Forensic Data Recovery for Aberdeen and the North East

An ordinary recovery answers one question. Are the files back? Forensic work gets judged months afterwards, by somebody paid to find the hole in it. So we copy the device once, put the hashes on the record, and the findings are written so a sheriff can lift them off the page. Our callers are energy and engineering firms at Altens and Tullos, professional and legal offices around Union Street, processors up at Peterhead and Fraserburgh, and family businesses the length of Aberdeenshire and Moray.

Footing first. Bench time after. The free diagnostic opens the job, a written scope follows it, and forensic fees clear ahead of any examination. No fix, no fee all jobs except electronic and mechanical failures, chip level work, DVR and Forensic jobs. Full pricing is on the data recovery cost page.

The paperwork counts for more than the software

Lifting files off a dying disk is engineering, and plenty of people can do it. Forensics adds one thing on top: a written account, made while the work happens, of exactly how those files were obtained. That is the part that survives an argument. Our sequence does not vary. Drive behind a hardware write-blocker. Copy into E01 containers. SHA-256 taken across both and compared. Exhibit sealed, labelled and entered in the custody log, after which every question is put to the copy and never to the source. Findings carry a number, a date and the artefact they came out of. That is the whole gap between forensic work and a straight recovery, and it is what the fee buys.

Scotland has its own legal system and this practice works inside it. Documents are recovered by specification, and by commission and diligence where the court grants it. Actions run in the sheriff court or in the Court of Session. Employment tribunals sit to the same statutory rules across Great Britain and follow Scottish procedure north of the border. Two things are UK-wide and stay exactly as they are: the digital evidence principles ACPO wrote and the NPCC keeps, and the Computer Misuse Act 1990.

Everything here sorts under three headings. Detection and evidence recovery settles what actually happened, be that on a machine, on a memory card, or somewhere inside a cloud tenancy. Legal work and chain of custody is about holding it afterwards: preservation, hashing, storage, and a log that stays clean while somebody hostile picks over it. Insider work aims the two previous headings at a named individual over a fixed run of dates.

// group one · working out what happened

Detection and evidence recovery

Four services aimed at events. When material was destroyed and by what method. Files crossing onto sticks and cards. Departures by mailbox or cloud account. And the whole machine lifted in a single capture.

// group three · the instructions that actually arrive

Insider work

Here the subject is a person, not a box. Credentials turned to the wrong use, the paper trail a server keeps without being asked, and after that, the four instructions we receive more often than the rest put together.

// how an instruction is run

Six habits behind every page here

It makes no odds which page brought you in. Underneath, the work looks like this.

Write-blocked, no exceptions

A hardware write-blocker sits between your exhibit and this bench. Nothing done at our end can reach back to the drive you handed us.

E01 containers

Copies are written as E01. It is an open format, so the other side's examiner can check our figures and repeat the exercise.

Two hashes, then compared

SHA-256 is taken at capture and recomputed afterwards. An image that has shifted fails verification rather than slipping past.

All analysis on the copy

Indexing, artefact extraction, recovery of removed material and timeline building run in OSForensics. The exhibit stays sealed.

Passware, only with the right

Sealed archives, locked documents and encrypted volumes come open under Passware where the client owns a right to the contents. Not otherwise.

Custody logged start to finish

Seals, signatures and movements go on the record from arrival at our Edinburgh location until the exhibit is handed back.

// the price, and who we may act for

Forensic fees, and the footing underneath them

The money, stated plainly

Each instruction opens on the free diagnostic. Allow 2 working days from the date a device reaches this bench. Forensic casework sits outside no fix, no fee. The full forensic investigation with report is £800 + VAT, payable 100% upfront. The less expensive Forensic binary image and deleted-file extraction service, without the report, is £400 + VAT. Any Forensic work required will be payable upfront. CCTV / DVR, BitLocker and ransomware cases are Forensic-classed and payable upfront on the same terms. You will find both figures repeated on the prices page, and we take nothing until a scope is agreed in writing.

