Recovery
Hard disk and SSD HDD, SSD, external drives, flash cards RAID, NAS & SAN All levels, all controllers, virtualisation Smartphones and tablets iPhone, Android, iPad, Huawei Tapes LTO, DAT, DLT and older formats
Access after signing in.
EN · RU · ZH · ES
For police, courts, lawyers and companies
When data is evidence, it is not only what you find that counts, but how. We work with a closed chain of custody, record every step, and never examine the original.
An ordinary recovery brings data back. A forensic investigation does so in a way that holds up afterwards: in court, with an insurer, in a disciplinary file or during an internal audit.
A finding is only worth as much as the path that led to it. That is why the method is fixed in advance and every action is documented.
A forensic copy is a sector-by-sector copy of the whole device, including the space the file system considers empty. Remnants of deleted files live there. We use the common formats (raw/dd and E01), so another expert can check the copy with their own tools. On a damaged device we make the copy in several passes and record, sector by sector, what could be read.
Recovering what seemed erased, formatted or overwritten, stating what could and could not be fully restored.
When a file was created, opened, changed or copied, and in what order.
Traces of USB sticks and external drives: which device, when connected, and what was copied.
Logins, searches, recently opened files, prints and operating system logs.
Mailboxes, attachments and documents, also from damaged files or older formats.
Smartphones and tablets, also after drop or water damage, down to chip level.
What we do not do: pronounce on guilt or intent. We record what is on the device and what follows from it. The legal assessment is for the client, the lawyer or the court.
Evidence often sits on a device that is broken: a laptop that fell in water, a drive that no longer starts, a phone with a cracked board. That is exactly what our lab does. X-ray, rework and reballing, nearly 20,000 donor drives and a Class 1 cleanroom let us make the device readable first, and examine it afterwards.
About encryption we are honest: modern encryption (BitLocker, FileVault, a recent iPhone) we do not break. With the password, the recovery key or a key from a management system we can reach the data. Without a key there is often still unencrypted information: logs, metadata, data from before the encryption, or copies on other devices.
We have experience as a court-appointed expert and work for police forces and law firms, among others.
Every start of a computer changes hundreds of files. The less happens to the original, the stronger the evidence.
A forensic investigation is priced to the case, because its size depends on the number of devices and on the question. After the intake you know what it costs. If the device has to be repaired first, our normal rates apply.
Call or write before you touch the device. We say straight away whether a step could harm the evidence, and what the next step is.
Questions about your drive? An engineer is reading.