Home // FORENSIC UNITS // DIGITAL EVIDENCE

Forensic Data Recovery

An in-house laboratory that recovers data from media with logical, electronic or physical damage and delivers, along with the files, the chain of custody that sustains them as evidence in court.

The problem

Recovering the file is only half the problem

The hard drive that was dropped held the e-mails proving the fraud. The broken phone contains the decisive conversations in the employment claim. The formatted server held the accounts of a company in a shareholder dispute. In those scenarios, the lost data is not a file: it is evidence.

And when the lost data is evidence, the way it is recovered decides whether it will be accepted or challenged. Recovery gives back the file; only a forensic method gives back the file together with the documentation that supports it against the opposing party.

The Brazilian Superior Court of Justice (STJ) has been consolidating the standard: digital evidence without hash values, without sealing and without documented handling is vulnerable evidence. In AgRg in HC 828,054/RN (5th Panel, 2024) and in RHC 205,441/GO (6th Panel, 2025), the absence of those precautions led to inadmissibility and to nullity.

The same logic reaches recovered data: a hard drive sent to an ordinary recovery firm comes back with the files, but with no acquisition hash, no seal and no record of who handled the media. The opposing party challenges it, and the evidence falls.

From damaged media to evidence: recovery with chain of custody
The forensic difference

What changes when the recovery is forensic

The difference lies not only in the recovery tool: it lies in everything that happens before, during and after it. The procedure includes, in every case:

  • Documented receipt: photographs of the original condition of the media, recording of serial number and IMEI, a numbered seal and a chain of custody record.
  • Bit-for-bit forensic imaging before any intervention, with a write blocker wherever the media allows it.
  • SHA-256 cryptographic hashing of the acquisition, verifiable by either party at any time.
  • Work carried out exclusively on the copy: the original media is preserved and returned sealed once again.
  • Documented physical interventions: where imaging is possible only after repair, every stage is photographed, identifying the components replaced and the donor unit used (make, model and serial number).
  • Chain of custody record: who handled the item, when, what and why, from receipt to return, under CPP, arts. 158-A to 158-F (Brazilian Code of Criminal Procedure) and ABNT NBR ISO/IEC 27037.
  • Delivery accompanied by a technical report or an expert report fit to support court proceedings.
Replacement of read heads on an open disk inside the clean chamber, with a donor unit
DATA LAB · Clean Chamber IHead replacement · donor unit
Data Lab data recovery workstation
DATA LABRecovery workstation
Data Lab clean chamber, with a bench of precision tools
DATA LABClean Chamber II
Facilities

An in-house laboratory, a dedicated facility

Forensic recovery demands an environment and equipment that cannot be improvised. The laboratory brings together:

Environment

Laminar flow cabinet

Media are opened in an environment of filtered, controlled air. A magnetic platter exposed to ordinary dust particles may suffer irreversible damage; outside that environment, opening a hard drive is a risk, not a procedure.

Workstations

Dedicated recovery workstations

Separate benches for diagnosis, physical intervention and acquisition, with specialised hardware able to read unstable disks and to access the firmware of the media.

Donors

Bank of donor and recipient drives

A stock of compatible drives for component transplants: logic boards, motors and head assemblies. Every donor used is identified and recorded in the report.

Acquisition

Forensic imaging tools

Duplicators and write blockers to generate the bit-for-bit image with hash values, plus firmware access tools for media that do not respond through conventional means.

Scenarios by type of damage

Three families of damage, three recovery routes

Logical

Logical damage

Accidental or deliberate deletion, formatting, file system corruption, ransomware and firmware failure. Recovery takes place on the forensic image: evidence of when and how the data was deleted is often worth as much as the data itself.

Electronic

Electronic damage

A logic board burnt out by a power surge or outage, damaged connectors. PCB transplant with ROM transfer and firmware adaptation, with the donor component documented.

