Taking work now — the first look is freeServer and RAID drives posted in from anywhere in the UK, or handed in at ten drop-off pointsQuicker still, give us a ring:0800 6890668
RDDRAID Drive Data Recovery 0800 6890668 Price my job
RDD / Every kind of member drive / Self-encrypting drives

TCG Enterprise · Opal · FIPS 140 · ISE · PERC LKM · Smart Array · KMIP

Self-encrypting drives. Every byte on the platters is encrypted, whether anyone turned it on or not.

Most SAS drives and many NL-SAS and enterprise SATA drives sold in the last decade are self-encrypting. The drive encrypts everything it writes with a key it generates itself, and only exposes that key to a host that presents the right credential: a PERC or Smart Array controller with local key management, a storage array, or a key manager over KMIP. Left unlocked, the drive reads like any other. Locked, after a controller change or a move to another chassis, it reads as noise, and the one command that unlocks it without the credential, the PSID revert printed on the label, does so by destroying the key and every byte with it. The bench unlocks a SED on the imager with the key you supply, then images it like any other drive; without the key there is nothing to recover, and that is said at the free look, not after. One SED imaged is £300 + VAT after the free look, fixed in writing, 3–4 days at the bench.

Free first lookOne fixed figure in writingNo data, no bill on most jobsReturn postage paid

Rather talk it through? An engineer answers the bench line
0800 6890668

Do not PSID revert. The 32-character PSID on the label resets a locked drive by destroying its encryption key, and every byte on the drive with it. It is the last resort for a drive whose data nobody wants. Find the controller, the passphrase or the key manager instead, and send the drive as it is.

Self-encrypting drive symptoms, and what each means.

Not listed? Describe it on the form →
Packing it and posting it: power the server or shelf down, write the slot number on each drive with a marker before it comes out of its carrier, and keep it in the carrier. Send every member from the set where the set is the job, or the one failed member where the set is healthy and you want it imaged for the rebuild. Each drive travels in an anti-static bag inside its own padding, in a box with nothing able to move. Send the controller only if we ask for it. Insure the parcel for what the data is worth rather than the price of the drives, and use a tracked service. The posting address is not printed anywhere on this site; it arrives by email in reply to the form, with a booking sheet to print; the sheet inside the parcel is what matches it to your enquiry when it is opened. Or hand the sealed parcel in at the nearest of ten drop-off points, your name on the outside and the sheet inside; say where you are on the form and it comes by email. We pay the postage home either way. The whole of it is written up on the guide to packing and posting.

Where it lives, and what fails.

How a SED worksThe drive generates a media encryption key at manufacture and encrypts everything with it. Locking wraps that key with an authentication key the host supplies. Unlocked, the drive is transparent; locked, it returns ciphertext; reverted, the media key is regenerated and the old data is gone forever.
Who holds the keyA PERC with local key management holds a passphrase you set; Dell's enterprise key manager, HPE's Secure Encryption, NetApp's NSE and EMC's D@RE hold it in a manager over KMIP. Synology and QNAP hold it in the unit. The key follows the controller, not the drive.
What the bench doesThe drive is unlocked on the imager with the credential you supply, then imaged like any other member, heads swapped in clean air where they need it. The key is used once, on the bench, and not kept.
What the bench does not doBreak the encryption. A TCG Enterprise SED with a 256-bit AES key does not yield to anyone, and a laboratory claiming otherwise is claiming something false. Without the key, the drive is returned unread and unbilled.

Model strings, and what they tell us.

Describe yours to us →
What you see What it means What the bench needs
Secured / Locked on a PERCLocal key managementThe controller's passphrase
Drive not authenticated (HPE)Smart Array encryptionThe encryption key or the controller
Random data on another hostLocked SEDThe key from the original controller
FIPS label, drive unreadableFIPS SED, tamper-evidentThe same: the key
PSID revertedKey destroyedNothing helps; assessed honestly

From the parcel arriving to your files going back.

Work we have closed →
01

Logged the day it lands, and the first look costs nothing Free

A case number goes on the parcel and a number on every drive the day it is opened, matched to the slot you wrote on it. An engineer settles what has actually happened before anything spins: the interface, the sector format, the firmware, the security state, and what the controller was saying when it stopped. Back to you come two things together: a straight note of what is liftable and what is not, plus one figure, fixed and written down. Accept it, or decline and owe us nothing.

