Open, and work is coming in · weekdays, 9am–5:30pm Faster by phone: 0800 6890668
PDR Plymouth Data Recovery 0800 6890668 Get a price
PDR / Legal and insurance work / Examination of exhibits, and court reports

Plymouth evidence work · for solicitors, HR and loss adjusters

Digital forensics in Plymouth. Nobody powers it up, which is what makes the findings stand.

In Plymouth as anywhere, most of the harm is done inside the first hour, by somebody meaning well. The machine gets switched on for a look, folders are opened, and timestamps move where nothing will put them back. So a hardware write blocker goes on first, and the image is taken before one file is opened. The continuity log is typed at the bench as the job runs, not assembled from memory a week later. The report is written expecting another expert to lean on it. Independent, discreet about who instructed us, and plain about where the evidence stops telling you anything.

Reports that meet what CPR Part 35 asks Every handover noted Impartial and private

A quiet word first?
0800 6890668

Four forensic principles, always.

1 — The exhibit is left unalteredNo action of ours may change what sits on media a court could later rely on. Blocker first, image second, and no file is opened before both.
2 — Competence where neededWhere the original has to be handled directly, whoever does that must be competent to, and must be able to account in court for what the handling changed.
3 — A record of each stepAn audit trail runs through everything done to an exhibit, detailed enough for an outsider to repeat those steps and land on the same result.
4 — Someone answers for itThe person running the case answers for it, these four principles included, from the first call to the day the report leaves.

What comes through here.

Not on this list? Call us →
What shows upWhat examination showsWhat goes to you
The laptop the whole thing hinges onWrite-blocked, imaged, and worked on the copy — artefacts, documents, and what happened in what orderA plain-English answer, in writing
An employee gone, and files gone with themEvery USB device connected, uploads to webmail or cloud accounts, deletions and wipes, all of it datedOne document HR and the solicitor can both use
Deleted files the case cannot do withoutProof they existed, when they were removed and what came next — lifted with continuity intactThe files back, dated, and the route we took
A locked volume, and the authority to open itPassware is set on it, once authority is shown and a key is actually reachableThe contents, and an account of how it opened
A dispute heading for a hearingIdentical bench work, then written to whichever rules govern it — CPR Part 35, or CrimPR Part 19A report built to the form required
Footage sitting on a CCTV recorderLifted off the disk with continuity held — our CCTV pages cover this in fullFootage that plays, with the paperwork behind it
Sending it in: the intake lab takes tracked, insured post, and we pay for the journey home. Ring us before the box goes if you want the packing talked through with an engineer. There is more on the contact page.

Each stage, in turn.

Every job written up →
01

A call in confidence first, then the price in writing Free

Ring us and say as much or as little as you like; the call itself is not charged for. What it has to settle is the shape of the matter — what took place, which machines and accounts it reaches, and the question the evidence must answer. That is the scope. One written figure follows from it, and you have that before anything is opened.

Kept in confidenceA single written figureThe question to be answered
02

A copy before any repair

Nothing is read at the start. The blocker goes in line, an image is taken, and looking comes after that. The device is an exhibit in itself, not a box with files inside, so the work happens on the copy and the original goes back in its bag.

Blocked, then copiedNothing written to it
03

The work happens on the copy

From there on, the image is what is examined. OSForensics is one of the tools used: what artefacts the system left behind, which files were opened and when, what was deleted, and in what order. The notes are typed while it goes on, never reconstructed later.

OSForensics against the copyNotes made as work runs
04

A report that reads plainly

Your question is answered at the top, in ordinary words, with the technical workings underneath for anybody who wants to check them. A finding that helps neither party goes in as well, and stays in.

The answer at the topThe workings beneath
05

Every exhibit, hash and log

Anything the other side cannot check is worth arguing about. So the bundle is built to be checked: the exhibit references, the images each finding was read from, every handover with a date on it, the hashes, and the notes written while the work was going on. Their own examiner can repeat the work and land in the same place.

Findings, and the exhibits behind themHashes kept, each move recordedAnyone can retrace it

What the work keeps showing

  • The court is owed the first duty — ahead of whoever instructed us, and ahead of the fee note. What the examination turns up is what the report says.
  • The Forensic Science Regulator's statutory Code — enforceable since 2 October 2023 — covers forensic science relied on in criminal proceedings in England and Wales. Civil claims, insurance losses and employment matters fall outside that regime, and at the outset you are told which of those your instruction is.
  • Handsets are somebody else's work — a phone gone over by a bench without the right kit is worse off than one left alone, so it goes to a bench set up for them.
  • It stays inside this room — a job carries a case number instead of anyone's name, and the findings reach the party who instructed us and nobody besides.

