An in-house laboratory that recovers data from media with logical, electronic or physical damage and delivers, along with the files, the chain of custody that sustains them as evidence in court.
The hard drive that was dropped held the e-mails proving the fraud. The broken phone contains the decisive conversations in the employment claim. The formatted server held the accounts of a company in a shareholder dispute. In those scenarios, the lost data is not a file: it is evidence.
And when the lost data is evidence, the way it is recovered decides whether it will be accepted or challenged. Recovery gives back the file; only a forensic method gives back the file together with the documentation that supports it against the opposing party.
The Brazilian Superior Court of Justice (STJ) has been consolidating the standard: digital evidence without hash values, without sealing and without documented handling is vulnerable evidence. In AgRg in HC 828,054/RN (5th Panel, 2024) and in RHC 205,441/GO (6th Panel, 2025), the absence of those precautions led to inadmissibility and to nullity.
The same logic reaches recovered data: a hard drive sent to an ordinary recovery firm comes back with the files, but with no acquisition hash, no seal and no record of who handled the media. The opposing party challenges it, and the evidence falls.

The difference lies not only in the recovery tool: it lies in everything that happens before, during and after it. The procedure includes, in every case:
Forensic recovery demands an environment and equipment that cannot be improvised. The laboratory brings together:
Media are opened in an environment of filtered, controlled air. A magnetic platter exposed to ordinary dust particles may suffer irreversible damage; outside that environment, opening a hard drive is a risk, not a procedure.
Separate benches for diagnosis, physical intervention and acquisition, with specialised hardware able to read unstable disks and to access the firmware of the media.
A stock of compatible drives for component transplants: logic boards, motors and head assemblies. Every donor used is identified and recorded in the report.
Duplicators and write blockers to generate the bit-for-bit image with hash values, plus firmware access tools for media that do not respond through conventional means.
Accidental or deliberate deletion, formatting, file system corruption, ransomware and firmware failure. Recovery takes place on the forensic image: evidence of when and how the data was deleted is often worth as much as the data itself.
A logic board burnt out by a power surge or outage, damaged connectors. PCB transplant with ROM transfer and firmware adaptation, with the donor component documented.
Crashed read heads, a seized motor, compromised platters. Replacement of the head assembly with a compatible donor, inside a laminar flow cabinet; opening the drive outside that environment contaminates the platters and can make the loss irreversible.
Internal, external and laptop drives: mechanical and firmware failures and bad sectors. Imaging with specialised hardware that reads unstable disks without pushing them further than necessary.
Controller failure, access in technical mode and chip-off. Frankly: on healthy SSDs, the TRIM command physically erases the cells shortly after deletion, and deleted data often does not come back. SSDs with a failed controller, on the other hand, may preserve data that TRIM never got to process.
Direct reading of the NAND chips (chip-off) and access to monolithic media via pinout, where the controller stops responding.
Rebuilding of arrays 0, 1, 5, 6 and 10, with each member imaged individually before any reassembly: no attempt is made on the original disks.
Repair of the device to make forensic extraction possible, where the content is the object of the examination: the device is brought back to life so that the evidence can be acquired with method.
Tapes and optical media, on request: relevant in probate matters, old corporate archives and long-term retention obligations.
Real situations, seen frequently on media that reach the laboratory after passing through other hands:
The standard is not theoretical. In AgRg in HC 828,054/RN (5th Panel, 2024), screenshots taken directly on the seized phone, with no extraction tool, no hash and no documentation, resulted in inadmissible evidence. In RHC 205,441/GO (6th Panel, 2025), a device with no seal and no record of its IMEI led to nullity. In HC 943,895/PR (5th Panel, 2025), access to the phone before the forensic examination rendered the evidence unusable. The same rigour that voids badly handled evidence is what threatens data recovered without method.
E-mails and files deleted by a former employee; the laptop handed back empty that must tell what it contained, when it was emptied and by whom.
Unfair competition, diversion of clients and data sabotage; the internal enquiry documented from the outset, in case it becomes litigation.
The damaged media holding the trace at the heart of the case, recovered with a defensible method; party-appointed expert work for the prosecution or the defence.
Access to documents, accounts, crypto assets and photographs of the deceased, with proven legitimacy and documentation that forestalls disputes between heirs.
Technical demonstration of the content lost in a claim or in a coverage dispute, with a list of files and a report that supports the claim.
The backup routine existed, but the restored file came back corrupted or incomplete precisely when the proceedings required it. Forensic recovery goes after the data at source and returns it with the documentation that supports its use as evidence.
In short: ordinary recovery answers the question "where are my files?". Forensic recovery also answers the next one: "how do you prove these are the ones?".
Technical honesty is part of the method. Before any engagement, it is worth knowing that:
See also
Computer Forensics → Expert Reports and Opinions → Forensic Laboratory →
Before deciding, it is worth seeing what has already come through this laboratory: cases described without identifying the parties, in the format of challenge, method and result.
The intruder's control channel was written into smart contracts. The examination decoded what he had deleted and handed the authorities concrete routes to identification.
See the case Negative proofThe official examination had concluded that he took part. The re-examination showed the links were false positives, and the accused person was cleared.
See the case