Material going out by mailbox or cloud account gets recorded twice. Once by the machine, once by the service. Any sound investigation reads the pair. Your tenancy supplies rules, attachment history and sign-in patterns. Your device supplies browser and sync traces. Both halves get lined up into a single dated account, for the professional and legal offices around Union Street and the energy consultancies instructing them.
◇ Footing first. Bench time after. The free diagnostic opens the job, a written scope follows it, and forensic fees clear ahead of any examination. No fix, no fee all jobs except electronic and mechanical failures, chip level work, DVR and Forensic jobs. Full pricing is on the data recovery cost page.
Every one of these has an innocent explanation of its own. Put together they make a pattern worth examining.
A mailbox being used to shift material behaves in a way you can learn to recognise. Attachment sizes climb while the recipient list narrows to one private address. A rule appears and starts forwarding chosen mail with nobody watching. Searches read like hunting rather than working: client names, project codes, price lists. Access drifts into evenings and weekends. Mail platforms note every bit of that, and each item is pulled out and dated during the examination.
The device gives you the other half. Browser traces catch accounts being created, then signed into, at Dropbox, OneDrive or Google Drive from a work machine. Sync-client logs and folder layouts show which directories were set to mirror upward, and from which date. Upload residue, meaning cached pages, confirmation screens and recent-file lists, sits on the image well after someone has cleared their browsing history. A personal account appearing on work hardware during a final month is rarely there by accident.
Microsoft 365 and Google Workspace hold evidence of their own, and it frequently decides matters. Message movement, sharing and downloads land in Microsoft Purview audit logs and eDiscovery exports. Google Vault retains mail and files. SharePoint and OneDrive logs record every share and bulk download with an account and an hour against it. Dropbox keeps version history and recoverable deletions. A deleted mailbox can often be recovered out of retention or from backup, though not for ever. That is the argument for ringing early.
Findings persuade when they agree with themselves. The tenancy logs a 3.4 GB download at 22:38. Two minutes on, the same files show up inside a personal sync folder on the device. Browser history closes the loop. Service evidence and machine evidence get built into a single run, and where they disagree we flag it rather than paper over it. Everything, mailbox export and audit extract and the disk image, is hashed before any account gets suspended or any licence reclaimed.
Method underneath the whole practice sits at the forensic recovery hub. Credentials and server records continue on insider threat forensics. Employer casework is employee data theft. Holding material is legal hold and chain of custody. Figures are on the prices page.
Service records and machine traces, checked against each other and set out as one run.
What went out to private addresses, at what size, and on which dates.
Forwarding and deletion rules, their creation dates, and what they caught.
Sign-in hours and locations, with out-of-hours clusters marked up.
Personal accounts, sync folders and upload leftovers on work kit.
Share, download and export events lifted from M365 and Workspace logs.
Messages and entire mailboxes brought back from retention or backup.
Each instruction opens on the free diagnostic. Allow 2 working days from the date a device reaches this bench. Forensic casework sits outside no fix, no fee. The full forensic investigation with report is £800 + VAT, payable 100% upfront. The less expensive Forensic binary image and deleted-file extraction service, without the report, is £400 + VAT. Any Forensic work required will be payable upfront. Where a scope reaches across several accounts, or a whole tenancy, we quote in writing once the free diagnostic is done. You will find both figures repeated on the prices page, and we take nothing until a scope is agreed in writing.
Mailbox and cloud work runs on tenancies and devices the company owns, or on the written instruction of a solicitor. Three doors in, and we have never found a fourth. Kit the business itself owns. A written instruction out of a solicitor, an insurer or from the court. Or else a device that genuinely belongs to the client, which in a matrimonial matter takes in one held between the two of them. Nothing gets hacked at this bench. Live traffic is never intercepted. Where the instructing client holds no right to look inside a device, we hold none either.
Cloud material is frequently preserved by export rather than by parcel. Ring 0800 689 0668 and we will sort out which parts can be captured remotely and which must travel. We run no collection service, so anything physical comes to Edinburgh tracked and insured, or across the counter, and custody starts at the signature.
Still bolted into a laptop, desktop, MacBook, iMac, server or CCTV / DVR box? Get the hard drive or SSD out first. The bare drive travels on its own. Stripping machines down is not a job this lab takes on. Flash soldered to a motherboard, as on Apple Silicon Macs and a couple of very thin laptops, is our one flat no: if it will not unbolt, it cannot be worked on.
↓ Print the shipping & booking-in form (PDF)
Address it for the attention of Edinburgh Data Recovery. From Aberdeen that is roughly 130 miles and two and a half hours down the A90, or next working day by tracked post if you would rather not make the run. You get a call the moment it is booked onto the bench.
Not sure what belongs in the box? Ring 0800 689 0668 before you tape it shut, or work through the free online diagnostic.
Retention windows shut on their own schedule and not on yours. Ring the freephone first.