From engineering firms around Port Talbot to software teams in the city centre, the pattern repeats: a trusted employee joins a rival, and soon your drawings, code or price list follow. We evidence what was taken, how and when — to a standard that supports an injunction.
Discreet, documented, defensible. A free diagnostic and an agreed written scope come first; forensic work is payable upfront.
For product, engineering and service businesses across Swansea Bay and the M4 corridor, these are the moments to preserve first and ask questions second.
Almost nobody hacks their way to a trade secret; they are handed a login and walk out with it. The commercial damage lands later, when a rival bid undercuts yours by a suspiciously precise margin or a familiar design appears under another badge. The forensic questions are narrow and answerable — which files, which route, which dates — and every one of them is asked of your own systems, where the evidence already sits.
Imaging the relevant workstation, laptop or file server lets us rebuild the exfiltration end to end. Removable-media records show bulk copies of drawing sets or code repositories; browser and sync artefacts show uploads to private cloud storage, webmail or transfer sites; access and print logs record who opened or output the confidential set. Deleted material is carved back, and a keyword sweep across the whole image finds files by project name, part number or the confidentiality banners they carry.
Provenance can be decisive. Office files, PDFs and CAD drawings carry hidden metadata — authorship, company fields, revision chains, creation stamps and internal identifiers — that survives casual renaming. Compared against your originals, it can demonstrate that a document produced by a competitor descends from yours, provided the material reaches us by a lawful route such as disclosure or a court order. That comparison often turns an uneasy resemblance into expert evidence.
IP disputes reward whoever preserves first. Early imaging strengthens a springboard or search-order application and fixes the evidence before it can be tidied away. Devices are secured immediately; work proceeds from write-blocked, hash-verified images under a logged chain of custody; and the report is prepared to expert-witness standard, findings first and technical appendix behind. Where a court orders a respondent's device imaged, we carry the order out exactly — covert access to anyone's private device is never on the table.
Our forensic data recovery hub explains the imaging, hashing and custody discipline every IP case runs on. Forensic fees are payable upfront — £800 + VAT for a standard investigation with a detailed report, £400 + VAT for the report-free binary-image and deleted-file extraction — as listed on the data recovery cost page. Encrypted exhibit drives go through our BitLocker recovery service using keys you lawfully hold.
From a forensic image of your systems, these are the strands that turn suspicion into an evidenced account.
Drawing sets, repositories and databases moved to USB or cloud.
Hits on project names, part numbers and confidentiality banners.
Metadata linking a rival's document back to your original.
Webmail, transfer sites and private cloud accounts in play.
Deleted and archived files brought back into evidence.
Who touched the confidential set, and what they did with it.
Everything we examine is either your own company equipment or a device a court has ordered imaged, executed precisely as directed. We do not covertly pull data from a competitor's systems or an individual's private hardware — not only because it is unlawful, but because improperly obtained material collapses in front of a judge and takes the rest of the case's credibility with it. In IP litigation the lawful path and the winning path are the same path.
In IP cases the first hours decide what survives, so call 0800 689 0668 before anyone has a look at the machine. We will agree which devices to image and how to move them securely, with the chain of custody logged from arrival at our secure Bristol location.
Sending a drive from a computer, laptop, MacBook, iMac, CCTV / DVR or server? Please remove the internal hard drive or SSD and send us just the drive — we don't provide an internal drive-removal service. We don't recover storage soldered to a motherboard (e.g. Apple Silicon Macs and some thin laptops) — only drives that can be removed and sent to us.
↓ Print the booking-in & shipping form (PDF)
Mark the package for the attention of Bristol Data Recovery and we'll call you as soon as we diagnose your media.
Not sure what to send? Call 0800 689 0668 first or use the free online diagnostic.
Withdraw the devices from use and call the freephone — early imaging is what keeps an injunction alive.