Taking work now — the first look is freeDrives posted in from anywhere in the UK, or handed in at ten drop-off pointsQuicker still, give us a ring:0800 6890668
BLKBitLocker Data Recovery 0800 6890668 Price my job
BLK / Why you are seeing the recovery screen / The drive shows RAW, or BitLocker finds no valid metadata

RAW volume · no valid BitLocker metadata · damaged header · repair-bde · key package · clone

The drive shows RAW, or BitLocker finds no valid metadata. The header that tells Windows what the drive is got damaged, and with the key it is often rebuildable.

When Windows shows a BitLocker drive as RAW, or BitLocker reports that it cannot find valid metadata, the usual cause is damage to the volume's header, the small but vital area that identifies the volume and holds the encrypted key material. A bad shutdown, a failing sector in the wrong place, an interrupted write, or a partition-table change can corrupt it, and Windows, unable to make sense of the volume, calls it RAW. This looks alarming and is often very recoverable, because BitLocker keeps more than one copy of its metadata on the volume, and Microsoft provides a tool, repair-bde, that can rebuild from those copies and decrypt the volume at the block level using your recovery key or a key package, writing the result to a separate clean drive. With the key, a RAW or no-valid-metadata BitLocker drive is frequently recovered in full. The firm rule, as ever, is that this is done on a sector image, never the original: repair-bde writes its output to a separate target, and we never work on the only copy. We recover these drives only for their owners, behind proof of ownership.

Owner-only, proof requiredFree first look£800 + VAT, one diskThe honest answer either way

Rather talk it through? An engineer answers the bench line
0800 6890668

Do not let Windows format a drive it calls RAW, and do not run chkdsk on it. A RAW BitLocker volume is damaged, not blank, and formatting or chkdsk can destroy the metadata copies that make recovery possible. Image it first, which is what we do, and repair on the clone.

Why RAW is often recoverable, and how repair-bde does it.

A BitLocker volume begins with metadata that identifies it as BitLocker and holds the encrypted key material and the information needed to decrypt the rest. If that header is damaged, Windows cannot recognise the volume and labels it RAW, and BitLocker's own tools may report that there is no valid metadata. Nothing has happened to the bulk of your data; the index to it has been hurt.

BitLocker anticipates this by keeping multiple copies of its metadata at different places on the volume. Microsoft's repair-bde tool is built to use them: given your recovery key, recovery password or a key package, it locates an intact metadata copy, reconstructs what it needs, and decrypts the volume at the block level, writing the recovered, decrypted data to a separate output drive. Because it works block by block rather than needing a healthy file system, it can recover data from a volume too damaged to mount normally. It is the right tool for exactly this situation, and we use it as part of a careful imaged workflow.

Two limits are worth stating. repair-bde writes its output to a separate drive, overwriting that target completely, so there must always be somewhere clean to write to, and the original is never the target; working on an image protects the original absolutely. And repair-bde cannot repair a drive that failed during encryption or decryption, the partly-encrypted case, which is a different and more delicate scenario covered on its own page. For an ordinary RAW or damaged-metadata BitLocker volume with the key in hand, though, the outlook is good.

What you see, and what it means.

Describe yours to us →
What you see The usual reason Where that leaves you
Windows calls the encrypted drive RAWThe volume header is damagedrepair-bde rebuilds from a metadata copy onto a clone
BitLocker reports no valid metadata, key heldThe primary metadata is corruptA backup metadata copy is used to decrypt
RAW after a bad shutdown or interrupted writeThe header was being written when it stoppedOften fully recoverable with the key
RAW and the drive is also failingMetadata damage plus hardware failureImaged first, then repaired on the clone
RAW after encryption was interruptedA partly-encrypted volumeA different, delicate case; see its own page

From the drive arriving to your files going back.

Work we have closed →
01

Logged the day it lands, and the first look costs nothing Free

A number goes on the parcel and the drive the day it is opened, matched to your enquiry by the booking sheet inside. Before anything is read we check the proof of ownership you sent. The drive is then connected through a write blocker, read-only, and examined: whether it is a healthy drive behind a lost key, or a failing drive behind a known key, is settled here, and so is whether what you want is possible. That first look is free, and you may stop at it owing nothing.

Nothing to pay for lookingProof of ownership checked firstRead-only, nothing written to the drive
02

Imaged at the sector level, before anything else

A drive that answers at all is imaged in full on a hardware imager, behind a write blocker, weak areas last, with a map kept of what could not be read. The image is a copy of the encrypted sectors, so it is useless to anyone without your key, which is a privacy gain in itself. Every later step is done on the image. The original drive is never decrypted, never written to, and never worked on directly.

