Taking instructions now — the first conversation is freeExhibits posted in from anywhere in the UK, or handed in at ten drop-off pointsQuicker still, give us a ring:0800 6890668
FDRForensic Data Recovery 0800 6890668 Price my job
FDR / What we examine / Mobile phones: not examined

Mobile phones · not examined · specialist field · computers and drives · what we do examine

Mobile phones: not examined. We are candid about our scope: phone forensics is a specialist field of its own, and it is not what this service does.

We are often asked whether we examine mobile phones, and the honest answer is no. Phone forensics is a distinct, specialist field, with its own tools, its own licensing and its own training, quite separate from the examination of computers and drives, and rather than take a phone we are not equipped to examine to the right standard, we say plainly that it is not part of this service. What we do examine is computers, hard drives, SSDs, USB sticks and memory cards, NAS and RAID, and CCTV, DVR and dashcam recorders, to a full evidential standard. If your matter needs a phone examined, we would rather tell you that up front, so you can go to a provider equipped for it, than take work we cannot do properly.

Owner-only, authority requiredFree first conversationStandard report £800 + VATImaged first, never the original

Rather talk it through? An engineer answers the bench line
0800 6890668

Before anything else: stop using the device, and do not let anyone have a look at it. Every time a computer is switched on and used, the very artefacts an examination relies on, the timeline, the recently-opened lists, the deleted-file space, are overwritten a little more. Do not reinstall, do not run recovery software, do not let IT open it to check, and keep it powered off. Preserve it as it is, record who has held it, and send it with the authority documents we ask for. If proceedings are contemplated, the duty to preserve evidence has already begun.

Why not, and what we examine instead.

Mobile phone forensics is a field of its own. Modern phones are heavily encrypted, their data is organised quite differently from a computer's, and extracting it to an evidential standard requires specialist tools, the major mobile forensic suites, that carry their own licensing and training, and that are a different discipline from computer examination. Doing it properly is a specialism, and doing it improperly risks both the evidence and the law.

So rather than stretch beyond our competence, we are clear about our scope. We examine computers and the storage in and around them: laptops and desktops running Windows, macOS or Linux; hard disks, SSDs and NVMe drives; USB sticks and memory cards; NAS and RAID; and CCTV, DVR and dashcam recorders. All of these we examine to a full evidential standard, imaged behind a write blocker and reported properly.

If your matter genuinely needs a phone examined, we will tell you so at the first conversation and suggest you instruct a provider equipped for mobile work. Being honest about what we do not do is part of being trusted with what we do.

What to know for this exhibit.

Phone forensics is a specialist fieldModern phones are heavily encrypted and organised differently from computers, and extracting their data to an evidential standard needs specialist tools, licensing and training, a discipline of its own.
We say so plainlyRather than take a phone we are not equipped to examine to the right standard, we tell you up front that it is not part of this service, so you can go to a provider equipped for it.
What we do examineComputers running Windows, macOS or Linux; hard disks, SSDs and NVMe; USB sticks and memory cards; NAS and RAID; and CCTV, DVR and dashcam recorders, all to a full evidential standard.
Honesty about scope is part of trustBeing clear about what we do not do is part of being trusted with what we do, and it is better for you than taking work we cannot do properly.

From the exhibit arriving to the report.

Work we have closed →
01

The first conversation, and the authority check Free

Tell us the situation, who owns the device, and what you need to know. We tell you whether it is a job we can take on, what authority we will need, and whether the standard report answers your questions or an expert report is called for. That conversation is free, and some enquiries end there, because we will not take work we cannot lawfully or honestly do.

FreeOwner-only; authority established firstThe honest answer about what is possible
02

Imaging behind a write blocker, and the hashes

When the exhibit arrives, your authority is checked, the device is logged and photographed, and the drive is connected through a hardware write blocker and imaged bit for bit. MD5 and SHA-256 hashes of the source and the image are computed and verified, so the copy is provably identical. Nothing is examined on the original; every later step is done on the verified image.