The footing we need

Most of this work arrives from employers, HR departments and solicitors. Private clients get taken on identical terms. Three doors in, and we have never found a fourth. Kit the business itself owns. A written instruction out of a solicitor, an insurer or from the court. Or else a device that genuinely belongs to the client, which in a matrimonial matter takes in one held between the two of them. Nothing gets hacked at this bench. Live traffic is never intercepted. Where the instructing client holds no right to look inside a device, we hold none either.

// getting your device to us

Getting it to the bench — plainly done

An exhibit is not just a parcel. Ring 0800 689 0668 before it moves and we will agree the wrapping, the paperwork and the timing between us. No collection service is offered, so it travels tracked and insured, or comes over the counter at reception at our Edinburgh location. Custody opens at the signature.

Still bolted into a laptop, desktop, MacBook, iMac, server or CCTV / DVR box? Get the hard drive or SSD out first. The bare drive travels on its own. Stripping machines down is not a job this lab takes on. Flash soldered to a motherboard, as on Apple Silicon Macs and a couple of very thin laptops, is our one flat no: if it will not unbolt, it cannot be worked on.

  • Bubble wrap, then a rigid box or padded envelope packed tight enough that nothing rattles. Keep the cables, caddies and power bricks at home.
  • Print the shipping & booking-in form (PDF). Name, mobile number, two lines on what went wrong. In the box with the drive.
  • Royal Mail Special Delivery is tracked and insured door to door. Your own courier account does the same job if you would rather use it.
  • Handing it over yourself instead? Reception takes drop-offs at the address below, Mon–Fri 9:00am–5:30pm.
// where your device is headed

Edinburgh Data Recovery

4 Redheughs Rigg
Westpoint, South Gyle
Edinburgh, EH12 9DQ

↓ Print the shipping & booking-in form (PDF)

Address it for the attention of Edinburgh Data Recovery. From Aberdeen that is roughly 130 miles and two and a half hours down the A90, or next working day by tracked post if you would rather not make the run. You get a call the moment it is booked onto the bench.

Not sure what belongs in the box? Ring 0800 689 0668 before you tape it shut, or work through the free online diagnostic.

// asked on the phone, before instructing

Before you instruct

The free diagnostic comes first. Allow 2 working days from the date the device reaches this bench. Forensic casework is outside no fix, no fee. The full forensic investigation with report is £800 + VAT, payable 100% upfront. The less expensive Forensic binary image and deleted-file extraction service, without the report, is £400 + VAT. Any Forensic work required will be payable upfront. CCTV / DVR, BitLocker and ransomware cases are Forensic-classed and payable upfront on the same terms. The scope is put in writing and the figure is fixed before any money moves.
The sheriff decides that, or the judge, or the tribunal panel, on the day. Any examiner promising admission is selling you something. What we control is method. Originals are read behind a write-blocker. Images check out on SHA-256. The custody log carries no blank stretches. The report is prepared to evidential standards suitable for Scottish civil or criminal proceedings, and it shows its own working, so a skilled witness on the other side can retrace all of it.
Employers, over kit the business itself owns. Solicitors, insurers and courts, in writing. Private clients, where the device is genuinely their own, and in a matrimonial matter that includes a machine the two of them hold together. We hack nothing. We intercept no live traffic. Where you hold no right to look inside a device, we hold none either.
Handsets, no. That is not work for this bench. What a handset deposits on a computer is another matter and we see it constantly. Backups written by Finder or iTunes. Photo libraries pulled down to a desktop. The WhatsApp Desktop cache. Exports taken out of a cloud account by a lawful route. Messages and pictures sit in every one of those.
Posted, or handed over. There is no collection service. Ring the freephone before anything is packed, so we can agree wrapping, paperwork and timing, then send it tracked and insured or bring it to reception at our Edinburgh location, 9am to 5:30pm, Monday to Friday. Custody starts at the signature.

Secure the evidence. The argument keeps.

Free diagnostic. Written scope. Images that check out. Ring the freephone and we will tell you which questions the machine settles, and which it does not.