Nothing to pay for lookingA single figure, put in writingNo rebuilds, no imports, no resets
02

The drive on its own bench

A member drive is read on the equipment its interface needs: a SAS imager for SAS and NL-SAS, a SATA imager for enterprise SATA, a terminated SCSI or Fibre Channel controller for the legacy drives, a PCIe adaptor for NVMe. It is never put back in a server, and never in a controller that will try to rebuild. Drives that answer at full speed are imaged; drives with weak or failed heads go to the clean bench, where matched donors are fitted and the service area repaired before a sector is read.

Read at its native interfaceFailing heads to the clean bench
03

Imaged once, at its native sector size

A self-encrypting drive is unlocked on the imager with the credential you supply, and then imaged sector by sector with its weak areas last. Where the mechanics have failed, the head work comes first and the unlocking second, on the repaired drive. The key is used once and not retained.

Head by head, weak areas lastNative sector size preserved
04

The image, and the set

Where the set is healthy and one member was the job, the image goes back to you on a fresh drive, sector-identical, ready to rebuild from. Where the set is the job, every member is imaged and the array reassembled in software from the images: order, chunk size, parity rotation and the reshape point read from the drives' own metadata, the file system repaired on the virtual volume, never on the originals. The array work is covered in full on our RAID array site, and it happens on the same bench.

One member: a sector-identical image on fresh mediaA set: reassembled in software from the images
05

You see the file list before you pay

What was recovered is listed for you first, and only then does a bill exist. Approve the list and it is invoiced; turn it down and it is not — and where nothing has come back, most jobs carry no charge at all. Recovered data travels home on fresh media bought in for your job, with the postage at our end. Your case is not closed until you have opened the files on a machine of your own.

No charge until you accept the figureFresh media, supplied with the job3–4 days at the bench

What arrives most often

  • Find the key before you post. The PERC passphrase, the HPE encryption key, the KMIP server and its credentials, the exported key file. Ten minutes now saves a week.
  • The PSID is not a password. It is the reset code, and it resets by erasing.
  • Export the key from a working controller before any controller is replaced. A drive whose controller died with the key inside is a drive the bench cannot help.
  • We do not open drives that are not yours to open. A SED from an employer or an estate needs the owner's written authority, and we ask for it.

One job, followed all the way through.

UK · RDD-2026-0557JOB LOGGED ✓

Four SEDs from a PowerEdge R740 whose PERC H740P had failed and been replaced by an engineer, leaving the set locked

The old controller's local key management passphrase was in the firm's password vault, which decided the job. The four drives were unlocked on the SAS imager with the passphrase and imaged, one after a head swap, and the images went back on fresh drives with the set reassembled from them. The same job without the passphrase would have ended at the free look, unbilled.

100% of the set recovered6 days here, and back by post
Illustrative example — replace with a genuine case

What helps, and what harms.

Do this much first

  • Find the passphrase, the key or the key manager first
  • Power down and label the slots
  • Send the drives as they are, locked
  • Have the owner's written authority if the drives are not yours

What sets us back

  • PSID reverting a locked drive
  • Replacing a controller without exporting its key
  • Guessing passphrases repeatedly on a keyed drive
  • Reformatting or initialising a drive that reads as noise

Questions answered before you commit.

My drives are locked after the controller was replaced. Can you unlock them?

With the old controller's passphrase, its exported key, or the key manager it used, yes. Without any of them, no, and nobody can.

Can you break the encryption?

No. A TCG SED uses AES-256 with a key the drive generates itself. A laboratory claiming to break it is claiming something false.

What is a PSID revert?

The reset code on the drive's label. It resets a locked drive by destroying its encryption key and every byte on it. It is not a recovery step.

Does encryption add to the price?

Not usually. The unlocking is a step on the imager once the key is supplied; the drive is then imaged like any other. £300 + VAT per drive.

How long does it take?

3–4 days at the bench for one drive with its key; 5–10 days at the bench for a set.

Find the key. Then send the drives.

Unlocked on the imager with what you supply, then imaged like any other member. The first look is free, and the figure is in writing before any chargeable work.

0800 6890668