
RAID and NAS data recovery We get it back.
A RAID survives the failure of one drive. What it often does not survive is the attempt to recover from it. Please do not start a rebuild.
- In-house clean room
- Never outsourced
- Our lab
- Transparent & fair
Image first, then reconstruct — never the other way round
We never work on a running array. Every drive is imaged individually and write-protected; the array is then rebuilt from those copies. Block size, drive order, the rotation pattern of the parity information and the starting offset are tested until a valid file system emerges. The originals are not written to a single time.
RAID, NAS & server
Whether logical or physical — in most cases the memory is still intact. The diagnosis shows what exactly is wrong.
One drive has failed
The array keeps running but without reserve. The next fault gets through — and a rebuild is at its most dangerous right now.
Volume crashed
Several members are missing or the array’s administrative data is damaged. The storage is offline; the data is not necessarily.
Controller or power supply faulty
The drives are fine, the system can no longer reach them. Frequently after a power surge.
Ransomware
Files renamed and unreadable. With some file systems, older states from before the infection can be extracted.
From symptom to cause.
Nobody searches for a fault pattern. You hear a noise or read a message — and the most pressing question is: may I switch the device on one more time?
Symptom
One drive reported as failed
Likely cause
The array keeps running without reserve.
What to do now
Do not start a rebuild. Secure what is still reachable, or shut the system down.
Symptom
“Volume crashed” or “storage pool degraded”
Likely cause
More members are missing than the array can absorb, or the administrative data is damaged.
What to do now
Shut down, confirm nothing, label the bay order.
Symptom
Rebuild started and aborted
Likely cause
A second drive gave up under the sustained load or reported an unreadable spot.
What to do now
Do not start it again. The state is recoverable, but every further attempt makes it worse.
Symptom
System will not come up after a power cut
Likely cause
A surge at the controller or power supply, or interrupted writes in the file system.
What to do now
Do not switch on repeatedly.
Symptom
System asks to initialise or import a foreign configuration
Likely cause
The controller no longer recognises the existing configuration.
What to do now
Decline. Confirming writes a new configuration over the old one.
Symptom
Files renamed and unreadable
Likely cause
Ransomware.
What to do now
Disconnect the system from the network and switch it off. Delete nothing, create nothing new.
What has to be reconstructed
An array is more than a collection of drives. For a coherent file system to emerge again, four values have to be right: how much data was written to one drive at a time, in which order the drives sit, by which pattern the parity information moves from drive to drive, and at which offset that begins. Some systems store these details on the drives — others do not, or they are damaged. Then they are derived from the data itself.
Equipment we use
In Frankfurt. Never outsourced.
Why this takes so much effort.
No jargon for its own sake — the reasons from which price, duration and prospects of success follow.
Why the rebuild is the riskiest measure
To reconstruct a missing member, every remaining drive has to be read in full — with today’s capacities that means hours to days without a pause. The drives in an array almost always come from the same delivery, have the same operating hours and the same environment behind them. When one dies of old age, the others are not far off. If even a single unreadable spot turns up, the process aborts — and the newly calculated redundancy has partly replaced the old one.
Imaging with write protection
Every member is imaged individually, with hardware that blocks writes and limits read attempts in time instead of repeating them endlessly. With weak drives, everything unproblematic is secured first and only then are the critical areas worked on in a controlled way. If a member is mechanically faulty it goes into the clean room beforehand.
The array is assembled virtually
Reconstruction happens exclusively on the copies. Candidates for block size, drive order, rotation pattern and offset are tested against each other until the resulting file system is internally consistent. That is computation, not guesswork — and it happens without any risk to the originals.
Why NAS systems have several layers
A typical NAS stacks three levels: the array, above it a management layer for storage areas, above that the actual file system. Vendor-specific modes additionally allow drives of different sizes by layering several arrays. Each of these levels has to be understood individually — which is why “just reassembling the RAID” is not enough.
