Deleted files, damaged drives, disputed documents, suspicious emails. The Waldrep Company provides forensic data recovery and authentication of digital records for attorneys nationwide, documented at every step so the work stands up to examination.
Two questions bring attorneys here: can the data be recovered, and can this record be trusted? Our forensic data recovery work retrieves deleted, corrupted, and formatted data from computers, phones, and storage media while preserving the original evidence. Our authentication work examines emails, documents, photos, and chat records to determine whether they are what they claim to be.
This is not consumer data recovery. A repair shop can pull photos off a dead drive, but it does not document methods, verify results with hash values, or maintain chain of custody, and those gaps become the other side's cross examination. Every engagement is led by Eric L. Waldrep, MCFE, with 19 years in digital forensics and 27 years in law enforcement.
Altered contracts, disputed messages in custody matters, vanished files in employment cases, contested photos in insurance claims, and intellectual property theft. When the work uncovers a broader problem, it can expand into a full digital forensics investigation.
Recovery and authentication documented well enough to survive the other side's expert, not just files on a thumb drive.
Recovery from HDDs, SSDs, USB drives, SD cards, and RAID arrays using write-protected forensic techniques with hash verification.
Analysis of email headers, routing information, and metadata to verify sender, timestamp, and transmission path.
EXIF metadata, hash comparison, and compression analysis to verify whether photos and videos are original or altered.
Every engagement is documented with hash values, methodology notes, and evidence handling records.
An honest scoping answer before you spend money beats a hopeful one after.
Deleting a file usually does not erase it; the operating system just marks the space as available. Until something overwrites that space, the file, or pieces of it, can often be recovered and verified with hash values.
What matters is what happened after the deletion. A drive that kept running for months has overwritten more than one powered off the same day, and modern SSDs clear deleted data in the background through TRIM, sometimes within minutes.
The honest answer to "can you get it back" is: sometimes, and we can usually tell you early. After a preliminary review we will say, in writing, what is realistically recoverable, what is partial, and what is gone. Proof that data no longer exists, and roughly when it stopped existing, can matter as much as the data itself.
A record is not evidence because it looks right. Its origin and integrity have to hold up under examination.
Every file carries data about itself: timestamps, author fields, device identifiers, editing history, GPS coordinates in photos. Metadata analysis compares what a file says about itself against what the surrounding system says. A document supposedly written years ago that carries last month's internal timestamps has already answered the question.
A hash value is a mathematical fingerprint: two files with matching hashes are identical to the bit. Hashes confirm a produced copy matches the original, detect substitution between productions, and show nothing changed while the evidence was in our custody.
Where has this record been? We trace a file back through the mailbox, device, server, or cloud account that created and stored it. A record with an unbroken provenance trail is far harder to attack than one that surfaced as an attachment with no history.
Forged records betray themselves in the details: software versions that postdate the claimed date, timestamps that conflict across metadata fields, editing artifacts, missing companion records. A genuine file leaves traces in more than one place, and a fake rarely covers them all. Findings go into a forensic report or declaration the opposing expert can check step by step.
A printout shows what a message looked like, not where it came from.
Email is the most commonly disputed record we see. Email authentication starts with the full headers: the routing chain each server stamped on the message, timestamps across time zones, Message-ID values, and DKIM signatures where they exist. A fabricated message has to fake all of it consistently, and most do not.
For discovery, request native email (PST, MBOX, or EML with full headers), not PDFs or forwards. Forwarding rewrites the very headers an examiner needs.
A screenshot is a photograph of a screen. Treat it accordingly.
A screenshot carries none of the message's metadata, cannot be hash-verified against any source, and can be faked in minutes with a basic image editor or an AI tool. When the other side produces a screenshot of a text thread, you are being asked to trust a picture.
How a particular court treats screenshots is a question for counsel, not for us. What an examiner can do with one is very little: the image alone cannot confirm when a message was sent, whether the thread was edited, or whether the conversation existed at all.
When data disappears at a convenient moment, the destruction itself becomes evidence.
We examine devices and accounts for signs of deliberate destruction: wiping utilities installed and run, factory resets, mass deletions in a narrow window, log gaps, and cloud sync activity that removed files from every linked device.
Timing is usually the heart of it: artifacts often place the destruction on a timeline against the events of the case, and destruction that lines up with a demand letter reads differently from routine housekeeping.
We are direct about limits: showing a device was wiped is often possible, while showing whose hands did it depends on the surrounding evidence. Findings are documented for motions practice, and expert witness testimony is available when the dispute goes further.
The full schedule, including testimony and retainers, is on the rates page. The initial consultation is free.
Preservation imaging of computers, phones, and external media with hash verification and chain of custody documentation from intake through return.
Recovery, authentication, metadata examination, and written findings, billed against a written estimate approved before work begins.
A written critique of the other side's forensic report: methodology, overreach, and what it leaves out.
What can be recovered, what can be proven, and what it costs.
We offer a free, confidential consultation for attorneys. Call or email to get started today.
Tell us what the matter involves and we will respond personally. Initial consultations are free, and nothing you send here is a retention.