Skip to main content
24/7 emergency lineFree diagnosis on eligible standard recoveriesFREE Postage Label, Australia-wide
WildfireData Recovery
No Data, No Fee policyNo success fee unless we recover your data

Real laboratory. Evidence handled properly.

Digital
forensics Brisbane

The evidence may be on the device.
Let’s preserve it before anything changes.

Deleted messages. Copied company files. Tracking and spyware. Tell our Brisbane digital forensics laboratory what happened and what you need to prove or rule out. We preserve available data, acquire it using a method suited to the device, verify the resulting copies and answer the questions agreed in writing, including what the data cannot show.

Fixed fees by stage, quoted in writing.You see the price of each stage before it starts, and you decide at every step whether to go further.
Digital forensics examiner connecting an iPhone to a Cellebrite UFED extraction unit in the Wildfire Brisbane laboratory ON THE WILDFIRE BENCH
DIGITAL FORENSICS
Real devices. Real equipment.
Photographed inside Wildfire.
Brisbane laboratory · Australia-wide intake IACIS CFCE examiner Chain of custody from collection to return Located and recovered data labelled

The 20-second answer

What is digital forensics?

Digital forensics is the preservation, acquisition and examination of data from electronic devices in a way another examiner could repeat and check. In practice, we minimise and document changes to the source, verify acquired copies and trace findings to their source records. A phone extraction may contain only some available data; the report explains what the method captured and what it did not. It answers questions such as what was deleted, what was copied, which account was used and when, and it reports the limits as plainly as the findings.

  • Written by Viktor Burcevski, IACIS Certified Forensic Computer Examiner (CFCE)
  • Last reviewed 3 October 2026
  • Brisbane laboratory, matters from across Australia

Start with the question

Find your matter.
Find the next step.

Select a matter for the specialist guide. We provide digital forensics Australia-wide from one Brisbane laboratory, and the scope we agree in writing is what we actually examine.

Protect the evidence.

About to reset, update, repair or hand the device to IT? Stop. Leave it as it is, write down who has held it, and call us before anything changes.

Evidence router

Not sure where your matter fits? Answer two questions.

Choose what holds the evidence and what you need to find out. The router points you to the right specialist page, tells you what that kind of device can usually show and what limits it, and gives you the one thing to do right now.

The router needs JavaScript. Every route it can suggest is listed in Find your matter above, or call us on 1300 806 557.

1. What holds the evidence?
2. What do you need to find out?

Choose an answer to both questions to see where to start.

  • The specialist page that fits your matter
  • What that kind of device can usually show
  • What limits it, in plain words
  • The one thing to do right now

Mobile phone forensics

What this device can usually show
What limits it
Do this now

    Fees

    How our forensic fees work

    Our digital forensics services are charged in stages. Each stage is a fixed fee quoted in writing before it starts, and you pay for a stage before it begins. You always know the price of the next step before you decide whether to take it.

    Stage 1

    Forensic access and imaging

    A fixed fee per device, quoted before collection. Covers sealed intake, the chain of custody record, acquisition, hash verification and a short note on what the image contains.

    Stage 2

    Examination and report

    A fixed fee for each question in your scope, quoted once Stage 1 shows what the extraction holds. You choose which questions go ahead.

    Further stages

    Anything beyond the scope

    More devices or questions, a conference with your lawyer, a supplementary report or secure deletion of data. Each is quoted separately before it starts.

    Why forensic fees are not success fees

    • The fee pays for the forensic work itself: specialist tools, imaging, hashing, custody records and examiner time, not for a particular result.
    • Nobody can know whether deleted data survived until the device is imaged and examined, so no outcome is guaranteed and completed stages are not refundable.
    • A damaged device may need repair-to-read work first. That is quoted after assessment, before any of it starts.
    • Ordinary recovery uses device-specific pricing. Hard-drive Levels 1–2 have no upfront recovery fee; Levels 3–5 include agreed upfront fees. Forensic stage fees follow the separately agreed scope. See the service comparison.

    Your next step

    Tell us the question.
    We’ll scope the examination.

    Your choices in the evidence router carry into this enquiry. A short, general outline is enough; we agree a secure intake method before you send evidence.

    Review or copy your enquiry brief

    Do not include passwords, recovery keys, private file contents or evidence attachments. If someone may monitor this device or account, use a safer device and contact route. Privacy policy.