Physical

Physical damage

Crashed read heads, a seized motor, compromised platters. Replacement of the head assembly with a compatible donor, inside a laminar flow cabinet; opening the drive outside that environment contaminates the platters and can make the loss irreversible.

Scenarios by type of media

Every medium fails in its own way

HDD

Hard disk drives

Internal, external and laptop drives: mechanical and firmware failures and bad sectors. Imaging with specialised hardware that reads unstable disks without pushing them further than necessary.

SSD · NVMe

SSD, NVMe and M.2

Controller failure, access in technical mode and chip-off. Frankly: on healthy SSDs, the TRIM command physically erases the cells shortly after deletion, and deleted data often does not come back. SSDs with a failed controller, on the other hand, may preserve data that TRIM never got to process.

Flash

USB sticks and memory cards

Direct reading of the NAND chips (chip-off) and access to monolithic media via pinout, where the controller stops responding.

RAID · NAS

RAID, NAS, servers and VMs

Rebuilding of arrays 0, 1, 5, 6 and 10, with each member imaged individually before any reassembly: no attempt is made on the original disks.

Mobile

Damaged mobile phones

Repair of the device to make forensic extraction possible, where the content is the object of the examination: the device is brought back to life so that the evidence can be acquired with method.

Legacy

Legacy media

Tapes and optical media, on request: relevant in probate matters, old corporate archives and long-term retention obligations.

How it works

The process in seven stages

01 · TriageInitial contact, description of the incident and immediate guidance: what not to do with the media until it is sent in
02 · ReceiptPhotographs of the original condition, recording of identifiers, a numbered seal and the opening of the chain of custody record
03 · DiagnosisTechnical assessment of the damage scenario and a quotation; no work is carried out before approval
04 · AcquisitionBit-for-bit forensic imaging with SHA-256 hashing; in cases of physical damage, a documented intervention followed by imaging
05 · RecoveryAll recovery work is carried out on the copy; the original remains preserved
06 · VerificationIntegrity check and a list of what was recovered, what was not and why
07 · DeliveryData on new media, a technical report or expert report, and return of the original media, sealed
The warning

When ordinary recovery destroys evidential value

Real situations, seen frequently on media that reach the laboratory after passing through other hands:

The standard is not theoretical. In AgRg in HC 828,054/RN (5th Panel, 2024), screenshots taken directly on the seized phone, with no extraction tool, no hash and no documentation, resulted in inadmissible evidence. In RHC 205,441/GO (6th Panel, 2025), a device with no seal and no record of its IMEI led to nullity. In HC 943,895/PR (5th Panel, 2025), access to the phone before the forensic examination rendered the evidence unusable. The same rigour that voids badly handled evidence is what threatens data recovered without method.

Use cases

Where forensic recovery decides cases

Employment

Equipment returned wiped clean

E-mails and files deleted by a former employee; the laptop handed back empty that must tell what it contained, when it was emptied and by whom.

Corporate

Shareholder and business disputes

Unfair competition, diversion of clients and data sabotage; the internal enquiry documented from the outset, in case it becomes litigation.

Criminal

A trace on damaged media

The damaged media holding the trace at the heart of the case, recovered with a defensible method; party-appointed expert work for the prosecution or the defence.

Probate

Digital estates

Access to documents, accounts, crypto assets and photographs of the deceased, with proven legitimacy and documentation that forestalls disputes between heirs.

Insurance

Claims and insurers

Technical demonstration of the content lost in a claim or in a coverage dispute, with a list of files and a report that supports the claim.

Failed backup

The backup that failed at the decisive moment

The backup routine existed, but the restored file came back corrupted or incomplete precisely when the proceedings required it. Forensic recovery goes after the data at source and returns it with the documentation that supports its use as evidence.

