Taking work now — the first look is freeSSDs posted in from anywhere in the UK, or handed in at ten drop-off pointsQuicker still, give us a ring:0800 6890668
SDRSSD Data Recovery 0800 6890668 Price my job
SDR / Whatever it is doing now / Encrypted and locked

BitLocker · FileVault · VeraCrypt · TCG Opal · Apple T2

Encrypted SSDs, and why the key matters most. We recover the drive. You hold the key.

BitLocker on Windows, FileVault on a Mac, VeraCrypt, and the self-encrypting drives that follow the TCG Opal standard all mean the same thing on the bench: we can image the drive, and the files on that image are readable only with the key. For BitLocker that is the 48-digit recovery key, usually saved to the Microsoft account that set the device up or held by your employer. For FileVault it is the account password or the recovery key. For an Opal drive managed by software, it is whatever that software holds. We never attempt to break encryption, and we do not accept a job where the key is not yours to use. One drive is £300 + VAT after the free look, fixed in writing; encryption adds a step, not usually a cost, provided the key is to hand.

Free first lookOne fixed figure in writingNo data, no bill on most jobsReturn postage paid

Rather talk it through? An engineer answers the bench line
0800 6890668

Where the key lives, and why it decides the job.

Modern encryption is not a lock on the front of the drive; it is the data itself, scrambled with a key that never leaves a small secure chip or your head. BitLocker on a business laptop keeps its key in the TPM and releases it only when the machine boots normally, which is why a drive moved to another computer, or a machine with a changed BIOS, asks for the 48-digit recovery key. That key was saved somewhere when BitLocker was turned on: the Microsoft account, a file, a printout, or Active Directory if the machine belongs to an employer. Find it before you post.

FileVault on a Mac works the same way with the account password, and on T2 and Apple silicon Macs the storage is encrypted in hardware even before FileVault is turned on, with the key inside the Secure Enclave. That is why a soldered Mac's board has to work for the data to be reachable at all; there is a separate page on soldered SSDs.

Self-encrypting drives are a third case. Many Samsung, Crucial and Kingston drives encrypt everything in hardware all the time, and by default the key is on the drive and released to anyone who asks. Turn on management, through BitLocker's eDrive mode, Samsung Magician or a corporate tool, and the key is protected by a password that only that management holds. On the bench, the drive is recovered as a drive, through its own controller, and the volume unlocked on the image with whatever you supply. Without the key, what comes back is an image of noise, and we say so first.

What you see, and what it means.

Describe yours to us →
What you see The usual reason Where that leaves you
A blue BitLocker recovery screen asking for 48 digitsThe TPM will not release the key; the drive or the machine changedThe recovery key from your Microsoft account or employer
FileVault asks for a password on a Mac that will not finish bootingThe volume is intact and lockedYour account password or recovery key
A T2 or Apple silicon Mac with a dead boardKeys inside the Secure EnclaveBoard repair, or nothing
A drive with hardware encryption managed by Magician or eDriveOpal lockedThe management password
A VeraCrypt volume on a failing driveContainer intact on the imageYour passphrase; unlocked on the image
A failing drive that is also encryptedTwo problems, in orderThe drive recovered first; the volume unlocked on the image

From the box arriving to your files going back.

Work we have closed →
01

Logged the day it lands, and the first look costs nothing Free

A case number goes on it the day the parcel is opened, and an engineer settles what has actually failed before anything else happens. The drive is read on our own equipment, never in a computer that might send it a TRIM command. Back to you come two things together: a straight note of what is liftable and what is not, plus one figure, fixed and written down. Accept it, or decline and owe us nothing.

Nothing to pay for lookingA single figure, put in writingNo TRIM, no writes
02

Powered on our terms

Every power-on gives a failing SSD another chance to run its own housekeeping. Here the drive is brought up in the controller's diagnostic state instead, which lets the bench speak to the flash directly and keeps damaged firmware out of the conversation.

