Every returned laptop has one forensic moment, and it sits between hand-back and rebuild. Captured then — behind a write-blocker, into E01 evidence files, verified by SHA-256 — the machine goes on answering questions for years. Returned to service instead, it answers fewer of them every week. For employers from the Baltic Triangle studios to university departments and the offices of the commercial district, the rule is short: the questions will wait, the image will not.
◇ Scope first, then work. Diagnosis is free and comes at the beginning; the written scope follows, and the forensic fee is paid in full before an examiner opens the image. No fix, no fee all jobs except electronic and mechanical failures, chip level work, DVR and Forensic jobs. The whole price list sits on the data recovery cost page.
Any one of these puts a machine on the list, ahead of the rebuild queue.
The arithmetic is one-sided. An image taken today — the disk read behind a write-blocker into E01 files and verified by SHA-256 — costs a fraction of what the same evidence is worth once there is a dispute to spend it on, and the hardware returns to service afterwards because the evidence no longer depends on it. Skip the image, reissue the laptop, and every day of the new user's work settles over the last user's traces. Firms that image every leaver's machine as routine never have to explain an absence.
A great deal more than the documents. Browsing history, cache and cookies reconstruct research and uploads. Drafts and copies nobody consciously saved sit among the temporary files. Fragments of memory — a document left open, a chat window, occasionally a credential — persist in the pagefile and the hibernation file. Slack and Teams keep local caches that return conversations deleted from the applications themselves. VPN and connection logs place the machine on given networks at given hours. A rebuild removes all of it. A capture keeps it.
Encryption rewards acting early. A device protected by BitLocker or FileVault should be imaged while the keys remain in escrow and the passwords are still known, before the leaver's account is closed, the directory tidied, or the TPM cleared by a rebuild. On a live, unlocked Windows volume there is a second route: Volume Shadow Copies taken from the running system, which sidestep the encryption question because the volume is open while you hold it. Encrypted-volume work counts as forensic and, like everything else on this page, is paid for in advance once the scope is agreed.
A claim of wiping is tested, not accepted. Erase utilities and boot tools, DBAN among them, leave their own evidence: boot records, tool signatures, the pattern an overwrite writes across the platters, and timing that can be set against everything else happening that week. Interrupted and partial runs are frequent and leave whole regions recoverable, while a hardware erase command can be read against the drive's own logs. If the wipe did complete, the report says so and dates it, because deliberately wiping a drive as proceedings approach is a finding in its own right.
Custody and verification are described at the forensic recovery hub. How deletion evidence reads on a copy belongs with deleted-file forensics, and the duty to preserve with legal hold and chain of custody. The numbers are on the prices page.
Taken once, verified once, and available for whatever the dispute asks later.
The whole disk in a container any examiner can open and verify.
SHA-256 proving the image, and each copy taken from it, unchanged.
History, cache and cookies reconstructing research and uploads.
Pagefile and hibernation contents: documents, conversations, credentials.
Local Slack and Teams stores, with deleted conversations recovered.
VPN and network traces placing the machine on networks at set hours.
Diagnosis is free and takes 2 working days from the morning the parcel is opened. Nothing forensic runs under no fix, no fee. A forensic investigation ending in a written report is £800 + VAT, settled in full before the examination opens. Where no report is wanted, the binary image with deleted-file extraction stands on its own at £400 + VAT. Forensic work is paid for in advance, without exception. BitLocker and other encrypted-volume work counts as forensic and is paid for in advance on the same terms. The same two figures appear on the prices page, and you are asked for nothing until the written scope has been agreed.
Imaging runs on company-owned machines, on hardware you own yourself, or under a solicitor's instruction. Only three routes reach an examination and there is no fourth. Hardware the business itself bought. A written instruction from solicitors, from an insurer or from the court. Or a device belonging to the client, which in a family matter extends to a machine the couple own between them. Nothing is broken into on this bench. Live traffic is never intercepted: that power belongs to the agencies named in the Investigatory Powers Act 2016 and nowhere else. If a client may not lawfully look inside a device, the answer here is the same one.
Tell us how many machines are involved and where you stand on encryption when you ring 0800 689 0668, and the capture is scoped in writing. Nothing is collected anywhere in this network, so the drives go by tracked, insured post to the Manchester laboratory and custody is recorded at booking-in.
Still screwed inside a laptop, tower, MacBook, iMac, server or a CCTV recorder? Take the drive out and post that on its own. We do not strip machines here, and any computer shop will do it in a few minutes. The one job nobody can take on is flash soldered straight to a logic board, as on Apple Silicon Macs and a handful of very slim laptops: if the storage will not unbolt, there is nothing to send.
↓ Print the shipping & booking-in form (PDF)
Address it to Manchester Data Recovery. It is roughly 35 miles from Liverpool along the M62 if you fancy the run, and next working day by tracked post if you do not. We ring or email the moment it is booked in, and the free diagnostic closes 2 working days after that.
Not sure what belongs in the parcel? Call 0800 689 0668 before you tape it shut, or step through the free online diagnostic first.
A single capture holds every answer the machine still contains — ring the freephone.