Service 01
Data recovery
Forensics laboratory &
Class 100 cleanroom based
data recovery service
No matter what type the storage is — a hard drive, a USB stick, a tape, a laptop, a mobile phone — there is a possibility to recover the data. What decides the outcome is usually what happened before the media reached us.
Before you contact a consultant
- Do not make changes to the storage media — no copying files, running or installing software, or browsing the web on it.
- Do not restart the storage media.
- If the media is physically damaged, shut it down and do not start it up again.
- If the hard drive makes an abnormal noise, shut it down and do not start it up again.
- Do not open the media yourself without professional tools.
Why a forensics lab recovers more
Our laboratory is equipped with multiple digital forensics tools and a Class 100 cleanroom. Forensic technique digs deeper than ordinary recovery: it scans hidden areas of the media and uncovers hidden or deleted files, which vastly improves the chance of success. The cleanroom is the operating theatre — it gives us a clean environment for media surgery and prevents a second, dust-borne failure while the drive is open.
How a case runs
- ConsultancyContact a consultant by email or on the service hotline. No consulting fee.
- Media collectionHand the media to our Bangkok office, or reserve onsite collection — free of charge.
- AnalysisWe analyse the media to find the cause of the fault. No win, no charge.
- Analysis report & file listYou receive a list of the files that can be recovered before any recovery work begins.
- Data recoveryOur engineers recover the files you assign from that list.
- DeliveryThe original media is returned along with new media holding the recovered files.
- Technical supportRecovered data is held for 7 days, then permanently deleted. Contact us within that window for any further work.
Turnaround
| Service | Stage 1 — Analysis | Stage 2 — Recovery |
|---|---|---|
| Priority | 1–2 workdays | 1–2 workdays |
| Standard | 3–4 workdays | 3–4 workdays |
| Onsite | 1 workday | 1 workday |
Project details are subject to change depending on the case.
What can be recovered
Media type
- Hard drive, micro drive, RAID, NAS, SAN
- Magnetic tape — DLT, LTO
- CD / DVD / Blu-ray optical disc
- Digital album frame, MP3 / MP4 player, PDA
- PC, tablet, cellphone, smartphone
- iMac, MacBook, PowerBook, iPhone, iPad, iPod
- SSD, CF, SD, Micro SD, MS, USB drives
- SyQuest, MO, ZIP, floppy diskettes
Operating system
- Windows 2000 / XP / Vista / 7 / 8
- Windows NT / Server 2003 / 2008 / 2012
- Windows 95 / 98 / 98SE / ME
- DOS / Windows 3.x
- Mac OS
- Unix, Linux
- iOS, Android, Windows Mobile, Symbian
- Novell NetWare, OS/2
- All database systems
File type
- Office documents
- Emails
- Pictures
- Videos
- Chats and instant messenger histories
- Social network communications
Your data is safe here
DataExpert holds ISO/IEC 27001 Information Security Management certification for the provision of data recovery and disposal services — certificate number IS 828154. The certificate represents our commitment, and gives clients the assurance that their information security is protected and respected. In DataExpert, not only project operators but all employees have signed an NDA and guarantee not to disclose, copy or transfer any client information to any person.
Service 02
Digital forensics laboratory
Established 2010 — the first and
only privately owned full-service
digital forensics lab in Hong Kong
What digital forensics is
Digital data is often the clue — or the evidence — that supports a criminal investigation or a piece of litigation. Digital forensics is the process of using scientifically proven methods to seize and process potential evidence found on a digital device (a computer, laptop, hard drive, mobile phone, memory card), and to interpret that data forensically so the digital evidence is admissible in court.
Electronic evidence may assist the prosecution of a criminal, help in the defence of an accused person, or serve as intelligence for someone seeking knowledge for personal or professional reasons.
The lab
The laboratory brings together every type of cutting-edge equipment and software so that IT experts, investigators and lawyers can work the same evidence in the same room, and professionally conduct computer forensics, mobile device forensics and forensic data recovery of information security incidents and crimes. Our experts come from an unmatched background — members of HTCIA (High Technology Crime Investigation Association) and IACIS (International Association of Computer Investigative Specialists) certified professionals.
