form (PDF)
Address the parcel for the attention of Leeds Data Recovery — about 40 minutes from York via the A64 and A1(M), or next working day by tracked post. You'll hear from us the moment it's booked onto the bench.
Not certain what to pack? Ring 0800 689 0668 first, or run the free online diagnostic.
One capture preserves every answer the machine will ever give — ring the freephone.