Insiders who do real damage do not announce themselves. Access carries on working past the leaving date. An export fires mid-afternoon on a Tuesday. The archive gets built the night before a resignation. Investigations here are assembled from records the company already holds, across endpoint, server and network, and they report what those records will carry against named accounts, sessions and hours.
◇ Footing first. Bench time after. The free diagnostic opens the job, a written scope follows it, and forensic fees clear ahead of any examination. No fix, no fee all jobs except electronic and mechanical failures, chip level work, DVR and Forensic jobs. Full pricing is on the data recovery cost page.
These are what turn an uneasy feeling into a written instruction.
Access survives employment far more often than companies plan for. Copy a profile and the cached credentials plus the password-manager store go with it. Keys and tokens taken during a final week keep on working until someone gets round to revoking them. A colleague's password, seen once across a desk, works fine from a kitchen table. So the job is to establish which credentials left, then read authentication logs alongside endpoint traces until the systems reached can be listed with their source addresses and hours. Everything after the leaving date goes in, and that is commonly the part that decides it.
Endpoints only ever give you half. Query history exposes extraction at scale: the SELECT that lifted a client table, timed and owned by an account. Set backups and snapshots side by side and the moment records altered or vanished acquires a date. File-server logs show who opened which shares and where a pattern broke away from habit. Network records and captures show sustained transfers out to addresses no business process explains. Server material also ages faster than anything else, because logs rotate to schedules counted in weeks, so it heads the preservation list. Targeted capture also keeps the business trading while the evidence sits still, which matters when the server in question runs job costing.
A tribunal will draw its own line between carelessness and planning, so the investigation gathers whatever speaks to it. Teams and Slack traffic discussing either the move or the material. Archives in RAR or 7z put together across the last few days, whose contents lists frequently survive even once the archives have been binned. Competitor sites and job boards threaded through browsing history. Metadata with a last-modified-by value setting a named account against a named file at a stated hour. Individually, not one of those decides a thing. Lined up, they generally do.
Somebody's own handset or laptop on the office Wi-Fi puts us hard against a legal line, and we stop on the lawful side of it. Whatever your network wrote down is company property and perfectly fair evidence: association times, hardware identifiers, volume carried, destination reached. Examining the kit itself would need the owner agreeing, a protocol settled between solicitors, or an order of the court. Reports here are built out of what the infrastructure lawfully shows, and they state where that line falls, which is exactly what keeps them usable.
Imaging discipline behind this service belongs to the forensic recovery hub. For exits by way of a tenancy, see email and cloud exfiltration. Endpoint capture is workstation deep imaging. The trade-secret angle is the IP theft page. Figures are on the prices page.
Tied to accounts and sessions, dated, and traced back into the systems' own records.
Which keys, tokens and stored passwords went, and when.
The systems reached with them, by hour and source address.
Extraction at scale out of databases and file servers, backed by query evidence.
Steady outbound transfers to external addresses, out of logs and captures.
Messages, archives, browsing and metadata that speak to intent.
What Wi-Fi records lawfully show about a personally owned device.
Each instruction opens on the free diagnostic. Allow 2 working days from the date a device reaches this bench. Forensic casework sits outside no fix, no fee. The full forensic investigation with report is £800 + VAT, payable 100% upfront. The less expensive Forensic binary image and deleted-file extraction service, without the report, is £400 + VAT. Any Forensic work required will be payable upfront. Where a scope reaches across several servers, we quote in writing once the free diagnostic is done. You will find both figures repeated on the prices page, and we take nothing until a scope is agreed in writing.
Insider instructions run on systems and records in the company's ownership, behind HR or behind a solicitor. Three doors in, and we have never found a fourth. Kit the business itself owns. A written instruction out of a solicitor, an insurer or from the court. Or else a device that genuinely belongs to the client, which in a matrimonial matter takes in one held between the two of them. Nothing gets hacked at this bench. Live traffic is never intercepted. Where the instructing client holds no right to look inside a device, we hold none either.
These cases usually begin with a scoping call and not a parcel. Ring 0800 689 0668, tell us what you are looking at, and we will list what needs preserving before tonight. Collection is not offered here. Where hardware has to travel it goes tracked and insured, or comes across the counter, and is booked into custody once it lands in Edinburgh.
Still bolted into a laptop, desktop, MacBook, iMac, server or CCTV / DVR box? Get the hard drive or SSD out first. The bare drive travels on its own. Stripping machines down is not a job this lab takes on. Flash soldered to a motherboard, as on Apple Silicon Macs and a couple of very thin laptops, is our one flat no: if it will not unbolt, it cannot be worked on.
↓ Print the shipping & booking-in form (PDF)
Address it for the attention of Edinburgh Data Recovery. From Aberdeen that is roughly 130 miles and two and a half hours down the A90, or next working day by tracked post if you would rather not make the run. You get a call the moment it is booked onto the bench.
Not sure what belongs in the box? Ring 0800 689 0668 before you tape it shut, or work through the free online diagnostic.
Preserve the logs before rotation takes them. The freephone puts you through to an examiner, not a queue.