What is in the lab
- Digital evidence preservation tools
- Computer analysis tools
- Mobile device analysis tools
- Forensic data recovery equipment
- Class 100 clean room
- Chip-off workstation
- Data erasure tools
- NSA certified degausser
- Professional storage media shredder
What we do in the lab
- Digital evidence acquisition & preservation
- E-discovery
- Forensic data recovery
- Password decryption
- Forensic analysis
- System emulation
- Data carving
- Chats & instant messenger analysis
- User artifacts analysis
- Timeline analysis
Before it becomes a lawsuit
When a company finds a suspect, or behaviour on a device that looks criminal, but is not yet certain it is true — going straight to a law firm or filing formally can arouse suspicion, cause internal chaos, leak intelligence, generate unnecessary cost, or create problems nobody expected.
Many managements have said what they actually want first is a beforehand investigation and discovery, conducted quietly, before any formal procedure or handover to a legal party. That is exactly the situation this laboratory is built for.
If you are an investigator, or you have already organised an internal investigation team, we also provide laboratory and equipment rental with related technical support.
Service 03
3D service
A consummate period
for your data — degaussing,
destruction, disposal
Do you discard out-of-date IT assets by simply throwing them away? Four things follow from that, and none of them are cheap.
Caution
- Data leakage
- Legal expenditure
- Embarrassment in public
- Negative impact on the environment
Step 1 — Degaussing
For magnetic storage media — hard disk, Super Disk, floppy, DLT, LTO, VHS, DDS tape — degaussing is the most reliable way of data sanitisation. It damages the storage system permanently, so no data can be recovered, even by the most sophisticated forensics tools that exist today. Many governments and listed companies require sensitive and top-secret information to be degaussed before disposal.
Per the NSA/CSS Storage Device Sanitization Manual, degaussing means reducing the magnetisation of a storage device to zero by applying a reverse coercive magnetising force, rendering previously stored data unreadable and unintelligible, and ensuring it cannot be recovered by any technology known to exist.
Non-magnetic media — erasing service available instead
Step 2 — Destruction
After degaussing we recommend standards-complying shredders to shred the device into small particles, as an additional layer of protection. For malfunctioning media that cannot be wiped normally, destruction is the only reliable protection against data leakage.
Step 3 — Disposal
We work with professional environmental and recycling companies to handle the remaining devices, meeting environmental protection obligations — or remarketing the equipment instead, according to the client's request.
Standards and regulations we work to
What the service includes
- Professional consultancy and tailor-made planning
- Onsite or offsite service
- Secure transportation
- Detailed inventory record
- Certificate of degaussing, wiping or destruction
- Filming, photographing or client witnessing of the destruction process — optional
- Degaussing effect verification — optional
Why clients trust this to us
- ISO 27001 certified
- IT engineers with 15+ years of experience
- Compliant with international standards and government regulations
- The choice of government departments, law enforcement and investment banks
Service 04
Erasing & shredding
Keep the hardware in service,
or reduce it to particles —
documented either way
Erasing keeps assets working
Not every decommissioned drive needs destroying. Secure erasure verifies the media, repairs it where that is viable, and returns it to service — which is both cheaper and considerably better for your waste figures.
Refurbish & re-use
- Drives are repaired and verified so they can go back into service
Re-market
- Up to 98% of serviceable equipment re-marketed rather than scrapped
Recycle
- Handled by professional recycling partners, with certificates issued
Shredding, when nothing may survive
Paper shredding
- Secure destruction to a 1×2 mm particle
Electronic media shredding
- Hard drives
- SSDs
- Magnetic tape
- USB drives
- Credit cards
- CD / DVD
One-stop solution
- Consultancy
- Onsite collection
- Secure transportation
- Process documentation
- Certification
Service 05
Laboratory design
We build the rooms
as well as work in them
Clean room
Dust- and particle-free environments built to industrial standard — the same class of room our own platter and head work is performed in, where a single particle in the wrong place ends a recovery.
Electromagnetic-wave-free room
Built using Skim Block shielding technology, blocking microwave, X-ray and radio transmission. Specify the attenuation your work requires: