IT forensics & evidence preservation

When data must not only come back, but hold up.

A data recovery asks: do we get the file back? A forensic image asks in addition: can it later be shown that the file was exactly like this and that nothing was changed along the way? That is a different standard — and a different procedure.

Get in touch →+49 69 6605368-0
  • Confidentiality first

    A confidentiality agreement before intake, not after.

  • Only on the copy

    What is analysed is an image with a checksum. The original stays untouched.

  • One location

    Everything in our own lab in Frankfurt. Nothing outsourced, no intermediate stops.

  • One contact

    You speak to the person handling the case.

The difference from data recovery

In a data recovery the result is what counts: the file is back, all good. In a forensic image the route there counts as well. Who had the drive and when? What was used to read it? Can it be shown that nothing changed between intake and analysis?

That is why a complete image always comes first, with a checksum calculated over it — a kind of fingerprint of the data. Every later analysis runs on a copy of that image. If the checksum can be recalculated at any time, it is established that the analysed state is the same as the one received.

For you that means one thing above all: please do not reach for it yourself beforehand. The most common reason a data set becomes worthless as evidence is not manipulation but well-meant initiative — a colleague who “just had a quick look”.

If it is urgent

Switch the device off, do not log in, copy nothing, hand it to nobody. Note who had the device last and when. Those four sentences save more cases than any software.

Typical occasions

  • Data leaving with a departing employee

    Someone leaves the company and there is a suspicion that documents went with them. What has to be established is what was copied to which medium and when.

  • Internal investigation

    Compliance cases, suspicion of breach of trust or manipulation. The findings have to withstand later scrutiny.

  • Civil dispute

    Securing and preparing a data set both sides refer to — with comprehensible documentation of how it came about.

  • Insurance and damage claims

    After fire, water or a break-in: what was on the device, and can its state be documented?

  • Estates and legal guardianship

    Access to devices when the entitled person can no longer access them — with evidence of entitlement.

  • Lost credentials in a company

    Encrypted drives with no findable key, locked devices with no known code. Legitimate, but technically demanding.

How we work

  1. 01

    Settle confidentiality

    A confidentiality agreement before intake — your template or ours. Only then is the device opened.

  2. 02

    Log the handover

    Record the device with its serial number, document its condition, put the handover in writing. From here on it is traceable who had access and when.

  3. 03

    Image with checksum

    A complete image, read with write protection. A checksum is calculated over the image and recorded.

  4. 04

    Analysis on the copy

    Every further step runs on a copy of the image. After the imaging the original is not touched again.

  5. 05

    Document the findings

    What was found, by which method, and what can be shown from it — and what expressly cannot.

  6. 06

    Handover or safekeeping

    Results handed over encrypted. The original goes back or stays under lock until revoked.

Mobile devices

A smartphone is today the richest source in almost any case — and the least accessible. Current devices encrypt by default, and the passcode goes into the derivation of the key. Without the code there is no access; the number of attempts is limited in hardware, so systematic guessing is out.

What is possible therefore depends on three things: model and software level, the state of the hardware, and whether the code is available. For the analysis we use Cellebrite UFED and Oxygen Forensics. If the device is physically damaged, repair comes first — the same chip-level work as in a smartphone data recovery.

Passwords and encryption

Encrypted containers, locked archives, drives with a forgotten password: for cases with a legitimate claim to access we work with Passware. That is expressly not a way around the encryption — by today’s standards it cannot be broken. It is a structured search for the password.

How promising that is depends entirely on what is known: approximate length, patterns used, older variants, company conventions. From such details a search space can be built that is small enough. From nothing it does not work, and we would rather say so beforehand.

What you get in writing

  • Confidentiality agreement

    Mutual, before intake. Your template or ours.

  • Intake record

    Device, serial number, condition, date, people involved.

  • Checksum of the image

    The proof that the analysed state matches the one received.

  • Findings report

    Method, tools, results — and expressly also the limits of what can be said.

  • Proof of deletion

    In writing on request, once our working copies have been removed.

Tools we use

What we work with.

Tools from professional data recovery and forensics. What is used in a given case depends on the medium — not on what reads well.

PC-3000 / ACE LabCellebrite UFEDOxygen ForensicsPasswareMRT LabApex Tool Lab
To be honest

What we do not offer.

This list is here on purpose. In forensics a clear boundary is worth more than a soft promise — and what is missing here you would otherwise take for granted.

No bypassing of encryption

Without a key, password or code, and without clues for a search, there is no access. That is mathematics, not a question of equipment.

No work without a claim to access

We only work on devices where a comprehensible claim exists. We ask about it, and we ask before intake.

No clear-up rate

We quote no success figures. Without the distribution of cases behind them they would be meaningless.

No certifications we do not hold

We hold no ISO 27001 certification and no comparable seals. If your procedure strictly requires that, say so early — then another address is the right one.

No court-appointed expert status

We are not a publicly appointed and sworn expert. We document comprehensibly; the assessment as an expert opinion lies with others.

Frequently asked

Answered briefly.

Do you sign a confidentiality agreement?

Yes, and before the device is accepted. Your template or ours — both are common. Only then is it opened.

How long does it take?

The imaging itself takes hours to days depending on scope. The analysis depends on the case. Tell us if a deadline applies — then we plan around it.

Can you open a locked phone?

Only with the passcode. On current devices the code goes into the key derivation and the number of attempts is limited in hardware. On older models it depends on model and software level — the diagnosis settles that.

Do we get something in writing?

Yes: an intake record, the checksum of the image and a findings report with method, tools and results — including the limits of what can be said.

What happens to the data after the case?

It sits exclusively on our encrypted server. After completion our working copies are deleted, on request with written proof. Alternatively we keep the image in safekeeping until revoked.

Do you also work for private individuals?

Yes, where a comprehensible claim to access exists — for example in an estate case or with your own devices and lost credentials.

Data Recovery Professionals logo
Association of leading data recovery labs

Data Recovery Professionals

A worldwide group of independent, owner-run data recovery companies. Members share methods from professional data recovery, forensics and software development — so on rare damage patterns the knowledge of the whole group stands behind your medium.

Member since 2022Our member profile
Next step

A case you would rather not discuss on the phone?

Then we start with the confidentiality agreement and talk afterwards. You reach us directly — no ticket system, no intermediary.

Wasserweg 8–10 · 60594 Frankfurt am Main