Data recovery Encrypted drives — In Frankfurt. Never outsourced.
Data recovery · Encrypted drives

Data recovery with encryption We get it back.

Encryption protects your data from us as well. That is not a shortcoming but the point of it. For a data recovery it means: we bring the hardware back, you bring the key.

✓ In-house clean room✓ Never outsourcedGDPR
  • In-house clean room
  • Never outsourced
  • Our lab
  • Transparent & fair
Methods & technology

Two problems that have to be kept apart

With an encrypted drive, two things are always in the way at once: the broken hardware and the missing access. A data recovery solves the first. If the key is missing, what remains at the end is a complete, technically flawless copy that nobody can read. That is why the most important question comes right at the order stage: do you have the password or recovery key?

Common fault patterns

Encrypted drives

Whether logical or physical — in most cases the memory is still intact. The diagnosis shows what exactly is wrong.

BitLocker

Windows drive encryption. With the 48-digit recovery key an ordinary case — without it, not.

FileVault & Apple Silicon

The key is created in a security chip on the logic board. It cannot be read out, only revived.

Encryption in the controller

Many SSDs encrypt everything they store — even without the user doing anything. A replacement controller has a different key.

Containers & drive passwords

LUKS, VeraCrypt and passwords set at drive level. Different mechanisms, different routes.

How do I tell what is wrong?

From symptom to cause.

Nobody searches for a fault pattern. You hear a noise or read a message — and the most pressing question is: may I switch the device on one more time?

  • Symptom

    Windows asks for the BitLocker key at start-up

    Likely cause

    The computer has detected a change — a different board, altered firmware settings or a faulty security chip.

    What to do now

    Look the key up in the Microsoft account or with your IT before trying anything else.

  • Symptom

    External drive shows nothing but garbage

    Likely cause

    With some external drives the bridge board in the enclosure does the encrypting. Without it the drive is unreadable.

    What to do now

    Do not dispose of the enclosure and always send it along.

  • Symptom

    Mac no longer starts, data is encrypted

    Likely cause

    A fault on the logic board. The key sits in the security chip of exactly that board.

    What to do now

    Do not order a board replacement — that would take the key with it.

  • Symptom

    SSD reports the wrong capacity, contents encrypted

    Likely cause

    Damaged administration inside the controller. The memory is there; the route to it and the decryption are not.

    What to do now

    Do not format and do not install a firmware update.

  • Symptom

    Container password forgotten

    Likely cause

    Not a technical fault but an access problem.

    What to do now

    Write down everything you still remember: fragments, patterns, older variants, lengths. That is exactly the starting point.

Methods & technology

First the hardware, then the door

The procedure is the same as always: first the drive is stabilised and a complete image is created. Only on that image is anything decrypted — never on the original, and never with tools that write. If the password is missing and there is a legitimate claim to access, we work with Passware: not a way around the encryption but a structured search for the password based on what you still know.

Equipment we use

PC-3000 / ACE LabCellebrite UFEDOxygen ForensicsPasswareMRT LabApex Tool Lab

In Frankfurt. Never outsourced.

The technology behind it

Why this takes so much effort.

No jargon for its own sake — the reasons from which price, duration and prospects of success follow.

Why encryption cannot be “bypassed”

By today’s standards the common methods cannot be broken. Systematically trying a password is not a question of effort at sufficient length but simply impossible. Anyone who promises you otherwise is selling a diagnosis. What actually helps is the access itself — key, password, code — or a device that can use its own key again.

Where the key sits

With BitLocker it hangs on the account, on the computer’s security chip or on the recovery key. With FileVault on the login password and the security chip. With a self-encrypting SSD in the controller. With a smartphone in the secure part of the processor, tied to your passcode. This distinction determines the route — which is why it comes at the beginning of every diagnosis.

Why a replacement controller does not help

An identical controller is electrically the same but has a different key burned in at the factory. It cannot decrypt the contents of the foreign memory. That is precisely why, with encrypted drives, the original electronics are repaired rather than replaced — even though that is more work.

