We're taking on new cases now · Weekdays, 9am–5:30pm Need it back quickly? Call 0800 6890668
MKDR Milton Keynes Data Recovery 0800 6890668 Get it diagnosed
MKDR / Investigations & evidence / Device forensics & evidence

Evidence work · forensic examinations across Buckinghamshire

Nothing touched. Everything provable.

Evidence is lost in the first hour, not the last. How the material is handled weighs as much as what it contains. So the exhibit is copied behind a write blocker before a single file is opened, the log is written while the work happens, and the report is built to be pulled apart — by the other side's expert, or by the bench. Independent, discreet, and clear-eyed about the limits of what we can claim.

Reports built for court — CPR 35 / CrimPR 19 Custody trail recorded Discreet and even-handed

Speak to an engineer in confidence
0800 6890668

Four principles, no exceptions.

1 — Leave the data as foundNothing we do changes what sits on media that might be relied on in court: the write blocker goes on first, the image is taken, and only then does examination begin.
2 — Only a competent handWhere the original genuinely has to be accessed, the person doing it must be qualified for the work and able to stand in a witness box explaining the step and its consequences.
3 — Record every stepEach process applied to the exhibit is written down fully enough for a third party to run the whole thing again and land on the same answer.
4 — A named examiner owns itResponsibility for the case, and for holding to all four of these rules, rests with the individual in charge of it.

The cases that come in.

Unsure? Call the lab →
The problemWhat the analysis turns upWhat you get back
A single laptop that a dispute turns onImaged behind a write blocker, then the copy is worked: artefacts, files, timelineA written answer, no jargon
A leaver you think took files with themStick connections, cloud and webmail residue, deletions, wiping tools — set out in orderSomething HR and your solicitor can use
Files someone deleted that now matterEvidence they were there, when they went, and what became of them — recovered forensicallyThe data itself, with dates and mechanism
An encrypted volume you have the right to openPassware works the encryption where a password or key can be recoveredThe contents, plus how we got in
A case that will end up in courtThe identical examination, written up to what CPR Part 35 or CrimPR Part 19 requiresAn expert report the court will accept
Video sitting on a CCTV recorder or DVRPulled off with custody unbroken — there's more on the CCTV pagesVideo that plays, and the custody log behind it
Sending it by post: gear and media reach our secure intake lab by insured, tracked post, and we cover the return postage — or ring first and we'll work out the best way to send it. There's more detail on the enquiry page.

Each stage of the work.

See past cases →
01

A confidential chat first, then a written quote Free

Work opens with a confidential briefing. You set out what has happened, which devices and accounts are involved, and what the evidence needs to prove. That fixes the scope, and the scope fixes one written quote, agreed before any examination starts. The scoping itself costs nothing.

Handled quietlyOne written quote, fixedThe question defined exactly
02

Imaging comes first

Nothing gets read until it has been copied through a hardware write blocker. The exhibit itself is the evidence; a quick look round it is what kills cases.

Blocked, then copiedOriginals left alone
03

Work on the image only

All examination runs against the image — OSForensics and the rest: system artefacts, file activity, what was deleted, when things happened. Notes are written while the work is done, never reconstructed later.

Examined in OSForensicsNotes made as we go
04

The report, unvarnished

You get an answer to the question you actually put, in ordinary English, with the technical working set out behind it. An unwelcome result is still the result, and it goes in unchanged.

Plain answer up frontTechnical annex behind
05

Imaged, logged, ready for court

Everything comes to you: the report, the exhibits, the underlying files, the hash values, the continuity log and our bench notes. Another expert — or a tribunal — can then retrace every step of the work for themselves.

Exhibits and reportHashes recorded, chain unbrokenStands up to challenge

What the lab will and will not say

  • In court work the court comes first — the instructing side and the invoice make no difference to what the report says.
  • The statutory Code from the Forensic Science Regulator — Version 2 took effect on 2 October 2025 — covers forensic work in England and Wales that is done for the criminal justice system. Instructions in employment, civil or insurance matters fall outside what it enforces; we'll say which side of that line your matter falls.
  • Handsets and tablets are turned away — a phone examined badly is worse than one not examined at all, so we send that work elsewhere.
  • Confidentiality is built in — files carry a case number rather than a name, and nobody but the instructing party sees the result.

