Call us — 01223 655015
Mon–Fri · 9am–5:30pm · No fix, no fee
Start a free diagnostic →
/ home / services / forensic
Specialist · digital forensics

Digital forensics in Cambridge.

Recovery and forensic examination use overlapping equipment and produce very different things. One returns your files; the other proves nothing was altered along the way. If findings might be challenged — a tribunal, a court, a disciplinary hearing — that difference decides whether you have evidence or an assertion.

From £800 + VAT
Hash-verified capture
Expert findings report
~ casework-001 — live RECOVERED
$ cdr image /dev/sdb
 Device: Seized laptop HDD (1 TB)
 Status: WRITE-BLOCKED — evidential image
 Case: civil dispute · ref 2026-014

$ cdr engineer-working
 Image hash: SHA-256 checked · confirmed against source
 Deleted files: 4,210 recovered
 Artifacts: metadata and timestamps kept intact

$ cdr verify
 ✓ documents — fully recovered
 ✓ deleted items — carved and dated
 ✓ findings — pulled back whole
// recovery or evidence?

Two different jobs, and the choice has to be made first.

It cannot be applied retrospectively, which is why this section comes before everything else.

RecoveryForensic
ObjectiveGet the files back Establish what happened, when, and by whom — in a form that will survive being challenged. Different aim
HandlingCareful but pragmatic Documented at every step, hash-verified, with an unbroken record of who held the media and when. Chain of custody
OutputYour files, on new media A written report of findings, the methodology used, and a verified image retained for independent examination. A report
Cost and timeFrom £800, days Higher, and longer. The documentation and verification are most of the work rather than an addition to it. Quoted individually
// what can be established

More than most people expect.

Deleted files and the traces they leave behind. When a file was created, last modified, last accessed, and whether those timestamps are internally consistent — inconsistency being itself informative. USB devices connected to a machine and when. Documents printed, files copied to removable media, search terms entered, websites visited and cloud accounts synchronised.

Also what did not happen, which is frequently the point. Establishing that a file was never opened, that a device was never connected, or that a machine was switched off during a period in question can matter as much as establishing the reverse.

What cannot be established honestly is intent. We report what the machine records show. Whether somebody meant to do a thing is a question for whoever is deciding the matter, not for a laboratory report, and any expert offering more than that is exceeding what the evidence supports.

// chain of custody

The part that decides whether findings survive challenge.

01 / RECEIPT

Logged, photographed, sealed

Media is recorded on arrival with condition, serial numbers and seals photographed. Every subsequent transfer is signed for.

02 / IMAGING

Write-blocked, hash-verified

Acquisition through a hardware write blocker so the original cannot be altered. The image is hashed and the hash recorded, so any later change is detectable.

03 / ANALYSIS

On the image, never the original

All examination is conducted against verified copies. The original media is sealed and stored, available for independent examination by another party.

04 / REPORTING

Methodology, findings, limitations

A written report stating what was done, what was found and what could not be determined. The limitations section matters as much as the findings.

// pricing

Quoted individually, after scoping.

Forensic work starts at £800 +VAT and is quoted individually above that, because scope varies enormously between examining one laptop and reconstructing activity across an estate. The figure is fixed after a scoping conversation, before any work begins.

Where a case requires it, a statement in the form courts accept can be provided, and we will say plainly in advance whether the material is likely to support the conclusions you are hoping for.

// questions

Forensic work, answered.

A common instruction and frequently answerable. USB connection records, file access timestamps and cloud sync artefacts are all examinable. Secure the machine now and do not let anyone use it in the meantime.

Often, where user accounts were separate and the machine was not shared. What we report is what the records show, not what somebody intended by it. That distinction matters if the findings are challenged.

That is the point of doing it this way. Write-blocked acquisition, hash verification, documented custody and a report stating methodology and limitations. Whether it is persuasive is for the tribunal.

Say so, and stop now. Using a machine alters timestamps and can overwrite exactly what matters. It does not necessarily ruin the examination, but it has to be recorded and accounted for in the report.

Yes, and in that order — forensic acquisition first, then recovery from the verified image. Doing it the other way round loses the evidential position permanently.

Two to four weeks typically. Acquisition is quick; analysis and writing the report are not, and neither benefits from being rushed.

// need evidence?

Need it recovered? Let’s do it properly.

A free assessment, a forensic write-blocked image, deleted-data recovery and a clear written report. Talk to us in confidence today.