The unit humming quietly on a shelf turns out to have been holding the company accounts and eight years of family photographs in the same chassis, which is how most owners learn it had never been a backup at all. Then a bay lights up red, or a rebuild gives up partway, or one morning the fans are not running. Synology, QNAP, Buffalo, Netgear and WD My Cloud volumes get reassembled here from the member disks and nothing else. Because it all travels by post, the NAS drive recovery London businesses need runs on the same bench as a four-bay box out of a Wokingham office, and a parcel from Croydon or Richmond is treated no differently. Send us the disks. Keep the enclosure.
Anything sent in for NAS recovery is diagnosed free. The written figure that follows is settled before a screwdriver leaves the drawer: from £500 + VAT for a NAS box, rising with the member count.
No fix, no fee covers logical recoveries. Outside it sit electronic and mechanical failures, chip-level work, DVR jobs and forensic jobs, and physical work is 50% up front. Every band is published on the data recovery cost page.
Reading a symptom back to the failure underneath it is where the work genuinely starts, and this set of thirty accounts for all but a handful of the parcels that reach the Guildford bench. If yours is not on the list, it will still be recognised — describe it on the phone and you will get a straight answer about the odds before you post anything.
The single most useful thing to understand before anything else. A four-bay box does not contain four copies of your files. It breaks each file into stripes, spreads those stripes across every member, and calculates parity so that one missing disk can be worked out from the others. Lose track of the arrangement and every disk in the box becomes meaningless on its own. That is why the disks are recovered as a set here and never one at a time.
Redundancy protects you from one disk dying. It does nothing about a deletion, a bad firmware update, a ransomware key, a flood or a theft, because all of those reach every member at once. Owners learn this at the worst possible moment, which is usually the same phone call. This lab sells no backup service and has nothing to subscribe to, so take the advice as it is meant.
A single failed member is survivable and rarely dramatic in itself. The danger is entirely in what happens next, because the standard advice is to replace the disk and rebuild, and a rebuild is the heaviest load the remaining disks will ever be asked to carry.
Rebuilding reads every surviving member end to end for hours without a pause. Disks bought as a batch, installed on the same day and worn identically since, tend to fail at similar points, and the second one gives out midway through. Nothing here ever asks that of your hardware: each disk is imaged individually first and the array is rebuilt from copies.
Alarming vocabulary, usually modest damage. In most of these cases what has failed is the housekeeping, while the data underneath sits exactly where it was written. Copy the members, reassemble the structure in software, extract the shares from the reassembly, and leave the original disks untouched.
Boot a unit that has lost its configuration and it frequently presents the initial setup screen, which looks like the obvious way forward. Accepting it writes a fresh array over the old one. If a NAS is asking you to create a new volume, switch it off at that screen and go no further.
DSM and QTS updates fail on units that were short of space or halfway through something else, and the result is an enclosure that no longer boots while the disks inside it are entirely intact. The array does not live in the enclosure. It lives on the members, and it is rebuilt from them.
A disk that dropped out three months ago and went unnoticed holds an old version of the array metadata. Put it back in alongside current members and the box has to choose which account to believe, and it sometimes chooses wrongly. Sequence numbers on the copies settle that question without any risk attached.
Power supplies and mainboards fail far more often than four disks do. In a Synology or QNAP the layout is written on the members themselves, so there is no need to hunt down an identical chassis on an auction site. Number the caddies, send the disks, keep the shell.
Underneath the badge, nearly every NAS runs Linux. Synology writes ext4 or Btrfs, QNAP writes ext4 on top of thin-provisioned volumes, Buffalo uses XFS or older ext3 and ext4, and Netgear moved to Btrfs years ago. Windows recognises none of those, which is why plugging a NAS disk into a PC produces a cheerful offer to format it. Declining that offer is the most important thing you will do all week.
A DiskStation is rarely just a RAID set. SHR sits on Linux software RAID, an LVM volume group sits on that, and ext4 or Btrfs sits on top again. Any one of those three layers can be the damaged one while the other two are perfectly sound. They are unpicked in that order from the images, which is why an SHR volume that no dashboard will mount usually comes back in full.
QTS builds a storage pool and then carves thin-provisioned volumes out of it, which means the LVM thin metadata has to be consistent before a single file can be read. When that metadata is damaged the volume mounts read-only or does not appear at all, while the data behind it is untouched. The pool is reconstructed from copies of the members and the volumes are extracted from it.
