There is a single window in which a returned laptop is worth imaging, and it closes when the machine is handed to the next starter. Taken inside that window — behind a write-blocker, into E01 files, checked on SHA-256 — the capture keeps answering questions for years. Left until later, it answers fewer of them with every fortnight that passes. For HR and IT teams on the Bracknell business parks, along the M4 towards Slough and across the London boroughs, the sentence to remember is that the questions will keep and the evidence will not.
◇ Footing first, bench afterwards. An investigation with its full written report is £800 + VAT; a verified image with deleted-file extraction and no report written is £400 + VAT, the same point as a recorder disk. The diagnostic is free and the scope goes in writing first. No fix, no fee all jobs except electronic and mechanical failures, chip level work, DVR and Forensic jobs. Ordinary recovery bands are published on the data recovery cost page.
One of these on its own is enough to justify capturing a machine rather than wiping it.
The sums only point one way. An image taken now costs a small fraction of what the same evidence is worth once there is something to spend it on, and the hardware goes straight back into circulation afterwards because the evidence has stopped depending on it. Skip that step, hand the laptop to a new starter, and their work settles over the previous user's traces a day at a time. Businesses that image every leaver's machine as a matter of routine never find themselves explaining a gap to a tribunal. Where you can, unbolt the drive and send that alone rather than the whole computer. The exception with no way round it is storage soldered flat to the mainboard, which is how Apple Silicon machines and a number of ultrabooks are built; if the storage cannot come out, there is no parcel to make up.
Considerably more than the documents. Browsing history, cache and cookies reconstruct research, uploads and the accounts somebody signed into. Drafts and autosaved copies nobody consciously kept sit among the temporary files. Fragments of memory — a document that was open, a chat window, occasionally a credential — persist in the page file and the hibernation file. Teams and Slack keep local caches that return conversations deleted from the applications themselves. Prefetch entries record which programs were run, how often and when. Connection and VPN records put the machine on a particular network at a particular hour. An afternoon of rebuilding disposes of every one of those. A capture keeps them for as long as you need them.
Encryption rewards moving early and punishes waiting. A BitLocker or FileVault device should be imaged while the recovery key is still in escrow and the password is still known — before the leaver's account is closed, the directory is tidied, or a rebuild clears the TPM. For Windows estates the key is usually still held in Entra ID, Intune or the Microsoft account tied to the machine, and for Macs in the recovery key held by the MDM or by the user. On a live, unlocked Windows volume there is a second route: a shadow copy taken from the running system, which sidesteps the encryption question entirely because the volume is already open while you hold it. The honest limit is blunt. Full-disk encryption on a powered-off machine, with no key anywhere and no escrow, is not something anybody opens.
A claim of wiping gets tested rather than accepted. Erase utilities and boot tools leave their own evidence: boot records, tool signatures, the repeating pattern an overwrite writes across the surface, and timing that can be set against everything else that happened that week. Interrupted and misconfigured runs are frequent and leave whole regions readable, while a drive-level secure erase can be read against the device's own logs. If the wipe genuinely completed, the report says so and dates it — deliberately erasing a machine as proceedings come into view is a finding in its own right, and often a more useful one than the files would have been.
Verification and the custody file are covered at the forensic recovery hub. Reading deletion evidence off a copy is deleted-file forensics, and the obligation to preserve is legal hold and chain of custody. A locked volume with nobody in dispute is an ordinary job instead — see BitLocker recovery and the bands on the prices page.
Acquired once, verified once, and waiting for whatever the dispute eventually asks of it.
The complete disk, in a format any examiner can mount and check for themselves.
SHA-256 showing the image and every working copy stand exactly as acquired.
History, cache and cookies, reconstructing research, uploads and sign-ins.
Page file and hibernation contents: open documents, chat, sometimes a credential.
Teams and Slack stores held locally, including conversations since deleted.
VPN and connection records tying the machine to a network at a stated hour.
Start with the part people are least often told: a forensic examination sits outside no fix, no fee. That guarantee belongs to logical recovery work, and the stated exclusions are electronic and mechanical failures, chip-level work, DVR jobs and forensic jobs. An examination is bench time spent answering a question, so it is charged whether the answer helps you or not. What it does have is two published figures, which is two more than most laboratories will put in front of you. An examination that ends in a full written report is £800 + VAT. An examination that stops at the evidence itself — a verified binary image with the deleted material extracted out of it, handed over for somebody else to interpret — is £400 + VAT. That second figure is the same point on the list as a recorder disk or a BitLocker volume, so it adds nothing new to the five bands the rest of the site publishes.
The examination and the full written report that comes out of it, produced so an expert acting against you can follow every step and test it.
The verified binary image with deleted files extracted from it, and no report written. The same figure a recorder disk or an encrypted volume carries, not an extra band.
Both figures assume one machine and one question put to it. Nine laptops, a file server and a tenancy export is a larger exercise, so anything spanning several devices is measured after the free diagnostic and written down before you agree to it. Diagnosis still costs nothing and still closes 2 working days after the device is booked in, and the fee is settled before an examiner opens the image rather than after. Encrypted volumes are treated the same way, so BitLocker and FileVault jobs also sit outside the guarantee. Everything that is not forensic keeps its published band on the prices page.
Capture is carried out on company-owned equipment, on hardware you own yourself, or on written instruction from a solicitor. Three routes reach this bench and there has never been a fourth. Equipment the business itself bought and issued. A written instruction from a solicitor, an insurer or the court. Or a device that genuinely belongs to the person asking, which in a family matter means one owned outright or owned jointly. Nothing is broken into here. We do not work out somebody else's password, we do not put monitoring software on a device the client does not own, and live traffic is never intercepted — interception belongs to the bodies named in the Investigatory Powers Act 2016 and to nobody else. Where a client has no lawful right to look inside a device, instructing us does not create one. Handsets and tablets fall outside the practice altogether.
Ring 0800 689 0668 with two facts to hand: how many machines you are talking about, and whether any of them are encrypted. The capture then gets scoped in writing before a single item moves. No part of this network collects and Bracknell has no counter, so drives reach Guildford by tracked, insured post or over the counter there in office hours, and custody is recorded at booking-in.
Is the storage still bolted into a machine — laptop, tower, iMac, MacBook, rack server, a DVR under the till? Free it first and send the bare unit. Stripping hardware is not something this lab does, though it is ten minutes' work for any repair shop on your high street. There is a single case with no way round it: memory chips soldered flat onto the mainboard, which is how Apple Silicon machines and certain ultrabooks are built. Where the storage cannot be unbolted, there is no parcel to make up.
↓ Print the shipping & booking-in form (PDF)
The name on the parcel wants to be Guildford Data Recovery. Driving it over from Bracknell is roughly forty minutes on the A322 then the A3; posting it costs you a stamp and a day. Either way, a message goes out to you as soon as it is logged onto the system, and two working days later the diagnostic is finished.
Unsure whether something should go in the box? Ring 0800 689 0668 while the lid is still open, or work through the free online diagnostic and let it tell you.
Everything the machine still knows fits inside one capture — ring the freephone while it is still on the shelf.