    Who instructs us

    Solicitors, businesses and individuals

    The method is the same for everyone: authority first, then a written scope, a sealed chain of custody and a report that can be checked. What changes is the question, and what you need to give us at the start.

    Solicitor and client signing a letter of instruction for digital forensics services
    A letter of instruction sets out the devices, the questions and how the findings will be used.

    Solicitors and their clients

    We take written instructions from solicitors, agree the questions and the devices in scope, and keep a chain of custody record from collection to return. Reports are examiner-signed, separate located data from recovered data, and set out the method and its limitations. An examiner CV is available on request.

    • Letter of instruction, with the numbered questions
    • List of devices, with who holds each one now
    • Deadlines, orders or undertakings that affect the work
    • How the report will be used, so it is written to suit

    Whether evidence is admitted is a matter for the court. We control the quality of the work, and we do not promise outcomes.

    Portable SSD connected to a laptop, the kind of evidence examined in computer forensics for copied company data
    In a departing employee matter, the computer and the drive each hold part of the story.

    Businesses: departing staff and copied data

    When someone leaves with company files, the questions are simple to ask and careful to answer: what was taken, when, and where it went. We examine the work computer and any USB or external drive together, because each holds half of the evidence. Computer forensics can show when a drive was connected and which files were opened; the drive itself can show when files arrived on it.

    • Stop IT from reimaging or reassigning the computer
    • Seal any returned drives, laptops or phones in envelopes
    • Write down who has handled each device since the person left

    Where a matter calls for it, company data can be removed from returned devices under a signed authority once the examination is complete, quoted as a separate stage.

    Individuals and families

    Tracking, spyware, harassing messages or a dispute over what was said. In a free first call we explain what your kind of device can and cannot usually show, before you pay for any stage. Start with domestic violence digital forensics.

    Executors and estates

    Access to a late family member's computer or phone needs authority, such as a grant of probate or letters of administration. Bring it to the first conversation and we will tell you what is possible on that device.

    Employers and HR

    Company-owned devices, workplace investigations and misconduct allegations. We work to the questions in your scope, and we report anything outside it only when you instruct us to look.

    What our clients say on Google

    4.8 from 95 Google reviews

    ★★★★★

    “Wildfire Data Recovery were fantastic to deal with from start to finish. Extremely responsive to any customer requests and we able to perform data recovery and phone repair where Samsung official repairer advised they would not likely be able to preserve the data. Very satisfied with Viktor and his team. Highly recommend 👌”

    AUS-ROV Underwater Inspections · Google review
    ★★★★★

    “Viktor is an absolute legend! I hit the worst-case scenario with BitLocker locking me out completely a problem that could’ve cost thousands. Viktor stepped in and had it fixed in mere minutes. He didn’t just fix it; he guided me step‑by‑step exactly what to do. Thanks to his clear, expert directions, everything was sorted quickly and stress‑free. Massive thanks to Viktor.”

    Joseph B. · Google review
    ★★★★★

    “Excellent Data Recovery and re set up. Viktor goes above and beyond to explain everything regardless of how long it takes. After disasters through the years gone by with other so-called experts, it was stessfree and a relief to discover Wildfire. Excellent pricing and communication. ☆☆☆☆☆ Highly recommend 👌”

    Phillip C. · Google review

    Forensic data recovery

    When the evidence device is broken

    A phone that will not turn on or a drive that clicks cannot be examined until it can be read. Forensic data recovery is the repair-to-read work that comes first, done under the same rules as the examination: photographed, logged and explained in the report, so the findings that follow can still be checked.

    1. iPhone opened on the forensic bench for assessment before mobile phone forensics extraction

      Open and assess

      The device is opened on the bench and its condition is recorded before anything is changed: corrosion, impact damage, swollen batteries and earlier repairs.

    2. Liquid-damaged phone being placed in an ultrasonic cleaner before forensic data recovery

      Clean liquid damage

      Liquid leaves corrosion that keeps spreading. Cleaning is selected for the affected components after assessment; compatible circuit boards may undergo ultrasonic cleaning. The method and any resulting changes are recorded.

    3. Micro-soldering a phone logic board during forensic data recovery so the phone can be extracted

      Repair to read

      A failed component on the logic board is replaced at the bench so the phone can start long enough to be extracted. A repair or boot can change device state. Each intervention is logged, and its possible effect on the evidence is considered in the report.

    Then the same forensic process as any working device: acquisition, hash verification and examination to scope. See the chain of custody for what is recorded at each stop.