Vendor diagnostic modeNo hopeful reboots
03

Past the fault, to the map

An encrypted drive is recovered as a drive first, exactly as an unencrypted one would be, through its own controller. The volume is unlocked afterwards, on the image and never on the original, with the key you supply. Where the drive was hardware-encrypted by its controller, that controller has to be the one doing the reading, which rules out chip-off and decides the route at the free look.

Loader in RAM, never on the flashMapping tables put back together
04

A full image, then the volume

Nothing is worked on live. The whole drive is imaged once, weak pages retried in their own passes, and the file system is put back together on the image. Encrypted volumes are unlocked there too, with the key you supply, and never on the original.

One careful imageThe volume verified end to end
05

You see the file list before you pay

What was recovered is listed for you first, and only then does a bill exist. Approve the list and it is invoiced; turn it down and it is not — and where nothing has come back, most jobs carry no charge at all. Recovered data travels home on fresh media bought in for your job, with the postage at our end. Your case is not closed until you have opened the files on a machine of your own.

No charge until you accept the figureFresh media, supplied with the job3–5 days at the bench

From the bench

  • Find the key before you post. BitLocker's is in the Microsoft account that set the machine up, under Devices, or with your IT department. FileVault's is your login password. Ten minutes now saves a week later.
  • Encryption is not a fault. A failing encrypted drive has two things wrong with it, and they are dealt with in order: the drive, then the volume.
  • We do not break encryption, and we do not accept devices that are not yours to open. A device belonging to an employer, an estate or a former partner needs the owner's authority in writing.
  • Hardware encryption is invisible until it matters. Samsung, WD and SK hynix drives encrypt everything by default. It changes nothing for you day to day, and it decides how the bench reaches the flash.

One job, followed all the way through.

UK · SDR-2026-0401JOB LOGGED ✓

A Surface Laptop 4 with a dead board, BitLocker on, and the key in a Microsoft account nobody had checked

The laptop died; the 2230 NVMe drive inside was healthy. BitLocker had been on from the day the machine was set up, as it is on most Surfaces, and the owner did not know it. The recovery key was where Windows had put it, in the Microsoft account under Devices. The drive was imaged whole, the volume unlocked on the image with the key, and everything came back.

100% of it recovered3 days here, and back by post
Illustrative example — replace with a genuine case

What helps, and what harms.

Do this much first

  • Find the BitLocker recovery key or FileVault password first
  • Tell us which encryption was on, if you know
  • Send the drive, or the whole Mac if it is soldered
  • Have the owner's written authority if the device is not yours

What sets us back

  • Turning BitLocker off or suspending it on a failing drive
  • Resetting the TPM or the BIOS
  • Reinstalling the operating system to get past the prompt
  • Guessing passwords against an Opal drive — many lock permanently after a few attempts

Questions answered before you commit.

I have a BitLocker prompt. Can you help?

With the 48-digit recovery key, yes. It is in the Microsoft account that set up the device, under Devices, or with your employer's IT. Without it, nobody can, and we say so.

Do you break encryption?

No. We recover the drive and unlock the volume with the key you supply. We do not attempt to bypass BitLocker, FileVault, Opal or anything else, and we do not take devices that are not yours to open.

Where is my BitLocker recovery key?

Sign in at account.microsoft.com, open Devices, and look for the recovery keys. If the machine was set up by an employer, ask them; it will be in their directory.

The drive is failing and encrypted. Is that two jobs?

Two steps in one job. The drive is recovered first, then the volume is unlocked on the image. Encryption adds a step, not usually a cost.

What does it cost?

£300 + VAT for one drive after the free look, fixed in writing.

Nothing gets worse while the power is off.

Looking at it is free. Back comes a list of what opened and what did not, together with a single price to finish, set down in writing while you are still free to say no. Until that list reaches you, leave the drive switched off.

0800 6890668