Home / Encrypted Drive

Encrypted Drive Data Recovery

Getting data off a drive that is encrypted and failing at the same time is not the same job as decrypting one, and treating it as though it were is how these cases get lost. The drive is stabilised, copied and shelved. Everything after that happens on the copy, with the key you supply.

Bring the key and the price is published. BitLocker with the key supplied is £400 + VAT and any single drive, SSD or NVMe is £300 + VAT, fixed in writing once the free diagnostic closes.

// locked, and breaking at the same time

The key is rarely the problem. The drive is

Unlocking a healthy encrypted drive is a two minute job you can do at your own desk. Every position below is the other case, where the volume is both locked and physically failing, and the order those two are dealt with decides whether anything comes back at all.

BitLocker on a drive with sectors going soft

The recovery key is to hand, the drive accepts it, and the volume still stalls partway through opening. Slow and unreadable sectors are usually the reason. Every fresh attempt to unlock the original reads across the whole of it again, which is exactly the sustained load a drive in that condition has no capacity left for.

A recovery key that is correct and gets refused

BitLocker stores its own metadata in three separate places on the volume, and a perfectly valid key will still be rejected when the block it has to be checked against is damaged. Putting that right is repair work on the metadata rather than an attack on the cipher, and it is done on an image, never on the drive itself.

FileVault on a Mac that will not start up

Apple has encrypted by default for years and most owners have not seen the recovery key since the afternoon they set the machine up. Where the SSD unbolts, it can be imaged and the copy opened with the password or the key. Where the storage is soldered to the logic board, as on every Apple Silicon machine, there is nothing to unbolt and no honest way round it.

A VeraCrypt volume with a damaged header

The header sits at the very start of the volume and holds the master key in encrypted form. Damage the first few sectors and a correct password stops opening anything at all. A backup header is written at the end of the volume for precisely this situation, and a great many of these jobs come down to whether one of the two survived.

A hardware encrypted enclosure with a dead bridge

Encrypting external drives keep the key inside the USB bridge board rather than on the disk. Pull the bare disk out and plug it straight into a computer, which is what the internet will tell you to do, and all you have is ciphertext with the key nowhere near it. The bridge has to travel with the disk.

A self-encrypting drive whose controller has died

Most SSDs encrypt everything internally whether or not anybody ever switched a password on, and the key lives inside the controller. When that controller fails the key goes with it, and no amount of clean bench work brings either back. It is the one situation on this page where the honest answer is that there is nothing worth attempting.

// the order this has to happen in

Image first, unlock second, without exception

Unlocking a volume is not a light operation. The moment a key is accepted the operating system starts reading structures scattered across the whole device, and then whatever software you point at it reads the rest. On a drive with weak heads or a growing count of pending sectors, that unstructured hammering is the fastest way to turn a difficult job into an impossible one, and it can happen inside a couple of minutes.

So the sequence here never changes. Any physical fault is dealt with on the clean bench first. The drive then goes onto a hardware imager which reads it in a controlled order, at a controlled speed, retrying weak regions deliberately and skipping the ones that will not give, and the result is a file. That file can be opened, closed, reopened and experimented on as many times as the job needs without a single further read of your drive. Where a decryption pass fails halfway, it is repeated against the image. Your original goes on a shelf and stays there.

Why a partial image of an encrypted volume is usually worth nothing

On a plain volume, a partial image is a partial success and a perfectly useful one. Files are stored as runs of sectors, so the runs that read come back whole and openable. The master file table can often be rebuilt from its own mirror. Where the metadata is beyond help entirely, raw data still carries recognisable headers, so photographs, documents and databases can be carved straight out of the image by shape. Ninety per cent of a plain drive is, roughly speaking, ninety per cent of your files.

Encryption removes every one of those fallbacks. Nothing in the image is a file until it has been through the cipher, and the information saying which sectors make up which file is itself inside the encrypted layer. Worse, the key material is concentrated: a few kilobytes of header, or a volume master key block in a fixed position. Lose those particular sectors and the other ninety-nine per cent is arithmetic noise with no way in. That is why imaging strategy on an encrypted drive is inverted. The key regions and the metadata blocks are read first, slowly, with the retry count wound right up, and only then does the bulk pass begin.

Berkshire and Surrey run on encrypted laptops

Full-disk encryption stopped being an enterprise nicety some years ago and is now simply how corporate machines are issued. Almost every laptop that leaves an office along the A329M, or comes out of the technology and data-centre corridor towards Slough and Reading, is encrypted before it reaches the person using it, and the same is true of the ones carried home to Wokingham, Crowthorne and Windsor or onto the London train each morning. When one of those drives starts to fail, the encryption is not the fault. It is the thing that makes an ordinary fault expensive to get wrong.

// what we need from you, and what we will not do

No key, no job, and no exceptions

This laboratory does not break encryption. Not on your own drive, not with a letter from your solicitor, not for a company that has lost the keys to its own estate. It is not a policy that gets bent for a good story, because the capability does not exist here or anywhere else, and pretending otherwise would only cost you a diagnostic and a fortnight. If the key material is genuinely gone, the honest answer is given on day one and nobody is charged for it.

