Services
What we recover, and what we’ll tell you straight.
One method underneath all of it: your media is imaged read-only first, and every recovery attempt happens on that copy. Nothing we do writes to your original.
Hard drives, deleted, formatted and corrupt
Deleting a file usually doesn't erase it. It removes the entry that points to it and marks the space reusable, so the contents sit there until something writes over them. Formatting is much the same at consumer level, a new, empty map laid over a disk that still holds the old data.
We rebuild the map. That means reading the filesystem's own structures directly. NTFS master file tables and USN journals, APFS and HFS+ catalogues, ext4 inodes and journal orphans, FAT and exFAT directory chains, and where those are gone, identifying files by their contents rather than their entries.
Where it ends: The enemy is writes. Every hour a drive stays in use after the loss, and every recovery tool run against the original, reduces what's left. If the sectors holding your file have been reused, no lab and no software can bring that file back. We'll tell you that rather than bill you to find out.
Failing and degraded drives
Slow reads, drives that vanish under load, folders that hang forever, SMART warnings. The drive still works, but not reliably, and every read attempt costs you a little more of it.
These are imaged before anything else happens, copied region by region onto stable storage, taking the healthy areas first at speed and returning for the difficult ones afterwards, in passes designed to get the most data before the drive deteriorates further. All recovery then runs against that image. Your original is read, never written to, and never worked on directly.
What decides it: Order matters enormously here. A tool that starts at sector zero and grinds head-first into the worst area of a dying drive can kill it before it reaches the 90% that was still readable. That sequencing decision is most of the job.
SSDs, NVMe and flash
Solid-state drives fail differently. There are no moving parts to seize, but there is a controller doing constant translation between what the operating system thinks it's addressing and where data physically lives.
We work with the drive's own presentation of itself where it still responds, and recover at the filesystem and file-content level from the image.
The part nobody wants to hear: On most modern SSDs, TRIM means deleted data is actively erased by the drive itself, often within minutes, whether or not anything else writes to it. When that has happened the data is genuinely gone, not hidden, not locked, gone. You'll hear that from us in the free assessment rather than after a fortnight of billing.
Memory cards, USB sticks and camera media
Cards that suddenly ask to be formatted, cameras that report a card error mid-shoot, footage that stops halfway through a file.
Where the filesystem is unreadable we carve by content signature instead, which recovers files a directory-based scan can't see. Video gets specific treatment: interrupted recordings often lack the index that tells a player where the frames are, so the stream is parsed and the index rebuilt from the footage itself.
The hard case: Cards that have been reformatted in-camera and shot over are the hard case, because cameras write large sequential files that overwrite generously.
RAID, NAS and servers
An array that won't assemble, a NAS that boots to an error, a controller that has decided two disks are foreign. The most common cause of permanent loss here isn't the failure, it's the rebuild attempted afterwards.
We work from the member disks, imaged individually, and determine the array's real geometry from the data itself, order, stripe size, rotation, parity, which member went offline first and therefore which is stale. The array is reconstructed virtually from those images. The original disks are never rebuilt onto.
What we can and can't undo: Any filesystem on top: ext4, Btrfs, ZFS, NTFS, APFS, VMFS and the virtual disks inside it. If a rebuild has already been run onto the array with a wrong member order, some of the data may have been overwritten by the rebuild itself, recoverable in part, and we'll say which part.
CCTV, NVR and DVR recorders
Surveillance recorders don't store footage the way a computer stores files. Most write a proprietary container straight to the disk in a continuous loop, so ordinary recovery tools scan the drive and report that it's empty.
We read the recorder's own structures directly from its disk, across the common vendor families and the many rebadges of them, and export playable footage for the window you need.
The clock: This one is a clock. The recorder overwrites its oldest footage automatically and continuously. If it is still running, it is consuming the thing you want back right now.
What we don’t do
We don’t run a cleanroom. If a drive is clicking, beeping, grinding or no longer spinning up, the problem is mechanical: heads, motor, or physical damage to the platters. That work needs a controlled environment and donor parts, and doing it on an ordinary bench is how a recoverable drive becomes an unrecoverable one. We assess those free, tell you plainly what you’re dealing with, and give you our findings in writing to take wherever you choose.
We don’t publish a success rate. A percentage measured across other people’s drives tells you precisely nothing about yours, and in this category it is usually marketing. We’ll assess your device and tell you what is actually recoverable from it.
We don’t work on devices without authority. Phone and recorder work requires proof of ownership, or an instructing solicitor’s engagement. That protects you as much as it protects us.