    Repair does not always succeed, and some damage cannot be reversed, such as a crushed memory chip or a phone that was reset before it broke. For phones, assessment often cannot confirm what data survives until the phone is running and extracted. We tell you what we found at each step, before the next fee.

    Explore the interactive hash demonstration

    Live demo

    What a hash verifies: try it yourself

    A SHA-256 hash is a 64-character fingerprint calculated from the bytes being checked. Matching hashes provide strong evidence that two copies of those bytes match. They do not prove that an extraction captured the entire device, that the source was authentic before collection, or who created it. Acquisition notes and examination remain essential.

    Original

    a64d5c55c2ef3c122a1110a3cfb3f6c964697348e281534f53c1868a76ef7afa

    Copy with one character changed

    The same text, one character different

    Meet at the café at 4pm on Friday.
    80a17797d8e1f873822452dae894b9ada792f962b5f7ef7aa1c4d10ea3252116

    62 of 64 hash characters changed after one character of text changed.

    Choose a file to see its SHA-256 hash. The file stays on your device: the hash is calculated in your browser.

    Same data, same hashHash the same file tomorrow or in ten years and you get the same 64 characters.
    One change, new hashChanging the input normally produces a very different hash. A mismatch detects a difference; it does not explain its cause.
    Not encryption or anonymityA hash does not encode the full file, but it can identify a known file by comparison. Treat hashes of sensitive evidence as part of the case record.

    Chain of custody

    From your hands to the report, one record

    Chain of custody is the written history of who held a device, when, and what was done to it. It is what lets a lawyer, a court or another examiner check our work. Step through the seven stops and what we record at each one.

    Stop 1 of 7

    Instructions and authority

    Before anything is collected, we confirm who is instructing us and their authority over the device, the devices in scope, the questions to be answered, how the results will be used and any deadline. The scope is agreed in writing, and it is the only thing we examine.

    Recorded at this stop

    • Instructing party and their authority
    • Device list and the numbered questions
    • Intended use and deadline
    • Date the scope was agreed
    Stop 2 of 7

    Sealing and transit

    Devices travel sealed in a tamper-evident bag, by tracked Australia Post Express from anywhere in Australia or by direct collection in the Brisbane area. We send sealing instructions first, so the seal number can be checked at both ends.

    Recorded at this stop

    • Seal number and who sealed it
    • Tracking number or collection details
    • Date and time handed over
    Stop 3 of 7

    Intake and condition

    The seal is checked before it is opened. The device is photographed, its identifiers recorded and its condition noted, including damage, power state and anything attached. If a passcode is supplied, the record notes only that it was supplied in writing and when, never the passcode itself.

    Recorded at this stop

    • Seal intact or not, and who opened it
    • Make, model, serial number or IMEI
    • Photographs and condition notes
    • Power state on arrival
    Stop 4 of 7

    Acquisition

    The device is imaged or extracted with a method suited to it: write-blocked imaging for computer and drive storage, and a supported extraction for phones and tablets. A damaged device first goes through repair-to-read work, and every step that touches it is logged.

    Recorded at this stop

    • Tool and version used
    • Acquisition method and settings
    • Start and finish times
    • Any repair step taken before acquisition
    Stop 5 of 7

    Hashing and verification

    Hash values are calculated for the acquired data and checked against the copy. Examination uses verified working copies where practicable. Any necessary live-device access, incomplete acquisition or repair is documented so another examiner can understand its limits.

    Recorded at this stop

    • SHA-256 hash values
    • Verification result
    • Where the image and working copy are held
    Stop 6 of 7

    Examination to scope

    Only the agreed questions are examined. Each finding is labelled located (live data the user already had) or recovered (deleted data restored), and traced to where it sits on the device, so nobody has to take our word for it.

    Recorded at this stop

    • Examiner notes against each question
    • Source location of every item reported
    • Located or recovered label for each item
    Stop 7 of 7

    Report, return and destruction

    An examiner-signed report sets out the method, the findings question by question, what was not found and the limitations. The device is returned sealed. How long the forensic image is kept is agreed in writing, and it is destroyed on instruction with a certificate of destruction.

    Recorded at this stop

    • Report version and date
    • Return seal number and tracking
    • Retention period agreed
    • Certificate of destruction when instructed

    Choose the right service

    Digital forensics or data recovery?

    Both start with the same device. They answer different questions, follow different rules and are charged differently. Pick the one that matches what the data is for.

