A blue recovery screen wants 48 digits nobody wrote down, and the drive behind it holds the business. For Swansea firms and households we find escrowed keys, decrypt fleets of ex-staff drives, and rescue failing disks through their encryption — never by breaking it, because nobody can.
Free diagnostic on every bitlocker job. One fixed quote in writing before any work begins.
No fix, no fee all jobs except electronic and mechanical failures, chip level work, DVR and Forensic jobs. Full pricing is on the data recovery cost page.
Every bitlocker job starts by matching the symptoms to the fault — these fifteen cover almost everything that reaches the bench.
A hardware or firmware change broke the TPM's seal; the data waits intact behind the prompt.
Escrow wins most of these — Microsoft accounts, Azure AD, exported files, printouts in drawers.
GPU-accelerated attack retrieves weak and middling passwords; strong lost ones get honesty instead.
New board, cleared TPM, BIOS update or Secure Boot change — the seal breaks exactly as designed.
An encrypted data partition stranded by a reinstall recovers once the key is found.
The double problem: a sick drive under encryption, captured whole while still locked, with decryption saved for the copy.
Encrypted USB and external volumes open the same three ways: key, password or forensic recovery.
Boxes of ex-staff drives decrypt in bulk against the organisation's escrowed keys.
Leaving its TPM behind locks the volume — expected behaviour, reversed with the key.
Corrupt encryption headers on a healthy drive are reconstructed before decryption runs.
A UEFI update clears or reseals the security chip and Windows demands the key — sourced from escrow or the TPM's own state.
GRUB installs and bootloader changes flip the machine into recovery mode by design.
Modern laptops enable device encryption silently at first sign-in; owners meet BitLocker at lockout.
Keys parked in organisational directories are located and matched to drive identifiers for leaver estates.
Usually the wrong key of several on the account — matched properly by key identifier, not trial and error.
Half the work is detective work: BitLocker almost never activates without parking a recovery key somewhere — a Microsoft account, Azure AD or Active Directory for work machines, an exported text file, a forgotten printout. Modern Windows enables device encryption silently at first sign-in, so the answer to a lockout is usually a disciplined sweep of every account the machine has ever met. The other half is genuinely hard: a drive that's dying and encrypted simultaneously, where the order of operations decides everything.
Our decryption bench runs Passware Kit Forensic, the same suite used across the forensic industry. It does not crack BitLocker — sound AES with no key is unbreakable by anyone, whatever a slick website promises. What it does is recover keys: lifted from memory captures and hibernation files, extracted from the TPM, or reached by GPU-accelerated attack when a human password guards the volume. BitLocker and BitLocker To Go are core work, FileVault, VeraCrypt, TrueCrypt and LUKS ride the same bench, and bulk decryption of leaver estates is a routine business service.
The compound case rewards patience: bad sectors inside encrypted space, a laptop stuck at the recovery screen because the disk under it is failing. Unlock attempts are exactly the wrong medicine — each one spends the drive's remaining life on reads that prove nothing. The drive is captured cold and still locked on the hardware rigs; only that stable copy is then decrypted with the recovered key. Worth knowing: BitLocker work is classed as forensic, so it's quoted after the free diagnostic and payable upfront.
BitLocker recovery is key-finding plus careful imaging — never code-breaking — and the bench reflects it:
The forensic industry's standard decryption suite: keys retrieved from memory captures, hibernation files, the TPM, or by accelerated password attack. It finds keys — it never breaks the AES.
On a machine that still boots, the live key can be captured out of RAM or the hibernation file — frequently the shortest path into a locked volume.
Banks of NVIDIA and AMD GPUs plus rainbow tables drive dictionary and brute-force password attacks at tens of thousands of guesses a second.
A failing encrypted drive is imaged in its locked state through write-blockers first; decryption then runs on the stable copy, never the original.
A disciplined hunt through Microsoft accounts, Azure AD and Active Directory, exported files and paper printouts — the place most lockouts are genuinely won.
Beyond BitLocker and BitLocker To Go, the bench handles FileVault, VeraCrypt, TrueCrypt and LUKS, along with 400-plus varieties of password-protected file.
Sound BitLocker without its key stays shut — full stop, whoever claims otherwise. Legitimate recovery means recovering the key, which is what Passware Kit Forensic does here, with an honest verdict either way. Like all forensic-classed work it's payable upfront once quoted; the assessment itself costs nothing.
Post every scrap of key material with the drive: the 48-digit recovery key if you hold it, the Microsoft or workplace account it might be escrowed under, exported key files, PINs and likely passwords. Each item shortens the job and the bill. A removed drive travels happily in an anti-static bag or kitchen foil.
Most customers post or courier their media to us.
Sending a drive from a computer, laptop, MacBook, iMac, CCTV / DVR or server? Please remove the internal hard drive or SSD and send us just the drive — we don't provide an internal drive-removal service. We don't recover storage soldered to a motherboard (e.g. Apple Silicon Macs and some thin laptops) — only drives that can be removed and sent to us.
↓ Print the booking-in & shipping form (PDF)
Mark the package for the attention of Bristol Data Recovery and we'll call you as soon as we diagnose your media.
Not sure what to send? Call 0800 689 0668 first or use the free online diagnostic.
Free diagnostic, fixed quote, no fix no fee — start now or call the freephone.