Password search is not magic but structure

If you still know fragments — the approximate length, a pattern, variants of an older password, which special characters you usually use — a search space can be built from that which is small enough to work through. From nothing at all it does not work. How promising it is depends entirely on what you can contribute.

The legal point up front

We only work on drives to which there is a claim of access. With jobs from companies, law firms and public bodies that is part of clarifying the assignment; with private individuals we ask. This is not a formality — it is the line between data recovery and something else.

Supported models

What works — and what does not.

Details for your storage medium.

Usually feasible with a key

BitLocker mit Wiederherstellungsschlüssel, FileVault mit Anmeldepasswort oder Wiederherstellungsschlüssel, LUKS und VeraCrypt mit Passwort, Container-Dateien mit bekannter Passphrase.

Hardware has to live first

Selbstverschlüsselnde SSDs, Macs mit T2 oder Apple Silicon, Smartphones — überall dort entsteht der Schlüssel im Gerät und verlässt es nicht.

Practically hopeless without a key

Starke Verschlüsselung ohne jeden Anhaltspunkt zum Passwort, zerstörte Sicherheitsbausteine, bereits zurückgesetzte Geräte.

First aid

Before you do anything.

Bring the medium in or send it to us. The Economy diagnosis is free — you find out what is possible before anything costs money.

First aid for data loss →

  • Take the medium out of service immediately — every further use can accelerate the loss.

  • No recovery attempts with tools from the internet.

  • Do not open the device or medium yourself.

  • Take it to a reliable data recovery specialist — analysis first, then a quote.

Please do not

The mistakes that make it expensive.

Almost every well-meant reflex makes the damage worse. That is why you find not only the rule here but also the reason — nobody follows an instruction without one.

  • With a BitLocker prompt, do not reinstall.

    A reinstall overwrites exactly the areas where the encrypted data sits. Look for the recovery key first.

  • Do not dispose of external enclosures.

    With a number of external drives the bridge board in the enclosure does the encrypting. Without it the drive is unreadable even in perfect condition.

  • Do not order a board replacement while data still matters.

    The security chip goes with the board — and the key with it.

  • No secure erase and no reset.

    These commands discard the internal key within seconds. Afterwards the contents are technically still there and permanently unreadable.

  • Do not try passwords blindly.

    On devices with a limited number of attempts that leads to the key material being discarded for good.

Prices

What this roughly costs.

The hardware is billed like any other drive — encryption changes nothing about that. What may be added is a password search; that is always shown separately.

  • Your case

    Encrypted hard drive is clicking, recovery key available

    What it becomes

    Head swap in the clean room, create an image, decrypt on the copy. Price up to 2 TB, above that in stages.

    Guide value

    €899 · +€100 per further 2 TB

  • Your case

    Encrypted SSD not recognised, password known

    What it becomes

    Revive the original electronics — a replacement controller would have a different key. Price up to 1 TB, above that in stages.

    Guide value

    €499 · +€100 per further TB

  • Your case

    Container deleted, drive fine, passphrase known

    What it becomes

    Create an image, extract the container from the image and open it.

    Guide value

    €299

  • Your case

    Password unknown but fragments are remembered

    What it becomes

    Structured password search with Passware. The prospects depend entirely on what you can contribute — hence no flat rate.

    Guide value

    after diagnosis

Examples are guide values, not an offer. What your case costs is fixed in writing after the diagnosis — only then do you decide whether we continue. Where it says “after diagnosis” above, our price list does not know the case as a flat rate; it is calculated individually and itemised in the quote.

Transparent & fair

Our diagnostic tariffs.

You set the pace. Shipping both ways is included in every tariff — from Standard upwards we collect from you. And you always get a written quote before we start the recovery.

