Home / Devices / forensic

Forensic Data Recovery Swindon

The laptop came back suspiciously clean, the leaver started with a rival on Monday, and the company needs to know what happened in the fortnight before the wipe. Forensic recovery is recovery that must hold up under cross-examination — delivered for Swindon and Wiltshire employers, insurers and solicitors with the documentation to match.

Free diagnostic on every forensic job. One fixed quote in writing before any work begins.

No fix, no fee all jobs except electronic and mechanical failures, chip level work, DVR and Forensic jobs. Full pricing is on the data recovery cost page.

// top 20 faults we recover from

The twenty ways they fail

Every forensic job starts by matching the symptoms to the fault — these twenty cover almost everything that reaches the bench.

Wiped before the exit interview

Our most frequent instruction — and both the wipe and the behaviour before it can usually be pieced back together.

USB copying suspected

Windows logs device serials and connection times; set against file-access records, the story assembles itself.

Webmail / cloud leaks

Transfers out via private Gmail, Dropbox or WeTransfer shed traces into histories, logs and leftover fragments.

Bulk deletions

Erased documents and mailboxes recovered by carving, then presented under a defensible, hash-verified method.

Timestamps in dispute

Establishing when a file genuinely came into being, was read, or changed — pieced together from file-system records, journal entries and event logs.

IP walking out the door

Which confidential material moved, at what moment, and under whose account.

Director and partner fallouts

Company equipment examined under company policy, often on instructions agreed by both sides' solicitors.

Evidence deleted from devices

Files and footage recovered forensically for claims, defences and proceedings.

HR and insurance matters

Neutral, fully documented findings serving HR processes, insurers and tribunal hearings.

Solicitor-directed work

Examinations run precisely to the joint directions the parties' solicitors agree.

Anti-forensics detected

CCleaner, BleachBit and their kind sign their own work — revealing which tool ran, at what time, and what escaped it.

Cloud-sync exfiltration

Sync artefacts from OneDrive and Google Drive map out what departed through a personal account.

Recycle-bin archaeology

$I records outlive the emptying of the bin and timestamp every deletion — tiny artefacts, outsized timeline value.

Printed-then-taken documents

Print spools and history betray paper-based exfiltration that never troubles a USB log.

Phone-adjacent evidence

Handsets stay outside our remit; the phone backups and sync folders sitting on a PC are firmly inside it.

Backdated document suspicion

Internal metadata, revision history and journal entries betray a file dressed up as older than it is.

Contractor left with the CAD library

Freelancers and subcontractors copying drawings on the last day leave the same USB and cloud traces as staff.

Shared-mailbox purges

Mass deletions from group mailboxes are timed, attributed to an account, and recovered where retention allows.

Desktop messaging artefacts

WhatsApp Desktop, Teams and Slack leave local caches that survive the apps — often the candid record a dispute needs.

Remote access after departure

VPN logs, event records and file access prove whether an ex-employee's credentials kept working — and what they touched.

The wiped laptop, reconstructed

The pattern rarely varies: during the notice period, company files migrate to a USB stick, a private inbox or a cloud share; a wiping tool or factory reset then cleans the machine before hand-back. It looks empty. It isn't. The wipe leaves its own evidence — which tool ran and to the minute when, which USB serial numbers appeared in the final weeks, which documents were opened just before each connection, what left through webmail, and which deleted files can still be carved back whole. It all lands in a readable report, technical workings attached.

Four recurring instructions, four guides

Nearly every forensic matter we take falls into one of four moulds, and each has its own detailed page: a departing employee taking company data, where the copying itself must be evidenced; examinations in divorce and family matters, conducted lawfully via the solicitors on each side; disputes between partners and directors over records, access and who did what; and stolen intellectual property — source code, designs and customer lists walking out the door. Different stories, identical method: write-blocked images, a rebuilt timeline, conclusions that survive scrutiny.

The toolset: OSForensics with Passware alongside

PassMark's OSForensics carries the investigative load — deleted-file recovery, full-drive indexing and search, USN-journal timelines, and artefact harvesting across USB history, browsers, downloads, webmail traces and recent-file lists. Passware Kit Forensic opens password-protected files and BitLocker volumes where the law permits. No examination ever runs on your original media: everything proceeds from a hash-verified, write-blocked image an opposing expert can independently confirm is exact.

