Taking work now — the first look is freeServer and RAID drives posted in from anywhere in the UK, or handed in at ten drop-off pointsQuicker still, give us a ring:0800 6890668
A self-encrypting drive is locked. The key stayed on the old controller. The PSID on the label is not it.
A drive that reports Secured or Locked on a PERC, not authenticated on a Smart Array, or that reads as random data on any host, is a self-encrypting drive that has been separated from its key. The controller that locked it held the authentication key, in local key management or on a key manager, and the drive will not release its media encryption key to any host that cannot present it. The way back is the key: the PERC's passphrase, the HPE encryption key, the KMIP server and its credentials, the exported key file, the old controller itself. The way forward, printed on the drive's label as a 32-character PSID, resets the drive by destroying its media key, and every byte on the platters with it. One locked SED unlocked and imaged is £300 + VAT after the free look, fixed in writing, 3–4 days at the bench; without the key there is nothing to recover, and that is said at the free look, unbilled.
Free first lookOne fixed figure in writingNo data, no bill on most jobsReturn postage paid
Rather talk it through? An engineer answers the bench line 0800 6890668
Do not PSID revert. The 32-character code on the label resets a locked drive by destroying its encryption key and every byte on it. Find the controller's passphrase, its exported key or its key manager instead, and send the drive as it is.
Where the key lives, controller by controller.
A TCG self-encrypting drive generates a media encryption key at manufacture and encrypts everything it stores with it. Locking wraps that key with an authentication key the host supplies; from then on the drive returns ciphertext to any host that cannot present the authentication key, and returns plaintext to the one that can. The authentication key is the thing to find, and it lives with the controller, not the drive.
On a Dell PERC with local key management it is a passphrase set when encryption was enabled, and it can be exported from a working controller; on Dell's Secure Enterprise Key Manager it lives on the key server. On an HPE Smart Array it is the encryption key set in HPE Secure Encryption, local or on a KMIP server. NetApp's NSE and EMC's D@RE keep it on the filer or the array and on their key managers. Synology, QNAP and TrueNAS keep it in the unit's configuration. A controller that died with the key in local mode and no export is the bad case, and the bench cannot help it; a controller replaced with the key still on the old one, or on a key manager, is a drive that unlocks on the imager in a minute.
The PSID is different. Every TCG drive has a physical security ID printed on its label so that an owner who has lost the key can return the drive to service, empty: the PSID revert regenerates the media encryption key, and the old ciphertext becomes noise forever. It is the right command for a drive being decommissioned and the wrong one for any drive whose data is wanted.
Logged the day it lands, and the first look costs nothing Free
A case number goes on the parcel and a number on every drive the day it is opened, matched to the slot you wrote on it. An engineer settles what has actually happened before anything spins: the interface, the sector format, the firmware, the security state, and what the controller was saying when it stopped. Back to you come two things together: a straight note of what is liftable and what is not, plus one figure, fixed and written down. Accept it, or decline and owe us nothing.
Nothing to pay for lookingA single figure, put in writingNo rebuilds, no imports, no resets
02
The drive on its own bench
A member drive is read on the equipment its interface needs: a SAS imager for SAS and NL-SAS, a SATA imager for enterprise SATA, a terminated SCSI or Fibre Channel controller for the legacy drives, a PCIe adaptor for NVMe. It is never put back in a server, and never in a controller that will try to rebuild. Drives that answer at full speed are imaged; drives with weak or failed heads go to the clean bench, where matched donors are fitted and the service area repaired before a sector is read.
Read at its native interfaceFailing heads to the clean bench
03
Imaged once, at its native sector size
A locked SED is unlocked on the imager with the credential you supply, and then imaged sector by sector with its weak areas last; where the mechanics have also failed, the head work comes first on the clean bench and the unlocking second. The key is used once and not retained.
Head by head, weak areas lastNative sector size preserved
04
The image, and the set
Where the set is healthy and one member was the job, the image goes back to you on a fresh drive, sector-identical, ready to rebuild from. Where the set is the job, every member is imaged and the array reassembled in software from the images: order, chunk size, parity rotation and the reshape point read from the drives' own metadata, the file system repaired on the virtual volume, never on the originals. The array work is covered in full on our RAID array site, and it happens on the same bench.
One member: a sector-identical image on fresh mediaA set: reassembled in software from the images
05
You see the file list before you pay
What was recovered is listed for you first, and only then does a bill exist. Approve the list and it is invoiced; turn it down and it is not — and where nothing has come back, most jobs carry no charge at all. Recovered data travels home on fresh media bought in for your job, with the postage at our end. Your case is not closed until you have opened the files on a machine of your own.
No charge until you accept the figureFresh media, supplied with the job3–4 days at the bench
From the bench
Export the key from every working controller now, before one fails. A PERC's local key management passphrase and an HPE encryption key both export.
The old controller is a key, if it still works. Send it with the drives.
Key managers have backups, and a decommissioned one usually left one. Ask whoever ran it.
We do not open drives that are not yours. A SED from an employer or an estate needs the owner's written authority.
One job, followed all the way through.
UK · RDD-2026-0557JOB LOGGED ✓
Four SEDs from an R740 whose PERC H740P had been replaced, leaving the set locked, with the local key management passphrase in a password vault nobody had looked in
The passphrase decided the job. The four drives were unlocked on the SAS imager with it and imaged, one after a head swap on the clean bench, and the images went back on fresh drives with the set reassembled from them. The same job without the passphrase would have ended at the free look, unbilled.
100% of the set recovered6 days here, and back by post
Illustrative example — replace with a genuine case
What helps, and what harms.
Do this much first
Find the passphrase, the exported key or the key manager
Send the old controller if it was replaced
Power down and label the slots
Have the owner's written authority if the drives are not yours
What sets us back
PSID reverting
Guessing passphrases repeatedly
Reformatting or initialising a drive that reads as noise
Decommissioning the key manager before the drives are read
Questions answered before you commit.
My drives are locked after a controller swap. Can you unlock them?
With the old controller's passphrase, its exported key, the key manager it used, or the old controller itself, yes. Without any of them, no, and nobody can.
Is the PSID the password?
No. It is the reset code. A PSID revert erases the drive by destroying its key.
Can you break the encryption?
No. A TCG SED uses AES-256 with a key the drive generated itself. Anyone claiming otherwise is claiming something false.
What does it cost?
£300 + VAT for one drive with its key, after the free look. Without the key, nothing, because nothing is possible.
How long does it take?
3–4 days at the bench for one drive; 5–10 days at the bench for a set.