Bit-for-bit, behind a write blockerMD5 and SHA-256, verifiedThe original never altered
03

The examination, on the image

The image is examined for the artefacts your questions turn on: USB device history, files opened from removable media, cloud and webmail activity, deleted files and the Recycle Bin, the USN journal, program execution, email, document metadata, shadow copies, and a timeline. Findings that matter are confirmed in a second tool. The work is scoped to what you asked; material outside the scope is not reproduced.

Scoped to your questionsConfirmed in a second toolPrivate material filtered out
04

The report

The standard forensic report sets out the exhibit and its condition, the integrity record, the tools and method, and the findings by category, with a timeline, the limitations, and factual conclusions, as a self-contained report with its chain-of-custody and case-log reports. It is written in plain terms, keeps fact separate from any comment, and is suitable for internal decisions, HR processes, negotiations and solicitors. Where you need opinion evidence for court, an expert report is quoted.

Factual, tool-generated, self-containedChain-of-custody and case-log reports5–10 working days

Before you send it

  • Do not send a phone; it will not be examined. Send the computers, drives, cards and recorders in your matter.
  • Tell us if a phone is central; we will point you to a provider equipped for mobile work.
  • Preserve any phone as it is in the meantime, and do not let anyone attempt to examine it improperly.

Phone forensics is a specialism with its own tools and training; we are candid that it is not part of this service, and say what we do examine instead.

What helps, and what harms.

Do this much first

  • Send computers, drives, cards and recorders, not phones
  • Preserve any device in your matter as it is
  • Tell us if a phone is central, for a referral
  • Gather your proof of ownership or authority

What sets us back

  • Sending us a mobile phone; it will not be examined
  • Assuming we do phone work; we are candid that we do not
  • Letting anyone examine a phone improperly
  • Carrying on using the devices in your matter
We examine devices only for the people and organisations with lawful authority over them. Before any work begins we ask for proof that the device is yours, or documented authority to have it examined: proof of ownership, a director's or HR letter for a company device with the lawful basis, a solicitor's instruction, a court order, or an executor's grant. It is a condition of the work, not a formality, and it is what keeps the examination on the right side of the Computer Misuse Act 1990. We will not access another adult's device or accounts without their consent or a court order, we will not install monitoring software or bypass anyone's security, and we do not undertake covert surveillance. A device with no proof of authority is returned unexamined.

Questions answered before you instruct.

Do you examine mobile phones?

No. Mobile phone forensics is a distinct, specialist field with its own tools, licensing and training, separate from computer examination, and it is not part of this service. Rather than take a phone we are not equipped to examine to the right standard, we say so plainly.

Why not, when you do computers?

Because they are different disciplines. Modern phones are heavily encrypted and organised quite differently from computers, and extracting their data to an evidential standard needs specialist mobile tools and training that are a specialism of their own. Doing it improperly risks the evidence and the law, so we stay within our competence.

What should I do if my matter needs a phone examined?

Tell us at the first conversation, and we will suggest you instruct a provider equipped for mobile forensics. For the computers, drives, memory cards and recorders in your matter, we can help to a full evidential standard.

What do you examine?

Laptops and desktops running Windows, macOS or Linux; hard disks, SSDs and NVMe drives; USB sticks and memory cards; NAS and RAID; and CCTV, DVR and dashcam recorders. All imaged behind a write blocker and reported to a full evidential standard.

What does a computer examination cost?

The standard forensic report for a one-disk computer is £800 + VAT. The first conversation is free, and if your matter needs a phone, we will tell you so honestly.

Preserve it, and let us image it first.

The first conversation is free. Tell us the exhibit and the situation, and who owns it, and we will tell you what can be examined, what authority we need, and whether we can take it on. Until then, stop using it and preserve it as it is.

0800 6890668