An image is the cheapest insurance in this trade and the one most often bought too late. Once a machine is wiped and reissued, every question anybody thinks of afterwards has no answer, and no amount of money reverses that. A capture takes the disk exactly as it stands, verifies it, seals it and files it — and the hardware goes back into service. £400 + VAT preserves and extracts; £800 + VAT adds the examination and its written report.
◇ Authority first. Bench afterwards. The full examination, written up as a report, comes to £800 + VAT. Stop at a verified image with its deleted material extracted and nothing reported, and it is £400 + VAT — the rung a recorder disk already occupies. Diagnosis is free and the scope is agreed in writing beforehand. No fix, no fee all jobs except electronic and mechanical failures, chip level work, DVR and Forensic jobs. Ordinary recovery bands are on the data recovery cost page.
Any single one of these justifies taking an image before the machine is touched again.
The conflict here is practical rather than legal. IT wants the asset back in circulation and the lawyers want it untouched, and those two positions look irreconcilable until somebody takes an image. Once a verified copy exists the physical machine stops being evidence and becomes a laptop again. In most cases that is a day or two out of service, not a month, and the copy is good for as long as the file is kept. The failure mode is always the same and always avoidable: a device gets rebuilt in week two because nobody had authority to say no, and in week nine somebody asks what was in the downloads folder.
A disk image is not a copy of the documents. It is a copy of the volume, including the parts the operating system does not show you. Deleted files still sitting in unallocated space. Browser history, cache and cookies, which reconstruct research, uploads and sign-ins in some detail. The page file and the hibernation file, which frequently hold fragments of documents that were open, chat that was on screen and occasionally a credential. Local Teams and Slack stores, including conversations since deleted from the server. Registry hives carrying the device register and the software history. VPN and network records placing the machine on a particular network at a stated hour. None of that survives a rebuild, and none of it can be reconstructed afterwards.
BitLocker and FileVault are the most common reason a capture goes wrong, and almost always for an administrative reason rather than a technical one. A volume can be imaged while it is locked, but the image is useless without a key, and the key has a habit of leaving with the person. BitLocker recovery keys are normally escrowed to Active Directory, to Entra ID or to a Microsoft account; FileVault keys go to a management platform or to the user's Apple account. Retrieve the key first, capture second, and record where the key came from. Where no key exists anywhere the answer is that the volume cannot be read, by us or by anybody, and that is said on the telephone rather than discovered after two weeks. <a href="bitlocker-recovery.html">BitLocker recovery</a> covers the non-forensic version of the same problem.
A machine handed back freshly reinstalled is not the dead end it is assumed to be, and it is often more informative than one handed back untouched. A quick reinstall leaves most of the previous volume in unallocated space. It also leaves timestamps: the installation has a date, and if that date sits between the resignation and the handover, the fact is worth stating on its own. Erase utilities leave prefetch entries, installation records and a characteristic pattern on the surface. A full multi-pass wipe of a spinning disk does genuinely destroy the contents — in which case the finding is that a wipe was performed, by which tool and at what hour, and that finding tends to be worth having.
The method and custody standards behind every capture are at the forensic recovery hub, the obligations that make a capture necessary are at legal hold and chain of custody, and what an image is then asked is at deleted-file forensics and USB device forensics.
All of it comes from one acquisition. None of it survives a rebuild, and none of it can be recreated later.
An E01 holding the whole volume, mountable and checkable by any examiner.
SHA-256 taken at acquisition and matched again at every verification since.
History, cache and cookies, rebuilding research, uploads and where somebody signed in.
Page file and hibernation data: documents left open, chat on screen, the odd credential.
What Teams and Slack kept on disk, server-side deletions included.
VPN sessions and connection records fixing the machine to a network at an hour.
The least popular sentence first. Forensic work does not sit under no fix, no fee. That guarantee belongs to logical recovery, and the exclusions published beside it are electronic and mechanical failures, chip-level work, DVR jobs and forensic jobs. An examination is bench hours spent answering a question you have asked, and the hours are the same whether the answer helps your case or wrecks it. Against that, two figures are printed here rather than quoted on application, which is two more than most laboratories will commit to in public. Where the examination finishes with a full written report the fee is £800 + VAT. Where it finishes at the evidence — a verified binary image with the deleted material lifted out of it, handed to your solicitor or to another examiner to interpret — the fee is £400 + VAT. That lower figure is the same rung as a recorder disk or a BitLocker volume, so nothing on this page invents a sixth band.
The examination plus the written report it produces, set out so that an expert paid to disagree with you can follow every step and try to break it.
The verified binary image with its deleted material extracted, and no report written. The rung a recorder disk or an encrypted volume already occupies, not an extra band.
Both assume a single machine and a single question asked of it. Eleven laptops, a file server and a tenancy export is a larger exercise altogether, so anything spanning several devices is measured during the free diagnostic and written down before you are asked to agree to it. Working out what is there costs nothing and still closes 2 working days after the device is booked in at Cambridge, and the fee is settled before an examiner opens the image rather than after the findings are known. Anything that is not forensic keeps the band it has always had on the prices page.
Capture work is done on hardware the business owns and issued, or on written instruction from a solicitor or the court. Three routes reach this bench and there has never been a fourth. Kit the business bought and issued to somebody. A written instruction from a solicitor, an insurer or the court. Or a device that genuinely belongs to the person asking, which in a family matter means owned outright or owned jointly. Nothing is broken into here. Somebody else's password is not worked out, monitoring software is not installed on a device the client does not own, and live traffic is never intercepted — interception belongs to the bodies named in the Investigatory Powers Act 2016 and to no private laboratory. Where a client has no lawful right to look inside a device, instructing us does not manufacture one. Handsets and tablets are outside the practice altogether.
Send the drive rather than the whole machine wherever the disk comes out, and ring 0800 689 0668 first so the packaging and the paperwork are agreed. Nothing is collected anywhere in this network and there is no Leicester counter: it goes to Cambridge by tracked, insured post, or over the counter there in office hours. Storage soldered to a mainboard, as on Apple Silicon machines, cannot be removed and cannot be posted.
The general rule is the drive travels and the machine stays behind — out of the laptop, out of the tower, out of the iMac, out of the recorder under the counter. This bench does not dismantle equipment, and a repair shop will do it while you wait. Three things are the other way round, and getting them wrong costs you the recovery: an external drive stays sealed in its own case, a NAS comes as a complete unit, and a WD My Passport or My Book travels whole with its cable, because on those the encryption key is held on the bridge board rather than on the disk — separate the two and the data becomes unreadable even to us. A Fusion Mac needs both of its drives, each labelled. The one thing nobody can work round is flash soldered onto the mainboard, as on Apple Silicon machines: if it will not come off, there is nothing to post.
↓ Print the shipping & booking-in form (PDF)
Address it to Cambridge Data Recovery. It is about seventy miles from Leicester if you fancy driving it — M1 south to Junction 19, then the A14 east — and the lab is two minutes off Junction 32 with parking at the door. Posting costs you a stamp and a day instead. Whichever you choose, you hear from us the moment it is booked in, and the free diagnostic closes two working days after that.
Not certain what belongs in the box? Ring 0800 689 0668 before you tape it up, or let the free online diagnostic ask the questions for you.
A verified copy takes a day or two and lasts as long as you keep the file. A rebuild takes an afternoon and lasts for ever.