Taking instructions now — the first conversation is freeExhibits posted in from anywhere in the UK, or handed in at ten drop-off pointsQuicker still, give us a ring:0800 6890668
FDRForensic Data Recovery 0800 6890668 Price my job
FDR / What we examine / SSDs, NVMe and TRIM

SSD · NVMe · TRIM · garbage collection · deleted data · limited recovery

SSD and TRIM forensics. A solid-state drive cleans up after itself, which is good for speed and bad for recovering deleted data.

A solid-state drive, including an NVMe module, behaves very differently from a hard disk when it comes to deleted data, and the difference matters to every examination. To stay fast, an SSD uses a feature called TRIM, together with its own garbage collection, to erase the contents of deleted blocks soon after deletion, often within minutes. The result is that deleted data on an SSD is frequently unrecoverable within a short time of being deleted, even though the same file on a hard disk might be recovered months later. This is not a limit of our tools or anyone's; it is how the drive works. We are candid about it: on an SSD exhibit, the live data, the artefacts and the file-system records are examined fully, but deleted-file recovery is limited, and we say so plainly rather than promise what the drive has already erased.

Owner-only, authority requiredFree first conversationStandard report £800 + VATImaged first, never the original

Rather talk it through? An engineer answers the bench line
0800 6890668

Before anything else: stop using the device, and do not let anyone have a look at it. Every time a computer is switched on and used, the very artefacts an examination relies on, the timeline, the recently-opened lists, the deleted-file space, are overwritten a little more. Do not reinstall, do not run recovery software, do not let IT open it to check, and keep it powered off. Preserve it as it is, record who has held it, and send it with the authority documents we ask for. If proceedings are contemplated, the duty to preserve evidence has already begun.

What TRIM does, and what survives.

An SSD stores data in blocks that must be erased before they can be rewritten, and erasing is slow, so to keep writes fast the drive erases deleted blocks in advance. The operating system tells the drive which blocks are no longer needed using the TRIM command, and the drive's own garbage collection then erases them, often within minutes of a deletion. As one forensic source puts it, once TRIM has run, the deleted data is effectively gone, and the drive returns zeros for those blocks even through a write blocker.

So on an SSD, deleted-file recovery is limited, and often not possible at all for anything deleted more than a short time ago. This is a property of the drive, not of the examination; no tool can recover what the drive has already erased. We identify whether an exhibit is an SSD at the outset and tell you honestly what it means for your matter.

What an SSD examination can do is everything that does not depend on recovering deleted content: the live files, the artefacts, USB history, jump lists, the change journal, Prefetch, email, documents, and the records of deletion (the journal and Recycle Bin $I records, which show that files were deleted and when, even where the content is gone). On an SSD, those records of deletion often matter more than ever, because the content itself may not survive.

What to know for this exhibit.

TRIM erases deleted data quicklyTo stay fast, an SSD erases deleted blocks soon after deletion, often within minutes, so deleted data is frequently gone within a short time, unlike on a hard disk.
Limited deleted-file recoveryOn an SSD, recovering deleted files is limited and often not possible for anything deleted more than a short time ago. We say so honestly; it is the drive, not the tools.
The live data and artefacts are examined fullyEverything that does not depend on recovering deleted content, live files, user activity, email, documents, a timeline, is examined in full on an SSD.
Records of deletion still matterThe change journal and Recycle Bin records show that files were deleted and when, even where the content is erased, which on an SSD is often the key evidence.

From the exhibit arriving to the report.

Work we have closed →
01

The first conversation, and the authority check Free

Tell us the situation, who owns the device, and what you need to know. We tell you whether it is a job we can take on, what authority we will need, and whether the standard report answers your questions or an expert report is called for. That conversation is free, and some enquiries end there, because we will not take work we cannot lawfully or honestly do.

FreeOwner-only; authority established firstThe honest answer about what is possible
02

Imaging behind a write blocker, and the hashes

When the exhibit arrives, your authority is checked, the device is logged and photographed, and the drive is connected through a hardware write blocker and imaged bit for bit. MD5 and SHA-256 hashes of the source and the image are computed and verified, so the copy is provably identical. Nothing is examined on the original; every later step is done on the verified image.