    How the two services differ at our Brisbane laboratory
     Data recoveryDigital forensics
    The questionCan I have my files back?What does the data show, and can someone else check it?
    Who instructs usThe owner of the deviceThe instructing party with established lawful authority for the agreed devices, accounts and scope
    HandlingCareful laboratory records, focused on getting your files backChain of custody from collection to return, with sealed transit
    The copyRecovered files delivered on new mediaVerified acquired material, with acquisition limits recorded, plus the items exported for the questions
    Deleted and live dataReturned together as your filesEvery item labelled located or recovered
    What you receiveYour files and a file list to checkAn examiner-signed report with method, findings and limitations
    How it is chargedFees depend on the recovery level. Hard-drive Levels 1–2 have no upfront recovery fee; Levels 3–5 include agreed upfront fees. See the written quote and policy.A fixed fee for each stage, paid before the stage starts, because it pays for the forensic work whatever the data shows

    Need your files back and nobody needs a report? Start a data recovery under our No Data, No Fee policy. Broken device and evidence rules? That is forensic data recovery, the overlap of the two.

    Honest limits

    What digital forensics can show, and what it cannot

    Overclaimed evidence helps the other side. These are the lines we hold in every report, and the lines any reliable examiner in Australia should hold too.

    What it can show

    • That a file existed, when it arrived and, often, where it came from, when the system recorded it.
    • Deleted items that have not been overwritten, wiped or locked away by encryption.
    • That a USB drive was connected to a computer, and when.
    • Messages, media and app data, within what the phone's security state allows.
    • Which accounts were signed in on the device.
    • That our copy is identical to what we acquired, by hash value.

    What no lab can show

    • Data from before a factory reset on a modern iPhone or encrypted Android phone.
    • A guaranteed route around strong encryption. Assessment may identify an available recovery key, authorised account access or a device-specific option; no bypass is promised.
    • Who was holding the device, unless the data itself ties an action to a person.
    • Data that has been overwritten.
    • Records not available through devices or accounts you can lawfully provide. Provider-held records may require the account holder’s export, provider cooperation or an appropriate legal process.
    • A guaranteed result before the device is imaged.

    Choosing an examiner

    How to find a digital forensics expert you can rely on

    Six questions to ask any forensic examiner before you hand over a device, including us. A good examiner answers all six without hesitating.

    • Ask who the examiner is, by nameA named examiner with a recognised certification and a CV your lawyer can read.Ours: Viktor Burcevski, IACIS Certified Forensic Computer Examiner (CFCE).
    • Ask how the copy is verifiedThe answer should mention a hash value calculated for the acquired data and for the copy.Ours: SHA-256, recorded in the chain of custody.
    • Ask whether located and recovered data are labelledLive data the user already had is not the same as deleted data restored, and a report should never blur the two.Ours: every item is labelled one or the other.
    • Ask what they cannot doAn examiner who promises any phone, any password and any deleted message is telling you something untrue.Ours: listed on this page, in plain words.
    • Ask how the fees are setFixed fees per stage, quoted in writing, let you control the cost and stop at any stage.Ours: staged fixed fees, paid before each stage.
    • Ask where your data goesWho handles it, where it is held, for how long, and how it is destroyed.Ours: our Brisbane laboratory, retention agreed in writing, destroyed on instruction.

    Viktor wrote this page and reviews it against the source standards listed here. He holds the IACIS Certified Forensic Computer Examiner (CFCE) credential, is trained on Cellebrite UFED, and holds further credentials with ACE Lab, ADISA and IACRB. Bench work at Wildfire began in Brisbane in 2016, and we have served more than 15,000 clients since. Read more about Wildfire.

    Laboratory
    Brisbane, Queensland. Matters accepted from across Australia.
    Business
    Wildfire Data Recovery, ABN 79 664 657 376
    Forensic tools
    Cellebrite UFED, Magnet AXIOM and MOBILedit Forensic Ultra for phones; PC-3000 by ACE Lab for damaged drives
    Corrections
    Found something wrong on this page? Email us and we will fix it.
    Last reviewed
    3 October 2026
    Show the sources behind this page

    Clear answers before you decide

    Digital forensics questions people ask us

    Courts, costs, locked phones and deleted data. Search the answers, or open the group that fits.

    About digital forensics

    What does a digital forensics examiner do?