Ransomware: the detour via older states
Some file systems overwrite nothing when changing data but write a new version and keep the old one as long as there is room. From such older states a condition from before the infection can sometimes be extracted. Whether that works depends on how much has been written since the incident — here too: switch off immediately.
RAID is not a backup
An array protects against the failure of one drive. It does not protect against accidental deletion, malware, a power surge, theft or fire — all of which hit every drive at once. Anyone who keeps the two separate saves themselves this page in an emergency.
What we work on.
Details for your storage medium.
RAID levels
RAID 0, 1, 5, 6, 10, 50 und 60 sowie herstellereigene Mischformen mit unterschiedlich großen Laufwerken. Hardware-Controller ebenso wie softwareseitige Verbünde.
NAS systems
Synology, QNAP, Buffalo, ASUSTOR, TerraMaster, Netgear ReadyNAS, WD My Cloud, Drobo und Eigenbauten.
File systems
ext4, Btrfs, XFS, ZFS, NTFS und ReFS — einzeln oder in mehreren Schichten übereinander, wie es NAS-Systeme üblicherweise aufbauen.
Servers
Einzelne Laufwerke ebenso wie komplette Verbünde aus Rack-Systemen. SATA, SAS und NVMe; auch heliumgefüllte Laufwerke hoher Kapazität.
Before you do anything.
Bring the medium in or send it to us. The Economy diagnosis is free — you find out what is possible before anything costs money.
Take the medium out of service immediately — every further use can accelerate the loss.
No recovery attempts with tools from the internet.
Do not open the device or medium yourself.
Take it to a reliable data recovery specialist — analysis first, then a quote.
The mistakes that make it expensive.
Almost every well-meant reflex makes the damage worse. That is why you find not only the rule here but also the reason — nobody follows an instruction without one.
Do not start a rebuild.
It puts maximum load on exactly the drives you are completely dependent on at that moment — and overwrites the existing redundancy in the process.
Do not run a file system check.
It writes and reorders administrative data on the basis of already damaged information. On a weakened array that does more harm than the failure itself.
Do not reseat or swap drives.
The order in the enclosure is part of the information from which the array can be reconstructed.
Confirm nothing that sounds like initialise, format or import.
The controller then writes a new configuration over the existing one.
Do not run recovery software over the network.
It forces weakened drives into hours of continuous reading and accelerates exactly the failure you are trying to prevent.
Do not reflash a NAS in emergency mode.
Installing the system software writes to the drives — frequently exactly where the array’s administrative data sits.
What this roughly costs.
An array is not billed as a whole but as two items: imaging each individual drive according to its fault pattern, and reconstructing the array. Both appear separately in the quote so you can see what you are paying for.
Your case
Four drives, all readable, the array does not come up
What it becomes
Image every member with write protection, rebuild the array offline from the copies. No drive needs mechanical work.
Guide value
after diagnosis
Your case
One member is clicking, the others are fine
What it becomes
The faulty drive goes into the clean room and is billed according to the fixed-price table for hard drives; the reconstruction comes on top.
Guide value
€899 up to 2 TB · +€100 per further 2 TB
Your case
Two drives failed at the same time
What it becomes
The classic case after an aborted rebuild or a power surge. Treat both members individually, then reconstruct.
Guide value
after diagnosis
Your case
Ransomware, drives technically fine
What it becomes
Check whether the file system keeps older states from before the infection and extract them.
Guide value
after diagnosis
Examples are guide values, not an offer. What your case costs is fixed in writing after the diagnosis — only then do you decide whether we continue. Where it says “after diagnosis” above, our price list does not know the case as a flat rate; it is calculated individually and itemised in the quote.
Our diagnostic tariffs.
You set the pace. Shipping both ways is included in every tariff — from Standard upwards we collect from you. And you always get a written quote before we start the recovery.
