The laptop came back suspiciously clean, the leaver started with a rival on Monday, and the company needs to know what happened in the fortnight before the wipe. Forensic recovery is recovery that must hold up under cross-examination — delivered for Swindon and Wiltshire employers, insurers and solicitors with the documentation to match.
Free diagnostic on every forensic job. One fixed quote in writing before any work begins.
No fix, no fee all jobs except electronic and mechanical failures, chip level work, DVR and Forensic jobs. Full pricing is on the data recovery cost page.
Every forensic job starts by matching the symptoms to the fault — these twenty cover almost everything that reaches the bench.
Our most frequent instruction — and both the wipe and the behaviour before it can usually be pieced back together.
Windows logs device serials and connection times; set against file-access records, the story assembles itself.
Transfers out via private Gmail, Dropbox or WeTransfer shed traces into histories, logs and leftover fragments.
Erased documents and mailboxes recovered by carving, then presented under a defensible, hash-verified method.
Establishing when a file genuinely came into being, was read, or changed — pieced together from file-system records, journal entries and event logs.
Which confidential material moved, at what moment, and under whose account.
Company equipment examined under company policy, often on instructions agreed by both sides' solicitors.
Files and footage recovered forensically for claims, defences and proceedings.
Neutral, fully documented findings serving HR processes, insurers and tribunal hearings.
Examinations run precisely to the joint directions the parties' solicitors agree.
CCleaner, BleachBit and their kind sign their own work — revealing which tool ran, at what time, and what escaped it.
Sync artefacts from OneDrive and Google Drive map out what departed through a personal account.
$I records outlive the emptying of the bin and timestamp every deletion — tiny artefacts, outsized timeline value.
Print spools and history betray paper-based exfiltration that never troubles a USB log.
Handsets stay outside our remit; the phone backups and sync folders sitting on a PC are firmly inside it.
Internal metadata, revision history and journal entries betray a file dressed up as older than it is.
Freelancers and subcontractors copying drawings on the last day leave the same USB and cloud traces as staff.
Mass deletions from group mailboxes are timed, attributed to an account, and recovered where retention allows.
WhatsApp Desktop, Teams and Slack leave local caches that survive the apps — often the candid record a dispute needs.
VPN logs, event records and file access prove whether an ex-employee's credentials kept working — and what they touched.
The pattern rarely varies: during the notice period, company files migrate to a USB stick, a private inbox or a cloud share; a wiping tool or factory reset then cleans the machine before hand-back. It looks empty. It isn't. The wipe leaves its own evidence — which tool ran and to the minute when, which USB serial numbers appeared in the final weeks, which documents were opened just before each connection, what left through webmail, and which deleted files can still be carved back whole. It all lands in a readable report, technical workings attached.
Nearly every forensic matter we take falls into one of four moulds, and each has its own detailed page: a departing employee taking company data, where the copying itself must be evidenced; examinations in divorce and family matters, conducted lawfully via the solicitors on each side; disputes between partners and directors over records, access and who did what; and stolen intellectual property — source code, designs and customer lists walking out the door. Different stories, identical method: write-blocked images, a rebuilt timeline, conclusions that survive scrutiny.
PassMark's OSForensics carries the investigative load — deleted-file recovery, full-drive indexing and search, USN-journal timelines, and artefact harvesting across USB history, browsers, downloads, webmail traces and recent-file lists. Passware Kit Forensic opens password-protected files and BitLocker volumes where the law permits. No examination ever runs on your original media: everything proceeds from a hash-verified, write-blocked image an opposing expert can independently confirm is exact.
Method is the deliverable: write-blockers from the first touch, verification by MD5, SHA-1 and SHA-256, custody documented without gaps, and reports split into readable findings plus a technical appendix so tribunals can lean on them. Joint instructions agreed between solicitors are welcome. The bright line: a lawful basis must exist — hardware you own, company kit governed by company policy, or matters that arrive through solicitors and insurers. Covert inspection of someone else's private device gets refused every single time, whatever the backstory.
The output of forensic recovery is evidence, so tooling and method carry the same weight:
The investigation platform doing the heavy lifting: deleted-file recovery, sector-by-sector indexing and search, plus artefact extraction over hundreds of formats with OCR.
File times, USN change-journal entries and system logs woven into a minute-level account of what happened and exactly when.
What connected, when it connected, and which files were opened around each plug-in — the backbone of a data-theft case.
Where the law allows, locked files and BitLocker volumes standing before the evidence get opened.
Originals sit behind write-blockers from first contact and are imaged to duplicates whose MD5, SHA-1 and SHA-256 hashes prove them exact.
Custody recorded without a gap from your hands into ours, with reporting divided into readable findings and the technical appendix behind them.
One rule precedes every instruction: a lawful basis must exist — hardware you own, company kit governed by company policy, or matters arriving via solicitors and insurers. Covert prying into another person's private device is declined without exception, and forensic engagements are settled up front once quoted.
The drive needs to be removed from your computer before you send it in to us. Unsure? Phone us on 0800 689 0668, or a local PC repair shop will remove it for a small fee.
Treat the machine as an exhibit from this moment: powered off, nobody signing in, nobody 'just checking', no IT re-image — every one of those tramples recoverable evidence. Jot down the relevant names and dates, then remove and label the drive; where the complete machine has to stay intact as an exhibit, phone 0800 689 0668 and documented chain-of-custody handling gets arranged for the whole unit.
Most customers post or courier their media to us.
Sending a drive from a computer, laptop, MacBook, iMac, CCTV / DVR or server? Please remove the internal hard drive or SSD and send us just the drive — we don't provide an internal drive-removal service. We don't recover storage soldered to a motherboard (e.g. Apple Silicon Macs and some thin laptops) — only drives that can be removed and sent to us.
↓ Print the booking-in & shipping form (PDF)
Mark the package for the attention of Oxford Data Recovery and we'll call you as soon as we diagnose your media.
Not sure what to send? Call 0800 689 0668 first or use the free online diagnostic.
Free diagnostic, fixed quote, no fix no fee — start now or call the freephone.