Taking work now — the first look is freeDrives posted in from anywhere in the UK, or handed in at ten drop-off pointsQuicker still, give us a ring:0800 6890668
BLKBitLocker Data Recovery 0800 6890668 Price my job
BLK / How the drive was locked

TPM · PIN · password · recovery key · startup key · escrow · To Go · Device Encryption

How the drive was locked, and where the key lives. The protector decides what happens when it goes wrong, and where to look first.

BitLocker locks a drive the same way underneath whatever you chose at setup: one key encrypts every sector, a second key encrypts that one, and a protector holds a copy of the second key. The protector is the part you interact with, and it decides what happens when something goes wrong. A TPM-only drive unlocks itself from a chip on the board, so you never see a prompt until the chip's measurements change and it drops to the recovery screen. A PIN or a password is something you type, so it can be forgotten, and a weak one can sometimes be recovered while a strong one cannot. A startup key lives on a USB stick that can be lost. And above all of them sits the 48-digit recovery key, which unlocks the drive when every other protector fails, and which is the first thing to look for. The pages below take each protector in turn: where its key is kept, how to retrieve it, and what it means for getting your data back. Every one of them is recovered only for the drive's owner, behind proof that it is yours.

Owner-only, proof requiredFree first look£800 + VAT, one diskThe honest answer either way

Rather talk it through? An engineer answers the bench line
0800 6890668

Stop before you reinstall or reformat anything. If the machine is at the BitLocker recovery screen, the data is intact behind the key; reinstalling Windows, reformatting the drive or clearing the TPM again will not get you in and can overwrite what is there. Do not keep typing the wrong key until a device locks you out. If the machine is still running and unlocked, do not shut it down before you have read the lost-password pages. Find your recovery key first, and send nothing until you have.

The one idea that makes sense of all of them.

One key encrypts the diskA single key, the Full Volume Encryption Key, encrypts every sector of the drive and never changes. You never see it. Everything else exists to protect it, and recovery is the business of getting back to it through something you have or know.
A second key protects the firstThe FVEK is itself encrypted, by the Volume Master Key. Protecting the VMK rather than the disk key is what lets you change a PIN, add a fingerprint or escrow a recovery key without re-encrypting the whole drive: only the small VMK is re-wrapped.
A protector holds a copy of the second keyEach protector you set up, the TPM, a PIN, a password, a startup key, the recovery key, holds its own encrypted copy of the VMK. Any one of them can unlock the drive. That is why the recovery key opens a drive whose TPM has changed: a different protector, same VMK.
The recovery key is the master spareThe 48-digit recovery key is a protector that unlocks the VMK directly, designed to work when the others cannot. It is the single most valuable thing to find, and the first thing every one of these pages tells you to look for.
While the drive is open, the key is in memoryWhen a BitLocker volume is mounted and in use, the Volume Master Key sits in the computer's RAM. This is the one route into a drive whose password is genuinely lost: if the machine is still running, or a hibernation file survives, the key can sometimes be lifted from memory. Once it is powered off and the volume locked, that route closes.
Without a protector you can open, there is no way inIf no protector can be opened, no key retrieved, no password recovered and no memory captured, the FVEK stays sealed and the data stays encrypted. AES cannot be brute-forced in any feasible time, so this is a real end, and the honest pages below say when a drive has reached it.

Every protector, and where its key is kept.

Find your recovery key → →

Which of these can be recovered, in one place.

Almost always recoverable: any drive whose owner has, or can retrieve, the 48-digit recovery key or the drive's password. That includes every machine sent to the recovery screen by a Windows update, a firmware update, a cleared TPM or a motherboard change, because the data is intact and only the key is needed; and it includes a drive that has physically failed, which is imaged and then decrypted from the clone. A work or school machine whose key is escrowed in Active Directory, Entra ID, Intune or MBAM is in this group, and so is a Windows Home machine whose Device Encryption key is in a Microsoft account.

Sometimes recoverable: a drive locked with a human-chosen password or a short numeric PIN, where the password is weak enough for a dictionary or mask attack, or where the machine is still running or a hibernation file survives so the key can be lifted from memory. The weaker the password and the more that is known about it, the better the odds; a strong random password is not in this group.

Not recoverable by anyone: a modern drive encrypted with AES-256-XTS, protected by TPM only or TPM and a strong PIN, with no recovery key escrowed anywhere, no password protector to attack, and no memory or hibernation capture. There is no backdoor and no feasible way to brute-force the key. We say so at the free look rather than take the work, and we would rather you heard it from us than paid someone who implies otherwise.

The questions that come up first.

What is the difference between the recovery key and the recovery password?

In everyday use, none: both mean the 48-digit number shown on the recovery screen and stored in your Microsoft account, Entra ID or Active Directory. Strictly, Microsoft calls the 48-digit number the recovery password and uses recovery key for a .BEK key file on a USB stick, but when people say recovery key they almost always mean the 48 digits.

I do not know which protector I had. Does it matter?

Not for finding the key. Whatever the protector, the 48-digit recovery key opens the drive, and that is what to look for first. The recovery screen shows the first eight characters of the key's ID, which tells us which stored key matches if you have more than one.

Can you recover any of these without the key?

Only the sometimes-recoverable group above, and only in the conditions described: a weak password, or a memory or hibernation capture. On a modern TPM-sealed AES-256 drive with none of those, no, and no legitimate service can. The honest pages here say which is which.

Do you need the whole computer?

No. Take the drive out and send the drive on its own. Whole laptops and desktops are not accepted. If you cannot remove the drive, the sending-in guide explains what to do.

Start with the key, whatever the protector.

Find your 48-digit recovery key before anything else; the finder page lists every place it could be. If the drive has also failed, or the key is truly lost, tell us what happened and send proof the drive is yours, and the first look will tell you honestly what can be done.

0800 6890668