Why take the copy early, and take it yourself: a computer still in daily use is not the same computer a fortnight on. Windows writes constantly, space holding deleted material gets handed out again, and logs wrap round. An image made on day one shows the state things were actually in; one made after a month of use shows something else. Where a dispute looks likely, copy it while the answer is still there to be found, then store the original away.

The tools on the bench.

The kitWhere it is usedWhy we keep it
X-Ways ForensicsClose work inside disk images: usage history, artefacts, timelines and deleted materialQuick, uncluttered, and a small bench does better knowing one tool thoroughly
OSForensicsIndexes an entire Windows machine, or its image, so anything on it can be searchedThe broad first sweep: registry hives, lists of recent files, every USB device ever attached
PasswareEncrypted volumes, where opening one is lawful and there is a route to the keyIt either opens or it does not. The report says which, and nothing gets dressed up
Atola Insight ForensicAcquisition behind a write block, hashed on the same runThe acquisition logs itself, so continuity begins at sector one
ACE Lab PC-3000 & Data ExtractorRepair at firmware level, when the exhibit is a failing drive as wellA disk is sometimes the exhibit and the repair job together; both trades sit in this room

What we do and don't do

  • We do: apply the four ACPO principles for digital evidence to everything that comes in, with no exceptions.
  • We do: image behind a blocker, take MD5 and SHA-256 on every copy and verify both, and hold a continuity log that would survive an outsider auditing it.
  • We do: work with documented tools other examiners recognise — the examination on OSForensics, Passware used only where decryption is lawful — aimed at the copy and never the exhibit.
  • We don't: claim UKAS accreditation, and there is no ISO certificate on the wall here — where credibility must be declared, that declaration sits on page one of the report, and on this page.
  • We don't: accept handset or tablet instructions, deal with ransomware operators, or tilt a finding towards whoever is paying.

Why put it in writing: the criminal rules require an expert to disclose anything capable of detracting from their credibility, and an accreditation that is not held qualifies. Declaring it first is not modesty — it takes away the easiest question the other side had waiting.

A job out of the casebook.

PL · PLY-2026-0521LOGGED ✓

Project files gone, and a south Devon firm certain of theft

The client came to us expecting to be shown a theft. What the evidence showed was duller than that: a sync client had been set up wrongly and had cleared the shared folder by itself. Most of what went was still there to be recovered. The finding closed the dispute, with nobody accused.

Dispute resolvedFindings back in six days

Before you seal the box.

Get these done

  • Power it down — every minute of use costs you something
  • Note who has touched it, and at what time
  • Send the leads, the charger and any passwords too
  • Call before IT starts poking about inside it

What to avoid

  • Pass it to IT to look into — every click costs traces
  • Pull the files off it yourself first
  • Accuse anyone before the evidence is secured
  • Take a missing file as proof of anything by itself

The questions callers ask most.

What does a forensic examination involve?

Three stages. A copy is taken, the copy is examined, and the findings are written up so they hold when somebody tries to take them apart. Nothing gets read until the copy exists. The notes are typed at the bench as the job runs, in enough detail for a second examiner to walk it and land in the same place.

What does digital forensics work cost in the UK?

No two instructions are alike, so there is no list to read a price off. Working out the scope is free. What follows is a single written figure covering imaging, examination and the report, agreed before anything is plugged in. The starting point is £800 + VAT. There is no hourly clock ticking.

Do you examine phones or tablets?

No. This bench takes disks, cards, PCs, Macs and the drives out of CCTV and DVR units; a handset is not on that list. Should the phone prove to be where your case actually lives, you will hear it on the call, along with the name of a lab that does handset work.

Is this lab accredited?

No — neither UKAS accreditation nor an ISO certificate, and the first page of every report states as much, since the rules oblige an expert to disclose it. What stands instead is a method anybody may inspect: acquisition made behind a hardware write block, MD5 and SHA-256 taken and checked, each step noted while it happens, and a report laid out under CPR 35 for civil work, CrimPR 19 for criminal.

The sooner it is imaged, the more it holds.

Evidence is strongest when the drive is imaged early and left alone after. Start it here and we will tell you plainly what can be shown and what cannot. The first look is free, and what you tell us goes no further.

0800 6890668