The comparison

An ordinary recovery firm and a forensic laboratory, side by side

Ordinary recovery firm
ObjectiveGive the files back
First actRead attempts made directly on the original
IntegrityNo control: no acquisition hash
HandlingNot recorded
InterventionNo record of what was opened or replaced
DeliveryA folder of files
Performed byA laboratory technician
In courtOpen to challenge: chain of custody non-existent
Forensic laboratory
ObjectiveGive the files back with evidential value
First actPhotographs, sealing and bit-for-bit forensic imaging
IntegritySHA-256 hash verifiable by either party
HandlingEvery act recorded by name (CPP, arts. 158-A to 158-F)
InterventionDonors identified and every stage photographed
DeliveryFiles, a technical report or expert report, and the original media returned sealed
Performed byA forensic expert who also serves as court-appointed expert and party-appointed expert
In courtDefensible: a repeatable, documented method

In short: ordinary recovery answers the question "where are my files?". Forensic recovery also answers the next one: "how do you prove these are the ones?".

Stated limitations

What forensic recovery does not promise

Technical honesty is part of the method. Before any engagement, it is worth knowing that:

Frequently asked questions on this practice
What is the difference between ordinary and forensic data recovery?
Ordinary recovery aims to give the files back; forensic recovery gives the files back with the documentation that sustains them as evidence: photographs at receipt, sealing, bit-for-bit imaging before any intervention, SHA-256 hashing, a record of every act of handling and a technical report. When the data matters to a case, that difference decides whether the evidence stands.
Is all data recoverable?
No. Platters scored in the data area, memory chips physically destroyed and actual overwriting mean permanent loss. The diagnosis identifies the scenario and states frankly what is feasible before any charge for recovery is made.
What is the chain of custody and why does it matter to my case?
It is the traceable record of everything that happened to the trace: who handled it, when, what and why, from receipt to disposal. It is set out in the CPP (arts. 158-A to 158-F, inserted by Law 13,964/2019) and in ABNT NBR ISO/IEC 27037. Without it, the opposing party challenges the evidence alleging tampering, and the STJ has been accepting that argument in recent decisions.
What is a hash and how does it show the file was not altered?
A hash is a mathematical fingerprint of the data: any change to a single bit produces a completely different value. The SHA-256 hash calculated at acquisition allows either party, at any time, to check whether the copy examined is identical to what was acquired. It is the integrity criterion the STJ has settled on for digital evidence.
My hard drive has already been through another recovery company. Can the data still be used as evidence?
In many cases, yes. The chain of custody is certified from receipt at the laboratory onwards, with the earlier history recorded as a qualification in the report. The evidential value is more exposed to challenge than it would have been had the forensic method started earlier, but documentation from that point on preserves what can still be preserved.
Do you open the hard drive? Does that not damage it?
Opening, where necessary, takes place inside a laminar flow cabinet, with filtered and controlled air, using compatible donor components; every stage is photographed and recorded. The real risk lies in opening the drive outside that environment: ordinary dust particles on the platters can make the loss irreversible.
How much does it cost and how long does it take?
It depends on the scenario, and only the diagnosis defines it: a logical recovery, a head assembly transplant and a chip-off are pieces of work of very different complexity. The quotation is presented after the diagnosis and before any work begins; nothing is done without approval.
What if the media is encrypted (BitLocker, FileVault, a locked phone)?
Physical recovery may succeed and the content still remain unreadable without the legitimate key or password. With credentials supplied by the owner or by whoever holds legitimate authority, the content is decrypted and documented as normal. The hardware encryption of some SSDs, however, may rule out techniques such as chip-off; the diagnosis clarifies each case.

See also

Computer Forensics →   Expert Reports and Opinions →   Forensic Laboratory →

The data your case lost can still become evidence

The fewer do-it-yourself attempts the media suffers, the greater the chance of intact recovery. The diagnosis defines feasibility, the damage scenario and the quotation before any work begins.

Request a diagnosis
Representative cases

The level of work you are engaging

Before deciding, it is worth seeing what has already come through this laboratory: cases described without identifying the parties, in the format of challenge, method and result.

See all representative cases →

The technical evidence your case requires. The authority courts respect.

Initial feasibility consultation at no cost. Reply within 24h on business days.
Request an Examination