When data must not only come back, but hold up.
A data recovery asks: do we get the file back? A forensic image asks in addition: can it later be shown that the file was exactly like this and that nothing was changed along the way? That is a different standard — and a different procedure.
Confidentiality first
A confidentiality agreement before intake, not after.
Only on the copy
What is analysed is an image with a checksum. The original stays untouched.
One location
Everything in our own lab in Frankfurt. Nothing outsourced, no intermediate stops.
One contact
You speak to the person handling the case.
The difference from data recovery
In a data recovery the result is what counts: the file is back, all good. In a forensic image the route there counts as well. Who had the drive and when? What was used to read it? Can it be shown that nothing changed between intake and analysis?
That is why a complete image always comes first, with a checksum calculated over it — a kind of fingerprint of the data. Every later analysis runs on a copy of that image. If the checksum can be recalculated at any time, it is established that the analysed state is the same as the one received.
For you that means one thing above all: please do not reach for it yourself beforehand. The most common reason a data set becomes worthless as evidence is not manipulation but well-meant initiative — a colleague who “just had a quick look”.
If it is urgent
Typical occasions
Data leaving with a departing employee
Someone leaves the company and there is a suspicion that documents went with them. What has to be established is what was copied to which medium and when.
Internal investigation
Compliance cases, suspicion of breach of trust or manipulation. The findings have to withstand later scrutiny.
Civil dispute
Securing and preparing a data set both sides refer to — with comprehensible documentation of how it came about.
Insurance and damage claims
After fire, water or a break-in: what was on the device, and can its state be documented?
Estates and legal guardianship
Access to devices when the entitled person can no longer access them — with evidence of entitlement.
Lost credentials in a company
Encrypted drives with no findable key, locked devices with no known code. Legitimate, but technically demanding.
How we work
- 01
Settle confidentiality
A confidentiality agreement before intake — your template or ours. Only then is the device opened.
- 02
Log the handover
Record the device with its serial number, document its condition, put the handover in writing. From here on it is traceable who had access and when.
- 03
Image with checksum
A complete image, read with write protection. A checksum is calculated over the image and recorded.
- 04
Analysis on the copy
Every further step runs on a copy of the image. After the imaging the original is not touched again.
- 05
Document the findings
What was found, by which method, and what can be shown from it — and what expressly cannot.
- 06
Handover or safekeeping
Results handed over encrypted. The original goes back or stays under lock until revoked.
Mobile devices
A smartphone is today the richest source in almost any case — and the least accessible. Current devices encrypt by default, and the passcode goes into the derivation of the key. Without the code there is no access; the number of attempts is limited in hardware, so systematic guessing is out.
What is possible therefore depends on three things: model and software level, the state of the hardware, and whether the code is available. For the analysis we use Cellebrite UFED and Oxygen Forensics. If the device is physically damaged, repair comes first — the same chip-level work as in a smartphone data recovery.
Passwords and encryption
Encrypted containers, locked archives, drives with a forgotten password: for cases with a legitimate claim to access we work with Passware. That is expressly not a way around the encryption — by today’s standards it cannot be broken. It is a structured search for the password.
How promising that is depends entirely on what is known: approximate length, patterns used, older variants, company conventions. From such details a search space can be built that is small enough. From nothing it does not work, and we would rather say so beforehand.
What you get in writing
Confidentiality agreement
Mutual, before intake. Your template or ours.
Intake record
Device, serial number, condition, date, people involved.
Checksum of the image
The proof that the analysed state matches the one received.
Findings report
Method, tools, results — and expressly also the limits of what can be said.
Proof of deletion
In writing on request, once our working copies have been removed.
What we work with.
Tools from professional data recovery and forensics. What is used in a given case depends on the medium — not on what reads well.
What we do not offer.
This list is here on purpose. In forensics a clear boundary is worth more than a soft promise — and what is missing here you would otherwise take for granted.
No bypassing of encryption
Without a key, password or code, and without clues for a search, there is no access. That is mathematics, not a question of equipment.
No work without a claim to access
We only work on devices where a comprehensible claim exists. We ask about it, and we ask before intake.
No clear-up rate
We quote no success figures. Without the distribution of cases behind them they would be meaningless.
No certifications we do not hold
We hold no ISO 27001 certification and no comparable seals. If your procedure strictly requires that, say so early — then another address is the right one.
No court-appointed expert status
We are not a publicly appointed and sworn expert. We document comprehensibly; the assessment as an expert opinion lies with others.
Answered briefly.
Do you sign a confidentiality agreement?
Yes, and before the device is accepted. Your template or ours — both are common. Only then is it opened.
How long does it take?
The imaging itself takes hours to days depending on scope. The analysis depends on the case. Tell us if a deadline applies — then we plan around it.
Can you open a locked phone?
Only with the passcode. On current devices the code goes into the key derivation and the number of attempts is limited in hardware. On older models it depends on model and software level — the diagnosis settles that.
Do we get something in writing?
Yes: an intake record, the checksum of the image and a findings report with method, tools and results — including the limits of what can be said.
What happens to the data after the case?
It sits exclusively on our encrypted server. After completion our working copies are deleted, on request with written proof. Alternatively we keep the image in safekeeping until revoked.
Do you also work for private individuals?
Yes, where a comprehensible claim to access exists — for example in an estate case or with your own devices and lost credentials.

Data Recovery Professionals
A worldwide group of independent, owner-run data recovery companies. Members share methods from professional data recovery, forensics and software development — so on rare damage patterns the knowledge of the whole group stands behind your medium.
A case you would rather not discuss on the phone?
Then we start with the confidentiality agreement and talk afterwards. You reach us directly — no ticket system, no intermediary.
Wasserweg 8–10 · 60594 Frankfurt am Main