Sector by sector, behind a write blockerNothing written to the original
03

The physical fault repaired on the clone, when there is one

A drive that has failed, that reads slowly or that drops out is stabilised and imaged in passes; a mechanically failed disk is repaired and read on the bench, a dead SSD controller read at the chip level, before any decryption is attempted. The aim at this stage is one clean image of the encrypted volume to decrypt from. Where the drive is healthy and the problem is only the key, this stage is skipped.

Mechanical and chip-level work where neededOne clean encrypted image to work from
04

The image decrypted with your key or password

With your recovery key, recovery password or the drive's password, the image is unlocked: the protector releases the Volume Master Key, the VMK releases the Full Volume Encryption Key, and the volume is decrypted from the clone. Where the metadata or header is damaged, repair-bde and the key package rebuild it at the block level onto a separate target. Where the key is lost but a memory image or hibernation file is available, the Volume Master Key is extracted from it with Passware. Without a key, a password to attack, or a memory capture, the volume cannot be opened, and you are told so at the free look.

Protector → VMK → FVEK → volumeDecrypted from the clone, never the original
05

The file system rebuilt, and the list before the bill

Once the volume is open it is an ordinary NTFS or exFAT file system, and any damage in it is repaired on the image and the files recovered. What was recovered is listed for you first, and only then does a bill exist. The files go home on fresh media. The original drive is returned, or securely destroyed at your request; we never send the key and the data by the same route.

Files listed before any invoiceFresh media, supplied with the job3–7 days at the bench

From the bench

  • Do not format a drive Windows calls RAW. It is damaged, not blank, and formatting destroys the metadata copies that make recovery possible.
  • BitLocker keeps more than one metadata copy, which is why repair-bde can so often rebuild a RAW volume when the key is available.
  • repair-bde writes to a separate drive and needs the key. We run it on an image, so the original is never touched.

Multiple metadata copies are why repair-bde can rebuild a RAW BitLocker volume so often, when the key is available.

What helps, and what harms.

Do this much first

  • Stop using the drive and do not let Windows format it
  • Have your recovery key or key package ready
  • Send the drive to be imaged and repaired on a clone
  • Send proof the drive is yours

What sets us back

  • Letting Windows format a drive it calls RAW
  • Running chkdsk on a RAW BitLocker volume
  • Decrypting or repairing the original in place
  • Assuming RAW means the data is gone; it often is not
We recover BitLocker drives for the people who own them. Before any work begins we ask for proof that the drive is yours or that you are authorised to have it recovered: a purchase receipt, the device serial, a letter on company letterhead for a work machine, or written authorisation from the owner, together with photo ID and a signed authorisation. It is a condition of the work, not a formality, and it is what keeps the service on the right side of the Computer Misuse Act. A drive with no proof of ownership is returned unread.

Questions answered before you commit.

My BitLocker drive shows as RAW. Is the data lost?

Usually not. RAW means the volume's header is damaged so Windows cannot identify it, not that the data is gone. BitLocker keeps multiple metadata copies, and with your recovery key the repair-bde tool can rebuild from them and decrypt the volume at the block level onto a clean drive. It is often fully recoverable.

What is repair-bde?

Microsoft's BitLocker Repair Tool. Given your recovery key, recovery password or key package, it finds an intact copy of the volume's metadata, reconstructs what it needs, and decrypts the drive block by block to a separate output drive. It is designed for exactly the RAW or damaged-metadata situation, and it works even when the volume will not mount normally.

Does repair-bde need my recovery key?

Yes. It decrypts the volume, so it needs a way to the key, your recovery key, recovery password, or a key package exported from the volume or your records. Without a key, a RAW BitLocker volume cannot be decrypted, the same limit as any BitLocker drive without a key.

Can I run repair-bde myself?

It is a command-line tool and it can be run by a capable user, but the safe way is on a sector image of the drive, not the original, and that imaging is the part most people are not equipped for, especially if the drive is also failing. Run on the original, or without a clean target to write to, it can make things worse. We do it as part of an imaged workflow.

What does it cost?

Recovering a RAW or damaged-metadata BitLocker drive falls under single-disk recovery at £800 + VAT, 50% non-refundable on acceptance and 50% no fix, no fee. The drive must be removed from the computer and sent in on its own.

The data is behind the key, not gone.

Looking at it is free. Tell us what the recovery screen says, what happened just before it, and whether you can find your recovery key, and send proof the drive is yours. Back comes an honest account of what can be done and the one price to do it. Until then, reinstall nothing, reformat nothing, and clear no TPM.

0800 6890668