Lab accepting new cases ·  Mon–Fri, 9am–5:30pm Urgent? Call 01273 964902
BDR Brighton Data Recovery 01273 964902 Start a case
BDR / Evidence & investigations / Forensic data recovery

Evidence & investigations · forensic data recovery

Recovery that would survive cross-examination.

Ordinary recovery asks one question: can the data come back? Forensic recovery asks two more: can you prove nothing changed, and could someone else repeat it? The answer is write-blockers, hashes, and notes taken as it happens — not afterwards.

Court-ready reports — CPR 35 / CrimPR 19 Documented chain of custody Independent & confidential

Talk it through, in confidence
01273 964902

Defensible acquisition, piece by piece.

Write-blockersHardware between the evidence and everything else: the source can be read but physically cannot be written to. The first principle, made of circuitry.
E01 and raw imagesBit-for-bit copies in Expert Witness Format — which carries its own metadata and checksums — or raw dd where a case calls for it.
MD5 + SHA-256 hashingA mathematical fingerprint taken at acquisition and verified after: proof the image matches the source, byte for byte, that anyone can re-run.
Exhibits & continuityUnique exhibit references, sealed storage, a handling log, and contemporaneous notes — the paper trail opposing experts actually check.

What forensic recovery is asked to do.

Not sure? Ask us →
The situationWhat we establishWhat you receive
Files deleted — innocently or otherwiseWhether they existed, when they went, and what can be brought backRecovered material with its recovery documented
A drive someone tried to wipeWhat the wiping tool was, when it ran, and what survived itA survival map, and the survivors
An encrypted container or BitLocker volumeDecryption via Passware where passwords or keys can be lawfully establishedDecrypted evidence, method on the record
A physically failing drive that's also evidenceRecovery with the same imaging discipline our lab applies to any failing drive — plus the forensic trailData back, chain of custody intact
A dispute over when something happenedFile-system timestamps and artefacts, read together and honestly caveatedA timeline that says what it can prove
Getting it to us: devices and drives travel tracked and fully insured to our secure intake lab — free return postage — or start by phone and we'll agree the safest route for your matter. Details on the contact page.

How the work runs, stage by stage.

See recent cases →
01

Scoped in confidence, quoted in writing Free

Every instruction starts with a confidential conversation: what happened, which devices and accounts exist, and what question the evidence needs to answer. You get a fixed written quote before any examination begins — and the initial scoping costs nothing.

Confidential scopingFixed written quoteClear question defined
02

Write-blocked acquisition

The source connects only through a hardware write-blocker and is imaged bit-for-bit — E01 with embedded checksums, or raw where instructed.

Hardware write-blockersBit-for-bit E01 / raw
03

Hash and verify

MD5 and SHA-256 fingerprints are computed at acquisition and re-verified against the completed image — the mathematical proof that nothing changed in the copying.

MD5 + SHA-256Verified before analysis
04

Recover on the image, forensically

Deleted, damaged and encrypted material is recovered from the image with the trail preserved — Passware handles encrypted volumes where lawful authority and credentials exist.

Deleted data recoveredPassware for encrypted volumes
05

Delivered, preserved, defensible

You receive the findings — report, exhibits and supporting files — with hashes, continuity records and our contemporaneous notes preserved. If the work is ever tested by another expert or a tribunal, the trail is there to be followed.

Report + exhibitsHashes & continuity keptReady if challenged

What the lab holds to

  • The E01 format carries its own honesty — metadata and block checksums travel inside the image, so tampering announces itself.
  • Hashes are re-run, not just recorded — verification after imaging is what turns a fingerprint into proof.
  • Notes are contemporaneous or they're anecdotes — reconstructed-later records are exactly what opposing experts pull apart.
  • Failing hardware doesn't excuse the discipline — a dying drive gets the same write-blocked, imaged, hashed treatment, just more carefully.

Where the statutory line sits: the Forensic Science Regulator's Code — Version 2, in force since 2 October 2025 — legally governs forensic work for criminal investigations and proceedings in England and Wales. Civil, workplace and insurance instructions sit outside its enforcement scope. We work to the same disciplines either way, and we'll tell you plainly which side of that line your matter is on.

From the casebook.

EX · BDR-2026-0527VERIFIED ✓

A wiped laptop, and the fifteen minutes that mattered

A leaver ran a wiping tool the night before returning their machine. The tool's own logs, the run window, and the files it missed were all recovered from the image — and the timeline of what happened first told the rest of the story.

Timeline establishedReport in 8 days

Before it reaches us.

Do

  • Power the device down and stop all use
  • Record who has handled it since the event
  • Preserve chargers, docks and any known passwords
  • Tell us if the matter could ever reach court

Don't

  • Let anyone preview the drive first
  • Run recovery software before imaging
  • Break seals or open the device
  • Wait — artefacts age and overwrite

Asked in confidence, answered honestly.

What makes digital evidence admissible?

Broadly: unchanged data, a competent examiner, a reproducible audit trail, and relevance. Write-blocked imaging, hashing and contemporaneous notes are how the first three get proven rather than promised.

What is a write-blocker?

A hardware device that lets a drive be read but physically prevents any write to it — so the original stays exactly as received, provably.

Can you open encrypted drives?

Where the instructing party has lawful authority and passwords or keys can be established, yes — Passware is our tool for that work, run against the image, with the method documented. Without any key, strong encryption stays shut; we'll say so early.

How is this different from normal data recovery?

The recovery techniques overlap; the difference is proof. Forensic work adds write-blocking, hashing, exhibit continuity and notes taken as-it-happens — so the result can withstand someone whose job is to doubt it.

Evidence doesn't wait. Neither should you.

Loops overwrite, artefacts age, deadlines pass. Open a case first — the scoping conversation is free and confidential either way.

01273 964902