Recovery and forensic examination use overlapping equipment and produce very different things. One returns your files; the other proves nothing was altered along the way. If findings might be challenged — a tribunal, a court, a disciplinary hearing — that difference decides whether you have evidence or an assertion.
$ cdr image /dev/sdb → Device: Seized laptop HDD (1 TB) → Status: WRITE-BLOCKED — evidential image → Case: civil dispute · ref 2026-014 $ cdr engineer-working → Image hash: SHA-256 checked · confirmed against source → Deleted files: 4,210 recovered → Artifacts: metadata and timestamps kept intact $ cdr verify → ✓ documents — fully recovered → ✓ deleted items — carved and dated → ✓ findings — pulled back whole
It cannot be applied retrospectively, which is why this section comes before everything else.
Deleted files and the traces they leave behind. When a file was created, last modified, last accessed, and whether those timestamps are internally consistent — inconsistency being itself informative. USB devices connected to a machine and when. Documents printed, files copied to removable media, search terms entered, websites visited and cloud accounts synchronised.
Also what did not happen, which is frequently the point. Establishing that a file was never opened, that a device was never connected, or that a machine was switched off during a period in question can matter as much as establishing the reverse.
What cannot be established honestly is intent. We report what the machine records show. Whether somebody meant to do a thing is a question for whoever is deciding the matter, not for a laboratory report, and any expert offering more than that is exceeding what the evidence supports.
Media is recorded on arrival with condition, serial numbers and seals photographed. Every subsequent transfer is signed for.
Acquisition through a hardware write blocker so the original cannot be altered. The image is hashed and the hash recorded, so any later change is detectable.
All examination is conducted against verified copies. The original media is sealed and stored, available for independent examination by another party.
A written report stating what was done, what was found and what could not be determined. The limitations section matters as much as the findings.
Forensic work starts at £800 +VAT and is quoted individually above that, because scope varies enormously between examining one laptop and reconstructing activity across an estate. The figure is fixed after a scoping conversation, before any work begins.
Where a case requires it, a statement in the form courts accept can be provided, and we will say plainly in advance whether the material is likely to support the conclusions you are hoping for.
A common instruction and frequently answerable. USB connection records, file access timestamps and cloud sync artefacts are all examinable. Secure the machine now and do not let anyone use it in the meantime.
Often, where user accounts were separate and the machine was not shared. What we report is what the records show, not what somebody intended by it. That distinction matters if the findings are challenged.
That is the point of doing it this way. Write-blocked acquisition, hash verification, documented custody and a report stating methodology and limitations. Whether it is persuasive is for the tribunal.
Say so, and stop now. Using a machine alters timestamps and can overwrite exactly what matters. It does not necessarily ruin the examination, but it has to be recorded and accounted for in the report.
Yes, and in that order — forensic acquisition first, then recovery from the verified image. Doing it the other way round loses the evidential position permanently.
Two to four weeks typically. Acquisition is quick; analysis and writing the report are not, and neither benefits from being rushed.
A free assessment, a forensic write-blocked image, deleted-data recovery and a clear written report. Talk to us in confidence today.