Deleting a share removes the directory entries and leaves the blocks in place until something claims them. Snapshots complicate this in your favour, because a Btrfs snapshot taken before the deletion often still references the original data. Stop writing to the unit and both routes stay open.
A mapped drive is exactly as reachable as a local one, which is how a single infected desktop encrypts everything on the box. Snapshots are checked first, then remnants and unallocated space. Work happens on an isolated bench with no network attached, and it is priced as ordinary media rather than as anything exotic: from £500 + VAT for an array.
The caddies came out during a house move or an office clear-out and went back in whatever order they happened to be lying. Member order matters, and guessing at it and then powering up can trigger a rebuild in the wrong direction. Once the disks are imaged, the order is derived from the metadata rather than from what anybody can recall.
Single-bay WD units brick themselves during firmware updates with some regularity. Inside is one entirely ordinary drive carrying a Linux file system, which is precisely why Windows offers to format it. Split the case, send the bare disk, and if the shell will not part, ring 0800 689 0668 before you start levering.
Buffalo units arrive here in numbers well ahead of what the brand sells. There is no proprietary component that has to be present before the data can be read and no lock tying the disks to the box, only XFS or ext formatting that Windows cannot see. Image the members, derive the geometry from the images, mount the volume in software, and the shares behave like ordinary folders again.
Four identical disks from one order, installed on one afternoon, spun for the same number of hours in the same warm cupboard. They do not fail randomly, they fail in a cluster, and the first one is a warning rather than an isolated event. Image the set when the first light turns red.
SMR disks such as the WD20EFAX write slowly when they are asked to write continuously, which is the precise definition of a rebuild. The controller waits, decides the disk is unresponsive and drops it from the array, and now two members are missing instead of one. The disks are usually fine. The rebuild was the problem.
Adding a disk to an existing volume reshapes the entire array, moving data across every member for a day or more. Interrupt that with a power cut and part of the set is in the new geometry and part is in the old. The boundary is plainly visible once the images are taken, and extraction is planned around it.
A NAS pushed into an airing cupboard or under a desk in a warm office runs every disk ten degrees hotter than it should for years at a stretch. Nothing fails on a particular day. Everything simply arrives at the end of its life early, and usually together.
A sector that was written correctly and quietly degraded since is invisible until something reads it. A scrub or a rebuild is what reads it, which is why long-dormant damage always seems to appear on the worst possible day. Imaging hardware reads round it patiently instead of giving up in seconds.
Synology and QNAP both mirror their operating system across a small partition on every disk. Damage that and the unit will not boot, while the data volume beside it is completely unaffected. It is a common and thoroughly recoverable state, and it looks far worse from the front panel than it is.
An iSCSI LUN is a file living inside the NAS volume, with its own file system sealed inside that file. Two structures have to be repaired in the right order, the outer one before the inner one. Get that order wrong and you repair nothing.
Btrfs checksums whatever it is given, so a NAS with failing memory writes corrupted blocks along with checksums that certify them as correct. The volume reports itself as healthy while individual files quietly come apart. Where that is suspected, the memory is the first thing to test, not the disks.
A read-only cache can be removed without consequence. A read-write cache is part of the volume, and when the cache device dies it takes the writes that were sitting in it. Send the cache SSD along with the disks, because whatever it was holding is part of the reconstruction.
Synology disks do not mount in a QNAP and a QNAP pool means nothing to a Netgear unit. Trying it is not usually destructive, but the migration wizard that offers to prepare the disks certainly is. If a set has already been moved around, say so on the call and it changes nothing about how they are imaged.
Btrfs allocates its metadata in chunks and needs free space to record any change at all, including deletions. A volume run to capacity can reach a state where nothing can be removed because removing something requires a write. That is repaired from images rather than by fighting the unit at the command line.
Synology encrypted folders are opened with a passphrase or a key file, and without either there is no way in, here or anywhere. If the key file was stored on the volume that failed, that is a genuine dead end and you will be told so before anything is charged.
Cloud Sync, Hyper Backup mirrors and desktop sync agents all faithfully copy a deletion to the other end within minutes. Somebody clears a folder on a laptop and the NAS obediently clears it too. That is sync working correctly, and it is the clearest illustration there is of why a mirror is not a backup.
What a NAS does with a file is break it into stripes and distribute those stripes over the installed disks, using either a standard RAID level or whatever the manufacturer decided to name its own arrangement. Synology calls its version SHR. Drobo used to sell BeyondRAID. Underneath the branding the margin for error is considerably narrower than the marketing implies. A single disk dropping out is survivable and rarely dramatic. The danger begins immediately afterwards, because a rebuild demands that every remaining member be read end to end for hours without a break, and that sustained load is exactly what finishes off a second disk of identical age from the same delivery. Nothing here ever asks that of your hardware. Each drive is copied in its entirety first. Stripe size, member order and the rotation of parity are then worked out from the copies rather than guessed at. The volume is stood up again in software, and a file is only extracted once that is done. At no point is anything written back to the disks you sent.
Do not press rebuild. Re-initialising sits there on screen looking like the natural next step, and it is the one action available that can end the job for good. The right sequence is different. Shut the unit down cleanly, pull the caddies one at a time, and mark the bay number onto each disk as it comes out, because that ordering matters enormously to whoever rebuilds the set later. Numbered drives go in the parcel, the empty chassis stays with you. A single-bay unit like a My Cloud only needs its case splitting so the bare drive can be sent. Where a case refuses to open, ring before you start applying force. Snapped clips with a cracked disk behind them are something this bench sees regularly.
Buffalo hardware arrives here in numbers well ahead of the company's share of the market. LinkStation 210 and 220 units out of spare bedrooms and two-person practices, TeraStation units out of firms that needed four bays in a rack-mountable shape. The good news is identical for both. What Buffalo installs is standard SATA drives, with no proprietary component anywhere in the chassis that has to be present before the data can be read, and no lock tying the disks to the box they came out of. The confusion is entirely about formatting. Volumes are written as XFS, or ext3 and ext4 on the older models, and Windows recognises none of those, so connecting a LinkStation disk straight to a PC produces a report that the drive is empty together with a friendly offer to format it. Declining that offer is the single most important thing you will do. Here, each member is imaged from beginning to end, the RAID geometry is derived from the images rather than from a controller that has lost its bearings, and the XFS volume is then mounted in software, at which point the shares behave like ordinary folders. One scenario repeats more than any other: a rebuild that nobody interrupted. A drive is flagged, a replacement goes into the empty bay, the rebuild then grinds through every surviving member for several hours, and a second drive of the same vintage from the same batch gives out midway. The array is now down and the box has run out of suggestions. Data in that state comes back off the member disks, and it comes back a great deal more reliably if nobody has since tried a third rebuild. Power it off, number the caddies, send the drives, hold on to the shell. Buffalo sits on the same pricing as the rest of the array bench: from £500 + VAT, going up as the disk count does.
Array work is a different discipline to single-drive work, and it needs the bench set up for it:
Every member is copied in parallel before a single question about layout is asked. Once that is finished, the disks you sent take no further part in the recovery.
Member order, stripe size, parity rotation and data offset are all derived from the images, and tested against them repeatedly until the file system parses cleanly rather than nearly.
A disk the NAS declared dead will frequently image on hardware willing to wait out a slow sector. Where a member has a mechanical fault, heads are exchanged in filtered air first and the image is taken afterwards.
The array is stood up in software over the images. Nothing is ever written back to the original disks, so a theory that turns out to be wrong costs an afternoon rather than the data.
mdadm superblocks, LVM volume groups and thin pools, SHR, X-RAID, and ext4, Btrfs and XFS on top of any of them. The stack is unpicked layer by layer in the order it was built.
My Cloud and similar enclosures are opened without damaging the drive inside. If a case will not part, it comes here intact rather than being forced at the kitchen table.
Two-bay DiskStations and the QNAP TS-x53 line are what actually sit humming in stockrooms, studios and back offices around Bracknell, Wokingham and the units off Western Road, and they lead the rebuild ledger accordingly. Drobo closing its doors left BeyondRAID owners with laboratory work as the only remaining route, which is unfortunate and true. Owners ask about bay order more than anything else, and the reassuring answer is that every disk carries its own place in the set inside its own metadata, so a pile of unlabelled drives is still a recoverable array. Numbering the caddies with a marker before they come out simply makes reconstruction faster and removes one opportunity to go wrong. Work on arrays, NAS boxes and servers opens at £500 + VAT and increases with the number of members, and the free diagnostic closes 2 working days after the drives are booked in. Whatever badge is on the front, the sequence never changes: shut it down, number the disks, send the disks, keep the shell.