    An examiner preserves the device, makes a verified copy, examines only the questions agreed in writing, and reports what the data shows with the method and the limits stated. Most of the work is careful recording: every finding has to be traceable to where it sits on the device, so a second examiner can check it.

    Is digital forensics the same as cybersecurity?

    No. Cybersecurity prevents and responds to attacks while they are happening. Digital forensics looks back at what a device holds and what happened on it. If a network is under active attack or ransomware is still spreading, contain it with an incident response provider first. Forensic preservation comes next.

    What is a forensic image, and why is it used?

    A forensic disk image copies the readable sectors acquired from storage; a mobile extraction may instead capture a supported subset of files or records. Hashes verify the acquired material and its copies, not completeness. The report records unreadable areas, acquisition limits and any changes to the source. You can see how the hash check works in the hash demo on this page.

    What is computer forensics?

    Computer forensics is digital forensics applied to Windows PCs, Macs, laptops and their drives. It covers file activity, USB connection history, user accounts, browser history and deleted documents. Our computer forensics page explains the questions it can answer.

    What is mobile phone forensics?

    Mobile phone forensics is the extraction and examination of data from iPhones, Android phones and tablets: messages, photos, call logs, locations and app data. How much can be extracted depends on the model, the software version and whether the passcode is known. See mobile phone forensics.

    What is forensic data recovery?

    Forensic data recovery combines documented repair-to-read or reconstruction work with evidence preservation when a device is damaged or data is inaccessible. It cannot restore overwritten content or encryption keys destroyed by a completed secure erase. See forensic data recovery.

    Working with us

    How do I find a digital forensics expert?

    Look for a named examiner with a recognised certification, a written scope, hash-verified copies, reports that separate located from recovered data, fixed fees per stage, and someone willing to tell you what cannot be done. Our six checks set out the questions to ask any digital forensics expert, including us.

    Who can authorise a digital forensic examination?

    We establish the instructing party’s lawful authority and agree the devices, accounts and questions in writing. Possession or ownership of a device does not automatically authorise access to every account or another person’s information. Where authority is disputed or unclear, obtain appropriate legal advice before examination.

    Will your report be accepted in court?

    Courts decide what evidence is admitted, under the Evidence Act 1995 (Cth), the Evidence Act 1977 (Qld) and the equivalent laws of each state. What we control is the work: a chain of custody record, hash-verified images, an examiner-signed report that sets out method and limitations, and an examiner CV on request. Tell us the intended use at the start, so the scope and the report suit it. We do not promise outcomes.

    Do you work with solicitors and businesses outside Brisbane?

    Yes. Our laboratory is in Brisbane and we take matters from across Australia. Devices travel sealed by tracked Australia Post Express, or we collect in the Brisbane area. Instructions, scope meetings and report walk-throughs can be done by phone or video.

    How long does a forensic examination take?

    It depends on the number of devices, their condition and the number of questions. We give an expected timeframe with each stage quote, and we tell you straight away if a deadline is at risk, so you can decide what to prioritise.

    How much does digital forensics cost?

    Each stage is a fixed fee quoted in writing before it starts: forensic access and imaging per device first, then examination and report for each question you choose to go ahead with. The fee depends on the device, its condition and the scope. How our forensic fees work explains the stages.

    Phones, passwords and deleted data

    Can you get into a locked phone?

    Sometimes. It depends on the model, the software version, the security patch level and the lawful options available. We do not promise access before assessment. If you know the passcode, give it to us through the secure method we agree at intake, never in an ordinary email or text.

    Can deleted data always be recovered?

    No. Results depend on the storage technology, encryption, how much the device was used afterwards and its physical condition. Deleted data that has been overwritten, or that sat on a phone that was later factory reset, cannot be recovered by anyone. Nobody can know what survived until the device is imaged and examined.

    Can you recover messages after a factory reset?

    Not from the phone itself. A reset on a modern iPhone or encrypted Android phone destroys the keys, so the old data cannot be read. Copies may still exist in a backup, on another device or in an account. Our guide to deleted messages after a factory reset explains where to look.

    Do you keep a copy of my data?

    Only for as long as agreed in writing at intake. Forensic images and working copies stay in our custody in Brisbane, and are destroyed when you instruct us, with a certificate of destruction on request. We handle personal information under the Australian Privacy Principles.

    Digital-forensics terms, in plain English

    Glossary

    Digital forensics terms, in plain English

    The words you will see in our reports, and in most forensic reports in Australia.

