Deleted and inaccessible data

Forensic Data Recovery for Legal Investigations

Proportionate recovery and examination of deleted or logically inaccessible computer and storage data where the method, provenance and limitations must withstand legal or workplace scrutiny.

Direct access to Alistair Ewing · Free initial consultation · Written estimate before work

Recovery with an evidential purpose

Forensic data recovery is different from ordinary repair. The first question is not simply whether a file can be opened, but whether useful data can be recovered without avoidable change and whether its source, method and limits can be documented for the case or investigation.

Alistair can assess available computers, storage media, forensic images, backups and related records, then propose a proportionate recovery stage. Recovered items are examined in context: file-system entries, application records, copies, thumbnails, archives and surrounding activity may matter as much as the visible content.

This is a professional legal and investigation service, not consumer password bypass or general computer repair. Authority to examine the source and the relevance of the requested material are confirmed before work begins. Hardware repair or another specialist technique is identified separately when required.

Recovery questions that may be examined

  • Whether deleted files, folders, messages or application records remain available in an accessible source or forensic image.
  • Whether earlier copies, temporary data, backups, thumbnails or related artefacts help reconstruct missing content.
  • Whether deletion, formatting, synchronisation, retention settings or routine system activity explains the present state.
  • Whether recovered material can be placed into a reliable chronology and linked to its source path or application.
  • Which recovery avenues are technically available, proportionate and likely to add evidential value.

Sources and context to preserve

  • The original computer or storage device, protected from further routine use where safe.
  • Existing forensic images, backups, exports and acquisition notes.
  • Information about deletion, failure, reset, repair, migration or reinstallation events.
  • Relevant dates, filenames, users, applications and the reason the material matters.
  • Available passwords or recovery keys supplied only through the agreed secure route after instruction.

Recovery limits

  • Deleted data may have been overwritten, discarded by solid-state storage processes or removed by application and retention behaviour.
  • Encryption and missing credentials can prevent or limit access; physical damage or unsupported hardware may require a separately scoped recovery specialist.
  • Recovered fragments may be incomplete, duplicated or stripped of the context needed for reliable interpretation.
  • Recovery does not by itself establish who created, deleted or used an item; attribution requires corroborating evidence.
  • No particular file, message, date range or recovery percentage can be guaranteed in advance.

What helps assess a recovery instruction

  • Party, organisation and relevant custodian names for the conflict check.
  • The source type, make, approximate capacity, condition and present location.
  • What appears to be missing and the relevant dates, applications or filenames.
  • What has happened to the source since deletion, failure or loss was noticed.
  • The legal or investigation question, deadline and required form of findings.

Please do not attach evidence, passwords or confidential case papers to the public enquiry. A secure route is agreed only after the conflict check.

How conflict checks, quotations and evidence transfer work

Frequently asked questions

Can deleted files always be recovered?

No. Availability depends on the storage technology, deletion method, encryption, subsequent use and other system behaviour. An initial assessment can identify a proportionate route, but cannot promise a result.

Should the device be switched on to check?

Avoid exploratory use where evidence may matter. Record its current state and seek device-specific advice; the safest action depends on whether it is running, encrypted or business-critical. Physical damage may require a separate specialist.

Read all questions about fees, timing, evidence and instructing Alistair

Initial enquiry

Is deleted or inaccessible data material to the case?

Describe the source, what is missing, what happened before the loss was noticed, continued use and the evidential question. Recovery prospects cannot be promised before the material is assessed.

Discuss forensic recovery