Why it pays to preserve privately, and fast: HMICFRS counted over 25,000 devices waiting in police digital-forensics queues in December 2022; BBC and University of Leicester analysis of Crown Prosecution Service data, reported in June 2025, found more than 30,000 prosecutions in England and Wales collapsed between October 2020 and September 2024 where evidence was lost, missing or damaged. Data secured properly on day one never joins any queue.

The kit, and what it does.

KitWhat it doesWhat it gives us
X-Ways ForensicsClose examination of disk images — artefacts, records of activity, deleted content and timelinesSpare, quick, and right for a small lab that would rather know one tool properly
OSForensicsTrawling, indexing and searching Windows machines, and any image taken from oneWide first-pass discovery: registry entries, recent-use traces, the history of attached USB devices
PasswareOpening locked volumes, where the authority is lawful and a credential is within reachHonest about encryption: either it opens or it doesn't, and the report says which
Atola Insight ForensicImaging with write protection in hardware and hashing done during the same runIts acquisition log builds itself while the copy is made — continuity from the first minute
ACE Lab PC-3000 & Data ExtractorFirmware-level repair when the exhibit happens to be a dying driveA drive can be evidence and half-dead at once — here it gets both trades in one go

Honest about where we stand

  • We do: hold every job to all four ACPO/NPCC principles for digital evidence.
  • We do: take every copy behind a write blocker, fingerprint it with MD5 and SHA-256, and log custody so an outsider can check it.
  • We do: use tools people know — OSForensics to examine, Passware where decryption is lawful — and run them on the copy, not the original.
  • We don't: hold UKAS or ISO accreditation, and we don't pretend otherwise — where the rules call for credibility disclosure, that goes at the front of the report, and it's said here too.
  • We don't: touch handsets or tablets, deal with ransomware gangs, or shade a conclusion towards whoever settles the invoice.

Why spell all that out: criminal procedure has required, since 2019, that anything touching an expert's credibility be disclosed — a missing accreditation among it. Printing it here isn't humility. It's what stops the other side turning our silence into their best point.

Lately in the casebook.

MK · MKD-2026-4521CONFIRMED ✓

Tracing a Buckinghamshire firm's missing project files

A client arrived certain that files had been taken. What we found was far more mundane: a badly configured sync had wiped them off the shared drive, and most came back. The plain answer settled the dispute quicker than any accusation would have.

Matter resolvedResults inside 6 days

While it is still in your hands.

Worth doing

  • Put it out of use — every session rewrites data
  • Write down who touched it and when
  • Send cables, power supply and any passwords along with it
  • Ring us first, before your IT team starts digging

Best avoided

  • Hand it to IT for a look — clicks overwrite the traces
  • Take your own safety copy of files
  • Challenge anyone before the evidence is secured
  • Read a deletion as proof of guilt, or of loss

Quiet questions, plain answers.

What does digital forensics mean?

Taking, examining and reporting electronic evidence so it holds up under challenge. The device is imaged before anyone looks at it, each step is recorded, and the report is written so a second examiner can follow the same path.

What does a digital forensics investigation normally cost in the UK?

Each case is costed on its own particulars. The scoping call is free; after it comes a single written quote covering imaging, analysis and reporting, agreed before any work starts. No hourly billing.

Do you handle mobile phones?

No. Computers, drives, storage media and CCTV recorders are what we take on; handsets and tablets are not. Where a phone turns out to be central to the case, we say so and put you in touch with a specialist.

Do you hold accreditation?

We are an independent lab: no UKAS accreditation, no ISO certification, and we say so openly — the reports state it too, as the rules require. What we offer instead is a method open to inspection: imaging behind a write blocker, hashes checked, every step documented, reports drafted to CPR 35 or CrimPR 19.

Evidence has a short life. Move now.

Loop recording writes over the old footage, and deadlines won't wait. Open a case now — the first look costs nothing and stays confidential.

0800 6890668