Home / Forensic Recovery / IP & Trade Secret Theft

IP & Trade Secret Theft

From engineering firms around Port Talbot to software teams in the city centre, the pattern repeats: a trusted employee joins a rival, and soon your drawings, code or price list follow. We evidence what was taken, how and when — to a standard that supports an injunction.

Discreet, documented, defensible. A free diagnostic and an agreed written scope come first; forensic work is payable upfront.

// does this look familiar

Signals that trade secrets are on the move

For product, engineering and service businesses across Swansea Bay and the M4 corridor, these are the moments to preserve first and ask questions second.

A senior hire departing for — or quietly founding — a competitor
CAD drawings, source code or formulations copied near a resignation
Tenders or pricing turning up in a rival's bid
Heavy USB or cloud activity in someone's final month
Confidential folders accessed far beyond one role's needs
A competitor's product that resembles yours a little too closely

How IP usually leaves — quietly

Almost nobody hacks their way to a trade secret; they are handed a login and walk out with it. The commercial damage lands later, when a rival bid undercuts yours by a suspiciously precise margin or a familiar design appears under another badge. The forensic questions are narrow and answerable — which files, which route, which dates — and every one of them is asked of your own systems, where the evidence already sits.

Reconstructing the route out

Imaging the relevant workstation, laptop or file server lets us rebuild the exfiltration end to end. Removable-media records show bulk copies of drawing sets or code repositories; browser and sync artefacts show uploads to private cloud storage, webmail or transfer sites; access and print logs record who opened or output the confidential set. Deleted material is carved back, and a keyword sweep across the whole image finds files by project name, part number or the confidentiality banners they carry.

When the file is already in a rival's hands

Provenance can be decisive. Office files, PDFs and CAD drawings carry hidden metadata — authorship, company fields, revision chains, creation stamps and internal identifiers — that survives casual renaming. Compared against your originals, it can demonstrate that a document produced by a competitor descends from yours, provided the material reaches us by a lawful route such as disclosure or a court order. That comparison often turns an uneasy resemblance into expert evidence.

Speed, injunctions and the High Court

IP disputes reward whoever preserves first. Early imaging strengthens a springboard or search-order application and fixes the evidence before it can be tidied away. Devices are secured immediately; work proceeds from write-blocked, hash-verified images under a logged chain of custody; and the report is prepared to expert-witness standard, findings first and technical appendix behind. Where a court orders a respondent's device imaged, we carry the order out exactly — covert access to anyone's private device is never on the table.

Our forensic data recovery hub explains the imaging, hashing and custody discipline every IP case runs on. Forensic fees are payable upfront — £800 + VAT for a standard investigation with a detailed report, £400 + VAT for the report-free binary-image and deleted-file extraction — as listed on the data recovery cost page. Encrypted exhibit drives go through our BitLocker recovery service using keys you lawfully hold.

// inside the examination

What we look for in the image

From a forensic image of your systems, these are the strands that turn suspicion into an evidenced account.

Bulk copy events

Drawing sets, repositories and databases moved to USB or cloud.

Keyword & marking sweeps

Hits on project names, part numbers and confidentiality banners.

File lineage

Metadata linking a rival's document back to your original.

Uploads & sends

Webmail, transfer sites and private cloud accounts in play.

Carved material

Deleted and archived files brought back into evidence.

Open, export & print logs

Who touched the confidential set, and what they did with it.

Your estate, or a court's order — never a shortcut

Everything we examine is either your own company equipment or a device a court has ordered imaged, executed precisely as directed. We do not covertly pull data from a competitor's systems or an individual's private hardware — not only because it is unlawful, but because improperly obtained material collapses in front of a judge and takes the rest of the case's credibility with it. In IP litigation the lawful path and the winning path are the same path.

// getting your device to us

Post or courier your device — it's simple

In IP cases the first hours decide what survives, so call 0800 689 0668 before anyone has a look at the machine. We will agree which devices to image and how to move them securely, with the chain of custody logged from arrival at our secure Bristol location.

Sending a drive from a computer, laptop, MacBook, iMac, CCTV / DVR or server? Please remove the internal hard drive or SSD and send us just the drive — we don't provide an internal drive-removal service. We don't recover storage soldered to a motherboard (e.g. Apple Silicon Macs and some thin laptops) — only drives that can be removed and sent to us.

  • Wrap the device in bubble wrap or a padded envelope — no need to include cables or power supplies.
  • Print and enclose the booking-in & shipping form (PDF) with your name, phone number and a brief description of what happened.
  • Send by Royal Mail Special Delivery or any tracked courier for full insurance in transit.
  • Prefer to hand it over in person? You can drop it in at reception at the address shown, Mon–Fri 9:00am–5:30pm.
// send your device to your nearest location

Bristol Data Recovery

Castlemead
Lower Castle Street
Bristol, BS1 3AG

↓ Print the booking-in & shipping form (PDF)

Mark the package for the attention of Bristol Data Recovery and we'll call you as soon as we diagnose your media.

Not sure what to send? Call 0800 689 0668 first or use the free online diagnostic.

// ip & trade secret theft — your questions

Common questions

Frequently, yes. An image of the work machine typically shows bulk copies to removable media or cloud storage, the confidential files being opened or printed, and attempts to tidy up afterwards — each anchored to dates and device identifiers and presented as an evidenced sequence.
Often. Embedded metadata — authors, company fields, revision history, internal identifiers — regularly survives renaming and light editing, and compared with your originals can show descent from your file. The rival's material must reach us lawfully, typically through disclosure or a court order.
Immediately, ideally. Preservation in the first days protects a springboard or search-order application and keeps the trail from being overwritten. Withdraw the relevant machines from use, image nothing yourself, and call us or your solicitor before the day is out.
It is prepared to that standard: write-blocked and hash-verified imaging, logged custody, a transparent method, and expert-witness-style reporting with a technical appendix — suitable for injunction applications and for directions agreed between solicitors.
// more forensic case types

Other case types we cover

Protect the proof before it fades

Withdraw the devices from use and call the freephone — early imaging is what keeps an injunction alive.