The laptop came back empty, the ex-employee started at a competitor on Monday, and the business needs to know exactly what happened before the wipe. Forensic recovery is data recovery that must survive cross-examination — handled for Swansea companies and solicitors with the paperwork to match.
Free diagnostic on every forensic job. One fixed quote in writing before any work begins.
No fix, no fee all jobs except electronic and mechanical failures, chip level work, DVR and Forensic jobs. Full pricing is on the data recovery cost page.
Every forensic job starts by matching the symptoms to the fault — these fifteen cover almost everything that reaches the bench.
Our most frequent instruction — and usually both the wipe itself and the behaviour leading up to it can be pieced back together.
Windows logs device serials and connection times; cross-referenced with file access, the picture forms.
Uploads to personal Gmail, Dropbox and WeTransfer leave residue in history, logs and remnants.
Deleted documents and mail carved back and presented under a hash-verified, defensible method.
When each file was really made, read and altered — reassembled from file-system records, the USN journal and event logs.
Which confidential material moved, when it moved, and under which account.
Company equipment examined under company policy, frequently on joint solicitor instruction.
Footage and files recovered forensically for claims and proceedings.
Impartial, documented findings for internal processes, insurers and tribunals.
Instructions carried out precisely as the two sides' solicitors have jointly directed.
CCleaner, BleachBit and similar wipers leave traces of their own — what ran, when, and what survived it.
OneDrive and Google Drive sync artefacts show what left through a personal account.
$I metadata survives emptying and dates each deletion — a small artefact with decisive timeline value.
Spool files and print history reveal hard-copy exfiltration no USB log would ever show.
We don't examine phones themselves, but their PC backups and sync folders are fully in scope.
The pattern repeats at employers everywhere: in the final fortnight, company files move to a USB stick, a personal inbox or a cloud share, and then a wiping tool or factory reset scrubs the laptop before it's handed back. What's left looks empty — and isn't. The wipe itself leaves fingerprints: which tool ran and at what minute, which USB serial numbers connected in those last weeks, what was opened moments before each one, what went out through webmail, and which deleted documents can still be carved whole from the disk. All of it lands in a plain-English report with the technical evidence behind it.
Four situations account for nearly everything we're instructed on, and each has a dedicated guide of its own: data theft by a departing employee, where a leaver's copying needs proving; divorce and matrimonial examinations, always run lawfully through the solicitors involved; partnership and director disputes over contested company records and system access; and finally theft of intellectual property — the designs, source code and client lists that walked. Beneath all four sits one unchanging method: write-blocked images, a rebuilt timeline, findings that hold.
The investigation bench pairs OSForensics — PassMark's suite for deleted-file recovery, whole-drive indexing, USN-journal timelines and artefact harvesting (USB history, browser and download records, webmail traces, recent-file lists) — with Passware Kit Forensic for lawfully opening the password-protected files and BitLocker volumes that block the view. Nothing runs against your original media: every examination works from a write-blocked, hash-verified image that any opposing expert can validate independently.
Procedure is the product: write-blockers from first contact, MD5, SHA-1 and SHA-256 verification, an unbroken documented chain of custody, and reports separated into findings and technical appendix precisely so tribunals can rely on them. We take joint instructions agreed between solicitors. And one bright line: there must be a lawful basis — your own equipment, company machines under company policy, or matters routed through solicitors and insurers. Covert examination of another person's private device is refused every time, however compelling the story.
Forensic recovery produces evidence, not just data — so the tooling and the procedure carry equal weight:
PassMark's investigation platform carries the caseload: pulling back deleted files, indexing and searching every sector of the drive, and extracting artefacts from hundreds of formats, OCR included.
Timestamps, the USN change journal and the machine's logs are woven into a minute-level account of activity — establishing what happened and precisely when.
Which devices connected, when, and what was accessed around each connection — the spine of any data-theft investigation.
Password-protected files and BitLocker volumes standing between us and the evidence are opened where the law allows.
From the first moment, originals sit behind write-blockers and are imaged to copies verified by MD5, SHA-1 and SHA-256 hashes — provably exact to anyone who checks.
An unbroken custody record from your hands to ours, with reporting delivered as readable findings up front and the technical appendix behind — a structure tribunals can lean on.
One rule sits before any instruction: there must be a lawful basis — your own hardware, company machines under company policy, or a matter routed through solicitors or insurers. Covert access to another person's private device is refused without exception, and forensic engagements are payable upfront once quoted.
The drive needs to be removed from your computer before you send it in to us. Unsure? Phone us on 0800 689 0668, or a local PC repair shop will remove it for a small fee.
Treat the device as an exhibit from this moment: power it off and let nobody log in, 'have a quick look' or re-image it — each of those tramples recoverable evidence. Note the names and dates that matter, remove and label the drive, and if the machine itself must stay intact as evidence, ring 0800 689 0668 and we'll set up documented chain-of-custody handling for the whole unit.
Most customers post or courier their media to us.
Sending a drive from a computer, laptop, MacBook, iMac, CCTV / DVR or server? Please remove the internal hard drive or SSD and send us just the drive — we don't provide an internal drive-removal service. We don't recover storage soldered to a motherboard (e.g. Apple Silicon Macs and some thin laptops) — only drives that can be removed and sent to us.
↓ Print the booking-in & shipping form (PDF)
Mark the package for the attention of Bristol Data Recovery and we'll call you as soon as we diagnose your media.
Not sure what to send? Call 0800 689 0668 first or use the free online diagnostic.
Free diagnostic, fixed quote, no fix no fee — start now or call the freephone.