Economy
0 €
free diagnosis
- Diagnosis
- approx. 5 working days
- After approval
- Regular queue
- Updates
- By email
Written quote · free shipping both ways
Standard
99 €
incl. VAT · per medium
- Diagnosis
- within 2 working days
- After approval
- Scheduled with priority
- Updates
- Email and phone call
Written quote · free collection and return
Emergency
249 €
incl. VAT · per medium
- Diagnosis
- next working day
- After approval
- Moved to the front
- Updates
- Named contact
Written quote · express collection and return. Arrives before 12 noon: diagnosis the same working day.
The Economy diagnosis is free of charge. With Standard and Emergency the diagnostic fee applies even if you decline the quote — it is not offset against a later recovery. Either way, you decide freely after the quote whether we continue.
Four steps to your data.
- 01
Send it in or drop it off
Order online or hand it in without an appointment in Frankfurt-Sachsenhausen.
- 02
Diagnosis
We examine the medium and send you a written quote.
- 03
Approval & recovery
We only begin the recovery once you have approved it.
- 04
Your data back
On a storage medium in the parcel or via an encrypted cloud download.
Where even we reach a limit
An array can be reconstructed surprisingly far. But there are states here too from which nothing comes.
Too many members physically destroyed
If more drives are missing than can be calculated from the redundancy, the data itself is missing.
A rebuild that ran all the way through on the wrong basis
If the entire redundancy was rewritten while the basis was already incomplete, the old state has been overwritten.
Encrypted areas without a key
Encrypted shares cannot be opened without the password or key file.
Ransomware without older states
If a lot was written after the infection, or the file system keeps no older states, there is nothing to bring back.
Answered briefly.
What does data recovery cost?
We work with transparent fixed prices based on the fault pattern — depending on the medium from €99, €299 or €499; in cases of total damage individually. Before every recovery you receive a written quote and decide freely whether we continue.
Do I pay even if no data is recovered?
The Economy diagnosis is free — if you decline afterwards, no costs arise. With Standard and Emergency the diagnostic fee (€99 or €249) applies even if you decline; it is not offset against a later recovery. The recovery itself is only charged after your approval.
How long does it take?
Depending on the tariff, the diagnosis takes about 5 working days (Economy), 2 working days (Standard) or one working day (Emergency) — with Emergency, the same working day if the medium arrives before 12 noon. How long the recovery itself takes depends on the fault pattern and is stated in the quote.
Is my data safe with you?
Yes. We work in line with the GDPR, pass nothing on to third parties and never outsource. Your data is stored exclusively on our encrypted server and completely deleted after handover.
Can I send the medium in?
Yes. Shipping both ways is included in every diagnosis tariff; with Standard and Emergency we collect the medium from you. Or you come to our lab in Frankfurt-Sachsenhausen without an appointment.
My NAS offers to restore the array. Should I let it?
If the data matters to you and there is no current backup: no. The rebuild is the riskiest measure at exactly the moment when there is no reserve left.
Do I have to send in the whole enclosure?
Usually not — what matters are the drives, packed individually and labelled with their bay number. With some systems the enclosure helps anyway; ask beforehand if in doubt.
I already started the rebuild and it aborted. Is everything lost?
Not necessarily. Even a partly overwritten array can often still be reconstructed. What matters is to attempt nothing further now and to leave the system switched off.
Can you not work out the drive order yourselves?
Usually yes — it can be derived from the data. But if it is known, the work is considerably shorter. Hence the request to label before removing.
We are a company and need a confidentiality agreement.
We sign it before intake. Chain of custody, a named contact and proof of deletion are part of the process — the details are on the page for businesses.

Data Recovery Professionals
A worldwide group of independent, owner-run data recovery companies. Members share methods from professional data recovery, forensics and software development — so on rare damage patterns the knowledge of the whole group stands behind your medium.
Every hour counts. Let us talk.
Bring the medium in or send it to us. The Economy diagnosis is free of charge.
Wasserweg 8–10 · 60594 Frankfurt am Main