Standards, and one refusal we never soften

Method is the deliverable: write-blockers from the first touch, verification by MD5, SHA-1 and SHA-256, custody documented without gaps, and reports split into readable findings plus a technical appendix so tribunals can lean on them. Joint instructions agreed between solicitors are welcome. The bright line: a lawful basis must exist — hardware you own, company kit governed by company policy, or matters that arrive through solicitors and insurers. Covert inspection of someone else's private device gets refused every single time, whatever the backstory.

// the equipment we use

A professional lab, not software guesswork

The output of forensic recovery is evidence, so tooling and method carry the same weight:

OSForensics (PassMark)

The investigation platform doing the heavy lifting: deleted-file recovery, sector-by-sector indexing and search, plus artefact extraction over hundreds of formats with OCR.

Activity timeline & USN journal

File times, USN change-journal entries and system logs woven into a minute-level account of what happened and exactly when.

USB & device-history analysis

What connected, when it connected, and which files were opened around each plug-in — the backbone of a data-theft case.

Passware Kit Forensic

Where the law allows, locked files and BitLocker volumes standing before the evidence get opened.

Write-blockers & hash verification

Originals sit behind write-blockers from first contact and are imaged to duplicates whose MD5, SHA-1 and SHA-256 hashes prove them exact.

Chain-of-custody & reporting

Custody recorded without a gap from your hands into ours, with reporting divided into readable findings and the technical appendix behind them.

// manufacturers & models

Instructions we accept

Leaver data theftWiped-laptop reconstructionUSB exfiltrationWebmail & cloud leaksDeleted-evidence recoveryIP & design theftTimeline & timestamp disputesHR & disciplinary supportInsurance investigationsSolicitor-instructed matters

What the report can establish

One rule precedes every instruction: a lawful basis must exist — hardware you own, company kit governed by company policy, or matters arriving via solicitors and insurers. Covert prying into another person's private device is declined without exception, and forensic engagements are settled up front once quoted.

// before you post it

Sending it in — the drive must be removed first

The drive needs to be removed from your computer before you send it in to us. Unsure? Phone us on 0800 689 0668, or a local PC repair shop will remove it for a small fee.

Treat the machine as an exhibit from this moment: powered off, nobody signing in, nobody 'just checking', no IT re-image — every one of those tramples recoverable evidence. Jot down the relevant names and dates, then remove and label the drive; where the complete machine has to stay intact as an exhibit, phone 0800 689 0668 and documented chain-of-custody handling gets arranged for the whole unit.

// getting your device to us

Post or courier your device — it's simple

Most customers post or courier their media to us.

Sending a drive from a computer, laptop, MacBook, iMac, CCTV / DVR or server? Please remove the internal hard drive or SSD and send us just the drive — we don't provide an internal drive-removal service. We don't recover storage soldered to a motherboard (e.g. Apple Silicon Macs and some thin laptops) — only drives that can be removed and sent to us.

  • Wrap the device in bubble wrap or a padded envelope — no need to include cables or power supplies.
  • Print and enclose the booking-in & shipping form (PDF) with your name, phone number and a brief description of what happened.
  • Send by Royal Mail Special Delivery or any tracked courier for full insurance in transit.
  • Prefer to hand it over in person? You can drop it in at reception at the address shown, Mon–Fri 9:00am–5:30pm.
// send your device to your nearest location

Oxford Data Recovery

John Eccles House, Oxford Science Park
Robert Robinson Avenue, Littlemore
Oxford, OX4 4GP

↓ Print the booking-in & shipping form (PDF)

Mark the package for the attention of Oxford Data Recovery and we'll call you as soon as we diagnose your media.

Not sure what to send? Call 0800 689 0668 first or use the free online diagnostic.

// forensic recovery questions

Common questions

Generally a great deal. Post-wipe work typically establishes the wiping tool and its run time, USB devices connected across the final weeks, files opened immediately prior, webmail and cloud activity, and a set of deleted documents carved back intact. Isolate the laptop today: no sign-ins, no IT re-image.
That's its entire design: hash-verified imaging, unbroken documented custody, disclosed method, findings separated from the technical appendix. Instructions agreed jointly between the parties' solicitors are equally workable.
Usually. Timestamps in the file system, USN change-journal entries and system logs cross-check into a defensible chronology of creation, access, modification and deletion — turning 'the file existed' into 'deleted at 21:14, two days before resignation'.
Not without a lawful basis, no — your own equipment, company machines under policy, or a matter brought through solicitors are the doors in. Where a legitimate route exists we'll walk it properly and discreetly; covert access is refused outright.
// related services

Also recovered here

Ready when you are.

Free diagnostic, fixed quote, no fix no fee — start now or call the freephone.