Coming Soon

Recovery is in final development. Be the first to know when it launches.

Skyfire Recovery

Get it back.

Forensic-grade file recovery for every major filesystem. Rust engine. Hash-chained chain of custody. Ed25519-signed output. Court-admissible.

Personal · Professional · Government & Law Enforcement

Forensic capabilities

Who uses Recovery

Three audiences.
One engine.

PERSONAL

Accidental deletion

Formatted a drive by mistake. Deleted photos that weren't backed up. SD card stopped mounting. Recovery finds what the filesystem no longer knows is there.

PROFESSIONAL

IT, legal discovery, compliance

eDiscovery, internal investigation, compliance audit, data breach response. Full chain of custody, signed manifests, case management — output you can hand to counsel.

GOVERNMENT

Law enforcement, government

Digital forensics investigations. Write-protected acquisition, multi-algorithm hashing, hash-chained audit log, SQLite case database. Output defensible in court.

Forensic engine

What's actually built.
Verified from source.

Every capability below is verified from the Rust engine and Swift forensic layer source code.

WRITE

Write-protected acquisition

Source opened O_RDONLY at the engine level. If write access is granted, the scan aborts. Source, working, and output directories are enforced as separate paths — the original is never touched.

HASH

Multi-algorithm source hashing

SHA-256, MD5, SHA-1, and SHA-512 of the complete source before any extraction. All four hashes recorded in the scan result. Covers every hash standard courts and agencies may require.

CHAIN

Hash-chained audit log

Every action logged with ISO 8601 timestamp. Each entry hashed against the previous (SHA-256 chain). Any single modification — even a whitespace change — breaks the chain and is detected by the verifier.

CARVE

Three-level file carving

Level 1: header/footer scan. Level 2: container-aware (ZIP internals, MP4 atom tree, SQLite pages, PDF xref). Level 3: fragmented file reconstruction using entropy continuity scoring and block adjacency — crosses bad sectors when confidence exceeds threshold.

FS

Six native filesystem parsers

APFS, HFS+, NTFS, exFAT, FAT32, ext4 — each a purpose-built Rust parser. Plus GPT and MBR partition table parsing. Reads filesystem metadata directly rather than relying on OS drivers.

SIG

Ed25519-signed manifests

Output bundle includes manifest.json (per-file SHA-256 hashes), manifest.sig (Ed25519 signature), and public.key. skyfire-verify confirms authenticity: exit 0 = authentic, non-zero = tampered, with specific failure reason.

CASE

SQLite case database

Every session, scan event, and recovery action logged to a persistent case database. Case number, case name, examiner field. Full case history — every action traceable.

RUST

Memory-safe Rust engine

The recovery engine is written in Rust. No buffer overflows, no use-after-free, no memory corruption vulnerabilities. Evidence integrity isn't just about procedure — it starts with the language.

Forensic output bundle

Every recovery session produces a verifiable output bundle. Run skyfire-verify <output> to confirm integrity before transfer.

extracted/

Recovered files from filesystem metadata

carved/

Signature-carved files from unallocated space

manifest.json

File inventory with per-file SHA-256 hashes

manifest.sig

Ed25519 signature over manifest.json

public.key

Verification key (also published separately)

audit.log

Hash-chained audit trail of all actions

case.db

SQLite case database (session + events)

Filesystem support

APFSApple — all modern Macs, iOS
HFS+Legacy macOS, older Macs, Time Machine
NTFSWindows — external drives, Boot Camp
exFAT / FAT32USB drives, SD cards, cameras
ext4Linux — NAS drives, Raspberry Pi, servers

GPT + MBR partition table parsing built in.

Reads partition structure directly — does not rely on OS filesystem drivers.

Pricing

Personal. Professional.
Government & Enterprise.

Personal

$29

one-time

For accidental deletion, formatted drives, and personal data loss.

  • File carving (all three levels)
  • Six filesystem parsers
  • S.M.A.R.T. monitoring
  • Photo, document, archive recovery
  • Preview before recovery
  • Chain of custody documentation
  • Case management
  • Signed manifests
  • CLI verifier

Professional

$299

per year

For IT professionals, legal discovery, compliance investigations, and digital forensics.

  • Everything in Personal
  • Write-protected acquisition (enforced)
  • Multi-algorithm source hashing (SHA-256, MD5, SHA-1, SHA-512)
  • