Diagnostic assessment
Check that the media are assessed first
Choosing a data recovery laboratory means choosing how technical risk will be assessed. Before discussing an outcome, the provider should identify the storage medium, symptoms, previous actions and priority data. A clicking hard drive, an absent SSD, a formatted memory card and a RAID that has already been rebuilt do not present the same risks or require the same sequence of work.
The initial assessment should distinguish at least physical, electronic, firmware, logical and application-level causes. The context also matters: impact, liquid, power loss, deletion, encryption, a multi-drive system, an available backup or an earlier repair attempt. This initial record helps prevent a generic procedure being applied to a fragile original.
Questions that reveal the method
| Question for the provider | Evidence-based answer | Warning sign |
|---|---|---|
| How will the original be protected? | Stabilise where justified, then acquire to a separate technical image whenever possible | Direct repair without an image or activity record |
| When is my approval required? | Define scope and cost before any invasive or irreversible step | Intervention without a clear approval boundary |
| How will the result be checked? | File list, representative samples, priorities and stated limitations | Only a file count or number of gigabytes |
| Who can access the data? | Explain restricted roles, transfer and retention | Confidentiality presented only as a slogan |
| What happens if recovery is partial? | Define acceptance criteria, cost and delivery in advance | Undefined all-or-nothing wording |
The professional data recovery process sets out the technical stages. When comparing providers, also establish whether those stages are explained, whether consent is recorded and whether the result can be evaluated before final acceptance. A capable laboratory must recognise the risks of each media family rather than describing every case as the same generic laboratory procedure.
Diagnostic assessment
Ask for a method you can understand
A sound method can be technically complex while remaining clear at each decision. The client should understand the sequence: receipt, inventory, initial evaluation, proposal, approval, acquisition, reconstruction, validation and delivery. Technical language must not obscure what will happen to the source.
Separate acquisition from analysis
Where the condition allows, a sector-level image protects the original from repeated analysis. A mechanically damaged hard drive may need stabilisation or a justified internal procedure before acquisition. For a RAID, every member, position and available item of metadata should be retained before a virtual reconstruction begins. For an SSD, controller behaviour, NAND architecture and encryption determine what is technically possible.
A cleanroom is therefore not a universal quality mark. A controlled particulate environment supports certain internal procedures on mechanical hard drives. It does not repair a damaged file system, reconstruct flash translation or determine the correct order of a RAID. The scope of ISO 5 Class 100 cleanroom data recovery should be described precisely and justified by the findings.
The quotation should state:
- What the initial technical assessment covers and what it will report;
- Which actions are authorised and which require further approval;
- How a complete, partial or unusable outcome is defined;
- How recovered data will be delivered;
- What costs apply after assessment, partial recovery or cancellation;
- How long the original, technical images and output data will be retained.
Two prices are not comparable without this scope. A charge that includes controlled acquisition, reconstruction and validation is different from one covering only bulk extraction. A data recovery quotation should describe the decisions and limits, not merely list equipment or repeat a headline capacity.
The presentation of the assessment also matters. A file listing, carefully limited sample or integrity result can support an informed decision. The statement “the data are recoverable” says nothing about the required period, folder structure, priority files or actual usability.
The intervention boundary is decisive. The laboratory should explain which action is reversible, which one places the original at greater risk and when your explicit approval becomes necessary.
Diagnostic assessment
Check confidentiality and traceability
Storage media often contain far more than the files requested: personal records, client data, trade secrets, legal archives or credentials. Confidentiality must be expressed through concrete handling controls without requiring the client to disclose every item of content in advance.
From the parcel to deletion of working copies
A traceable case links one reference to the media, detached components, technical images and delivery. Serial numbers and original bay positions reduce the risk of confusing RAID members or visually identical cards. For sensitive cases, clearly limited access roles and a defined validation scope reduce unnecessary exposure.
Clarify at least these points before authorisation:
- Identification on receipt and verification of all parts;
- People or roles permitted to access the data;
- Protection of technical images, passwords and encryption keys;
- Encryption and transport of the delivered result;
- Retention period after the case closes;
- Return, secure deletion or agreed destruction.
An organisation may add an authorised contact, encrypted delivery, a confidentiality agreement, evidential preservation or exclusions from content sampling. A private client should receive the same clarity for photographs, documents and private communications.
Traceability does not mean curiosity. Validation can be limited to priority files, formats and integrity. Unrelated content need not be examined to prove that the agreed result is usable.
FileVault or BitLocker recovery keys, passwords and application credentials should be supplied only where technically necessary, through an agreed channel. Their use and retention belong within the same controls. If a lawfully required key is unavailable, that is a technical limit rather than a reason for a vague promise to bypass encryption.
Diagnostic assessment
Reject promises made before assessment
No provider can know the condition of platter surfaces, NAND cells, overwritten blocks or encryption material before examination. An overall success rate says little about an individual case. A promise of complete recovery, a fixed completion time or one particular file before assessment is marketing language, not technical evidence.
Ask for a qualified finding
The assessment should report observable facts: stability, ability to acquire, areas read, structures recognised, priority data found and obstacles recorded. The finding may be favourable, partial, negative or conditional on an intervention that still requires approval.
Useful limits may identify:
- An unreadable region of a platter surface;
- A NAND component that cannot be acquired coherently;
- Blocks already overwritten;
- An incomplete snapshot chain;
- A missing encryption key;
- A file that exists but fails structural validation.
A percentage without a defined scope is not a decision tool. “90% recovered” has little value if the essential database is within the remaining 10%. Assessment should be tied to agreed files, periods and integrity criteria.
Advice that shifts a technical risk back to the client is another warning sign: opening a hard drive, initialising a RAID, accepting a format prompt or running repeated full scans before sending the media. Useful guidance preserves the current state until the fault has been assessed.
Professional commitments are still possible. A laboratory can commit to its method, reporting, prior approval, confidentiality and transparent description of the result. It cannot recreate overwritten or physically destroyed data.
Diagnostic assessment
Prepare a useful case record
A good case record reduces assumptions and unnecessary reads. It does not need to be a technical report; an honest chronology, precise symptoms and clear priorities are usually enough to begin.
Minimum information for handover
Record:
- Device, media type, model and capacity;
- Date and event associated with the first fault;
- Messages, unusual sounds, heat or disconnections;
- Restarts, repair attempts, copies and replaced components;
- Priority files, periods, folders or services;
- Available backups and alternative sources;
- Known encryption and legitimately available credentials.
Keep related components: the enclosure and power supply of an external drive, every member removed from a RAID, the controller card, source device or specialist adaptor. Whether they should be sent depends on the intake instructions, but they should not be discarded before assessment.
Photograph and label components before transport. A mechanical hard drive needs protection from impact and electrostatic discharge, but must not be opened or cleaned. Wet, chemically contaminated or badly damaged media require case-specific packing instructions rather than improvised drying.
The final decision should compare method, approval boundaries, confidentiality, cost framework, stated limits and delivery. A suitable data recovery laboratory does not promise files before assessment; it makes every decision and result verifiable. Datastrophe places diagnostic assessment and protection of the original ahead of any claim about the recoverable content.
Diagnostic assessment
Primary Technical References And Limits
Reference scope — a data recovery laboratory: For choose a data recovery laboratory, the primary references used are NIST SP 800-86. Physical evidence — a data recovery laboratory: They define the relevant preservation, storage or validation concepts, but they cannot establish the exact physical condition, controller state, key availability or business consistency of the device received. Controller evidence — a data recovery laboratory: Those points require measurements on the original set and verification on copies.
Diagnostic assessment
Arrange A Controlled Assessment
Complete set — a data recovery laboratory: For a technical examination of choose a data recovery laboratory, provide the complete device or storage set, its associated power and interface parts, the symptom timeline and the priority records. Incident history — a data recovery laboratory: Keep member order, labels and authorised credentials separate from the parcel paperwork; do not restart the source merely to obtain a new screenshot.
Laboratory responsibility — a data recovery laboratory: Datastrophe performs the diagnosis, integrity checks and recovery directly in its own laboratory with its own team. Free assessment — a data recovery laboratory: Diagnosis and the quotation are free. Transport boundary — a data recovery laboratory: Private collection and return is included; the carrier moves only the sealed parcel and neither accesses nor processes its data.
Controlled list — a data recovery laboratory: Before any payment, the client receives the proposed price and a checked list. Verification classes — a data recovery laboratory: Each item is classified, in order, as recoverable_verified, partial, detected_unverified or unrecoverable. Payment trigger — a data recovery laboratory: Only recoverable_verified items whose contents were checked and found usable are presented as recoverable. No-result rule — a data recovery laboratory: Payment is due only after the client accepts both the list and the price.
No-result rule — a data recovery laboratory: If no usable data is verified, recovery fails, or the client declines the list or price, no standard fee is payable. Rare-part exception — a data recovery laboratory: The only exception is a rare, costly and non-refundable part, which may be ordered only after a separate, explicit and priced proposal has been accepted.