Economy

0 €

free diagnosis

Diagnosis
approx. 5 working days
After approval
Regular queue
Updates
By email

Written quote · free shipping both ways

Recommended

Standard

99 €

incl. VAT · per medium

Diagnosis
within 2 working days
After approval
Scheduled with priority
Updates
Email and phone call

Written quote · free collection and return

Emergency

249 €

incl. VAT · per medium

Diagnosis
next working day
After approval
Moved to the front
Updates
Named contact

Written quote · express collection and return. Arrives before 12 noon: diagnosis the same working day.

The Economy diagnosis is free of charge. With Standard and Emergency the diagnostic fee applies even if you decline the quote — it is not offset against a later recovery. Either way, you decide freely after the quote whether we continue.

How it works

Four steps to your data.

  1. 01

    Send it in or drop it off

    Order online or hand it in without an appointment in Frankfurt-Sachsenhausen.

  2. 02

    Diagnosis

    We examine the medium and send you a written quote.

  3. 03

    Approval & recovery

    We only begin the recovery once you have approved it.

  4. 04

    Your data back

    On a storage medium in the parcel or via an encrypted cloud download.

To be honest

Where even we reach a limit

This is the most honest page in the whole section, because here the limit is not effort but mathematics.

No key, no clues

Without a password and without fragments from which a search space could be built, strong encryption cannot be opened. Full stop.

Destroyed security chip

If the chip that holds the key is destroyed, the key is gone — even with intact memory.

Already reset

A reset discards the key material. There is no way back.

No claim to access

Without a comprehensible claim to the drive we do not work on it.

If the diagnosis shows that little or nothing can be retrieved, we say so — instead of writing a quote that makes hope more expensive.
Questions

Answered briefly.

What does data recovery cost?

We work with transparent fixed prices based on the fault pattern — depending on the medium from €99, €299 or €499; in cases of total damage individually. Before every recovery you receive a written quote and decide freely whether we continue.

Do I pay even if no data is recovered?

The Economy diagnosis is free — if you decline afterwards, no costs arise. With Standard and Emergency the diagnostic fee (€99 or €249) applies even if you decline; it is not offset against a later recovery. The recovery itself is only charged after your approval.

How long does it take?

Depending on the tariff, the diagnosis takes about 5 working days (Economy), 2 working days (Standard) or one working day (Emergency) — with Emergency, the same working day if the medium arrives before 12 noon. How long the recovery itself takes depends on the fault pattern and is stated in the quote.

Is my data safe with you?

Yes. We work in line with the GDPR, pass nothing on to third parties and never outsource. Your data is stored exclusively on our encrypted server and completely deleted after handover.

Can I send the medium in?

Yes. Shipping both ways is included in every diagnosis tariff; with Standard and Emergency we collect the medium from you. Or you come to our lab in Frankfurt-Sachsenhausen without an appointment.

Where do I find my BitLocker recovery key?

Often in the Microsoft account under the device information, in a corporate setting with the IT administration. Sometimes it was printed out or saved to a file when it was set up. Look there before doing anything else.

My hard drive is encrypted and mechanically faulty. What happens first?

The hardware first: we stabilise the drive and create a complete image. The decryption happens afterwards on the image — and needs your key.

Do I pay even if the key is missing?

The hardware repair has been performed and is billed, even if the data stays encrypted. That is exactly why we clarify the key question before approval — so that nobody pays for a result that is of no use to them.

Can you crack a password?

We can search for it in a structured way if you supply clues — length, pattern, older variants. Without such clues strong encryption cannot be opened, and we would rather say that beforehand than afterwards.

Data Recovery Professionals logo
Association of leading data recovery labs

Data Recovery Professionals

A worldwide group of independent, owner-run data recovery companies. Members share methods from professional data recovery, forensics and software development — so on rare damage patterns the knowledge of the whole group stands behind your medium.

Member since 2022Our member profile
Let's go

Every hour counts. Let us talk.

Bring the medium in or send it to us. The Economy diagnosis is free of charge.

Wasserweg 8–10 · 60594 Frankfurt am Main