What counts as a key is broader than most people assume, and it is worth checking every one of these before concluding it is lost. For BitLocker: the 48-digit recovery key, a Microsoft account that the machine was signed into, an Entra ID or Azure AD tenancy, Active Directory where the machine was domain-joined, a printed sheet in a drawer, or a USB startup key. For FileVault: the login password of any enabled user, the recovery key, or an institutional recovery key from a managed Mac. For VeraCrypt or BitLocker To Go: the password, plus any keyfiles that were used, which people forget are part of it. The BitLocker recovery key page walks through where each of those hides.

Prices, and which side of the guarantee this lands on

A BitLocker volume with the key supplied is £400 + VAT. Any single hard drive, SSD or NVMe module is £300 + VAT, cards and pen drives are £250 + VAT, and arrays, NAS boxes and servers open at £500 + VAT. Every figure is fixed in writing after the free diagnostic, which closes 2 working days after the drive reaches the bench and never sooner, and from the moment you approve the figure the fastest a finished recovery runs is 2-4 working days.

Where the fault turns out to be purely logical, the job keeps its guarantee: no fix, no fee all jobs except electronic and mechanical failures, chip level work, DVR and Forensic jobs. Where the drive needs the clean bench, a donor head stack, a board or chip-level work, half the quoted figure is settled upfront before anything invasive begins, with the balance falling due when your data goes back to you. Firmware work stays inside the guarantee; board repair does not. All of it is spelled out on the quote you read before agreeing to anything, and the wider bands are on data recovery cost. Send the drive alone rather than the laptop, tracked, to the Guildford address below.

// related pages

Nearby on this site

// questions about locked and failing drives

Common questions

No. Modern full-disk encryption has no back door and no shortcut, and any firm suggesting it has one is either mistaken or misleading you. Work through every place the key could be first, because a Microsoft account, a company Entra tenancy or an Active Directory record turns up the answer far more often than people expect.
The clicking, always. A drive making that noise has a mechanical fault and needs the clean bench and a donor head stack before anything else happens. Only once a stable image exists does the key come into it, and the unlocking is then done against the copy so the drive is never read again.
A BitLocker volume with the key supplied is £400 + VAT, and any single drive, SSD or NVMe module is £300 + VAT. A logical job keeps no fix, no fee. Where the drive is physically damaged, half the quoted figure is settled before the invasive stage begins, and every term appears on the written quote first.
Sometimes, and it depends entirely on which parts failed. Where the header and key blocks read cleanly, an image with holes in it can still be unlocked and the intact regions carved out file by file. Where the damage sits on the key material itself, a nearly complete image is unfortunately of no use to anybody, which is why those sectors are read first.
If the SSD unbolts from the logic board, yes, and the password or the FileVault recovery key opens the image. If the machine is an Apple Silicon model, the storage is soldered down and tied to that particular board, so there is nothing that can be posted and nothing that can be read elsewhere. Ring 0800 689 0668 with the model and year and you will get a straight answer in a minute.

Encrypted and failing? Copy it before you open it.

Find the key, leave the drive alone, and let the unlocking happen against an image rather than against failing hardware.

// getting the media to the bench

Booking a device in — what actually has to happen

Almost every job on this bench arrived as a parcel. Tracked, insured post is the gentlest way to move storage that is already in trouble, and a box handed in around Bracknell, Wokingham or Ascot is normally on the Guildford bench the next working day.

Is the storage still bolted into a machine — laptop, tower, iMac, MacBook, rack server, a DVR under the till? Free it first and send the bare unit. Stripping hardware is not something this lab does, though it is ten minutes' work for any repair shop on your high street. There is a single case with no way round it: memory chips soldered flat onto the mainboard, which is how Apple Silicon machines and certain ultrabooks are built. Where the storage cannot be unbolted, there is no parcel to make up.

  • Pick packaging that holds its shape — a rigid carton or a heavy padded mailer — and pack round the unit so it cannot shift in transit. Leave the caddy, the mains adaptor and the leads at home; none of them are wanted at this end.
  • Print the shipping and booking-in form (PDF), put your name and mobile on it along with a sentence describing how the fault started, and slip it in alongside the media.
  • Send it Special Delivery through the Post Office and it travels tracked and covered. A courier account of your own works just as well. The only thing that matters is that somebody signs for it at this end.
  • If you would sooner deliver it by hand, the Guildford reception on the address card takes devices over the counter, Mon–Fri 9:00am–5:30pm. Neither a Bracknell shopfront nor a pickup van exists — those are the two things we cannot offer.
// write this on the label

Guildford Data Recovery

Building 2, Ground Floor
Guildford Business Park
Guildford, GU2 8XH

↓ Print the shipping & booking-in form (PDF)

The name on the parcel wants to be Guildford Data Recovery. Driving it over from Bracknell is roughly forty minutes on the A322 then the A3; posting it costs you a stamp and a day. Either way, a message goes out to you as soon as it is logged onto the system, and two working days later the diagnostic is finished.

Unsure whether something should go in the box? Ring 0800 689 0668 while the lid is still open, or work through the free online diagnostic and let it tell you.