More DiskStations pass through here than any other badge, and the reason is simply that Synology sells more of them. SHR is the layer that confuses people: it is Linux software RAID underneath, with an LVM volume group over the top and ext4 or Btrfs above that, which is a sensible design and three separate things that can break. A crashed volume in DSM is usually damage to one of those layers rather than to your files, and the shares are still sitting on the members waiting to be read. The work runs the same way every time. Each disk is imaged in full, the RAID is reassembled from the copies, the volume group is reconstructed, and the file system is mounted in software so that folders can be browsed and extracted normally. Btrfs snapshots are worth mentioning on the call, because a snapshot taken before a deletion or before ransomware arrived is frequently the shortest route back. Pricing starts at £500 + VAT and climbs with the disk count. Do not rebuild, do not initialise, and do not accept the setup wizard.
QNAP builds a storage pool from the disks and then carves thin-provisioned volumes out of that pool, so there is an extra layer of bookkeeping between the RAID and your files compared with a simpler box. When the LVM thin metadata is damaged, QTS mounts the volume read-only, or reports it as missing entirely, while every byte of data sits untouched behind it. That is a recoverable position and a common one. Both the pool and the volumes are reconstructed from images of the members, and ext4 is then mounted over the result. Two other patterns turn up regularly: a QTS update that failed partway and left a unit which will not boot, and an SSD cache that died and took recent writes with it. In the first case the enclosure is irrelevant, because everything needed is on the disks. In the second, send the cache device along with the array. Number the caddies, keep the chassis, and expect from £500 + VAT depending on how many disks are involved.
These two arrive in numbers well ahead of their market share, and both are more straightforward than owners fear. Buffalo fits ordinary SATA disks with no proprietary component in the chassis and no lock tying the drives to the box, formatting them as XFS or, on older units, ext3 and ext4. Netgear ReadyNAS uses X-RAID over Btrfs, which brings its own metadata to repair but keeps the data itself readable. In both cases connecting a member to a Windows PC produces a report that the disk is empty together with a friendly offer to format it, and declining that offer is the single most important step. The scenario that repeats more than any other is a rebuild nobody interrupted: a disk is flagged, a replacement goes into the empty bay, the rebuild grinds through every surviving member for hours, and a second drive of the same age from the same batch gives out midway. Data in that state comes back off the members, and it comes back a great deal more reliably if nobody has tried a third rebuild since. Power it off, number the caddies, send the drives, keep the shell.
Shut the unit down properly first, then take the disks out one bay at a time and write the bay number onto each drive in marker pen as it comes free. That numbering pays for itself several times over during reconstruction. The disks by themselves are enough in most cases. This is also one of the few products where the whole box can be sent instead, if opening it worries you, and a sealed single-bay unit generally has to travel intact anyway. Send it tracked and insured to Guildford Data Recovery, Building 2, Ground Floor, Guildford Business Park, Guildford GU2 8XH, about forty minutes from Bracknell on the A322 and the A3, or hand it in at reception between 9:00am and 5:30pm, Mon–Fri. Nothing is collected from anywhere, so the journey has to be arranged at your end.
Nearly every job here arrived as a parcel. Tracked, insured post is the calmest way to move a drive that is already struggling, and something handed over in Berkshire, Surrey or London is normally on the Guildford bench the next working day.
Is the storage still bolted into a machine — laptop, tower, iMac, MacBook, rack server, a DVR under the till? Free it first and send the bare unit. Stripping hardware is not something this lab does, though it is ten minutes' work for any repair shop on your high street. There is a single case with no way round it: memory chips soldered flat onto the mainboard, which is how Apple Silicon machines and certain ultrabooks are built. Where the storage cannot be unbolted, there is no parcel to make up.
↓ Print the shipping & booking-in form (PDF)
The name on the parcel wants to be Guildford Data Recovery. Driving it over from Bracknell is roughly forty minutes on the A322 then the A3; posting it costs you a stamp and a day. Either way, a message goes out to you as soon as it is logged onto the system, and two working days later the diagnostic is finished.
Unsure whether something should go in the box? Ring 0800 689 0668 while the lid is still open, or work through the free online diagnostic and let it tell you.
Snapshots missed and guests left switched off are where estates come back
The routes home that do not involve paying anybody
Three copies, two media, one off site, and where firms slip
Ten districts, no office, and no Zone 1 rent inside the figure
Nothing to pay for the diagnosis, one written figure before any work begins, and the band on this page is from £500 + VAT for a NAS box, rising with the member count.