Bit-for-bit, behind a write blockerMD5 and SHA-256, verifiedThe original never altered
03

The examination, on the image

The image is examined for the artefacts your questions turn on: USB device history, files opened from removable media, cloud and webmail activity, deleted files and the Recycle Bin, the USN journal, program execution, email, document metadata, shadow copies, and a timeline. Findings that matter are confirmed in a second tool. The work is scoped to what you asked; material outside the scope is not reproduced.

Scoped to your questionsConfirmed in a second toolPrivate material filtered out
04

The report

The standard forensic report sets out the exhibit and its condition, the integrity record, the tools and method, and the findings by category, with a timeline, the limitations, and factual conclusions, as a self-contained report with its chain-of-custody and case-log reports. It is written in plain terms, keeps fact separate from any comment, and is suitable for internal decisions, HR processes, negotiations and solicitors. Where you need opinion evidence for court, an expert report is quoted.

Factual, tool-generated, self-containedChain-of-custody and case-log reports5–10 working days

Before you send it

  • Act fast; on an SSD, TRIM erases deleted data quickly, so time matters even more than on a hard disk.
  • Do not use the drive; continued use lets garbage collection erase more, and powering it on alone can trigger it.
  • Expect records of deletion rather than deleted content; on an SSD the journal often matters more than recovery.

Once TRIM has run, deleted data on an SSD is effectively gone, and the drive returns zeros for those blocks even through a write blocker.

What helps, and what harms.

Do this much first

  • Stop using the device and keep it powered off
  • Preserve it as it is; record who has held it
  • Gather your proof of ownership or authority
  • Tell us the situation and the questions you have

What sets us back

  • Letting anyone open it to have a look
  • Reinstalling, wiping or running recovery software
  • Carrying on using the device
  • Sending us a mobile phone; they are not examined
We examine devices only for the people and organisations with lawful authority over them. Before any work begins we ask for proof that the device is yours, or documented authority to have it examined: proof of ownership, a director's or HR letter for a company device with the lawful basis, a solicitor's instruction, a court order, or an executor's grant. It is a condition of the work, not a formality, and it is what keeps the examination on the right side of the Computer Misuse Act 1990. We will not access another adult's device or accounts without their consent or a court order, we will not install monitoring software or bypass anyone's security, and we do not undertake covert surveillance. A device with no proof of authority is returned unexamined.

Questions answered before you instruct.

Can you recover deleted files from my SSD?

Often not, and we will be honest about it. An SSD's TRIM feature and garbage collection erase deleted data quickly, often within minutes, so deleted content is frequently gone. This is how the drive works, not a limit of our tools. The live data, artefacts and records of deletion are examined fully, but deleted-file recovery is limited.

Why can a hard disk recover deleted files but not an SSD?

A hard disk leaves deleted data in place until the space is reused, which can take months, so it is recoverable. An SSD actively erases deleted blocks in advance, through TRIM, to stay fast, so deleted data is erased soon after deletion. The two drive types handle deletion in opposite ways.

Is there any point examining an SSD then?

Yes, a great deal. Everything that does not depend on recovering deleted content, the live files, user activity, email, documents, a timeline, and the records showing that files were deleted and when, is examined in full. On an SSD those records of deletion are often the key evidence, because the content itself may not survive.

How do I know if my drive is an SSD?

We identify the drive type at the outset. Most laptops sold in recent years have an SSD or NVMe drive; many desktops have both an SSD and a hard disk. We tell you which your exhibit is and what it means for your matter.

What does it cost?

The standard forensic report for the one drive is £800 + VAT. The first conversation is free.

Preserve it, and let us image it first.

The first conversation is free. Tell us the exhibit and the situation, and who owns it, and we will tell you what can be examined, what authority we need, and whether we can take it on. Until then, stop using it and preserve it as it is.

0800 6890668