    Digital forensics
    Preserving, acquiring and examining data from electronic devices so that the method can be repeated and every finding can be checked by another examiner.
    Forensic image
    A copy of the material acquired for examination. Its coverage depends on readable storage and the acquisition method; phone extractions may be partial.
    Hash value
    A fixed-length fingerprint calculated from data. We use SHA-256. If one byte changes, the hash changes, so matching hashes show a copy is identical.
    Write blocker
    Hardware or software that lets a computer read a drive without being able to write to it, so the original is not changed during imaging.
    Chain of custody
    The written record of who held a device, when, and what was done to it, from collection to return.
    Logical extraction
    A copy of the data a phone or computer makes available through its normal interfaces, such as a backup. Quick, but it usually leaves out deleted records.
    Full file system extraction
    A copy of the phone's whole file system, including app databases and system logs, where the model and security state allow it.
    Located data
    Live data that was still present and visible on the device. It is reported as located, never as recovered.
    Recovered data
    Deleted data restored from free space, database pages or other areas where it survived. Labelled separately from located data.
    Unallocated space
    Parts of a drive the file system marks as free. Deleted files can survive there until new data overwrites them.
    Artefact
    A trace left by the operating system or an app, such as a log entry, a link file or a database row, that records an action or event.
    Scope
    The numbered questions and devices agreed in writing before examination. Work outside the scope needs a new instruction.
    Acquisition
    The step that copies data from the device into a forensic image or extraction, using a method that is recorded in the chain of custody.
    Chip-off
    Removing a memory chip from a damaged device to read it directly. Used for forensic data recovery when the device cannot be repaired.
    Looking for ordinary data recovery?

    Inside the laboratory

    Documented recovery work.
    Clearly stated results.

    Three published data-recovery cases from our bench, showing acquisition, reconstruction and validation work. These are not forensic litigation cases or proof of admissibility; each case explains the work, the result and its limits.

    Editorial illustration of a camera, an SD card and recovered video frames for a formatted SD card data recovery case
    Editorial illustration from the case file. No client footage is shown.
    Featured case · Formatted SD card · 4K camera video

    A formatted Sony SD card: 70 priority videos recovered in full

    The problem
    The card had been formatted. The client needed the newest 66 to 70 recordings first: demanding 4K footage from a Sony FX3.
    The recovery work
    We imaged the card and worked only from that image, never writing back to the card. Each recording was rebuilt from the camera’s own MP4 sample tables, then checked for complete audio and video decoding.
    The outcome
    All 70 priority recordings were rebuilt and decoded in full. When the 4K files froze on playback, we kept the originals and supplied 1080p viewing copies, each one frame-count checked. “In full” means that priority set, not every older file on the card.
    Read the complete case file
    Formatted SD card · Action camera

    An empty DCIM folder, 27 videos rebuilt

    A 64 GB SanDisk card showed an empty folder after a format and earlier recovery-software attempts. Reads stalled near the 30 GB mark, so we paused and reassessed, then took a full image before rebuilding any footage.

    Outcome

    27 complete videos from the latest session, each with its 4K file and preview, plus 28 photos. We also explained why some dates were misleading, and why 44 videos could not all be tied to the requested day.

    Read the case file →
    Level 4 · Dropped hard drive

    A dropped 4TB WD_BLACK, three project folders back

    It fell while it was running. By the time it reached us it clicked on power-up and Windows could not see it. We fitted compatible donor heads, kept the original electronics, and imaged the healthy platter regions first.

    Outcome

    The three project folders the client nominated came back, opened, and were verified against their list.

    Read the case file →

    Past outcomes do not set the price or guarantee the result of a new matter. Assessment and your written quote govern the work. More case files are on our blog.

    Before you do anything else

    Let’s discuss your matter.

    Preserve the current state before making changes. A reset, an update, a well-meant IT reimage or a repair shop can destroy what you need. Call or email first, and we will tell you how to preserve the device and send it to us sealed.

    Do

    • Leave it as it is. If it is on and stable, ask before changing its state.
    • Write down who has held it, and when.
    • Keep chargers, cables and any recovery keys together.
    • Give passwords only through the secure method we agree.

    Do not

    • Reset, update or clean it up.
    • Install recovery or spyware-checking apps.
    • Let IT reimage or reassign it.
    • Open files to check them, or post it unsealed.

    Contact Wildfire

    Call 1300 806 557 admin@wildfiredata.com.au Send a short enquiry

    Only need your files back? Start a data recovery instead.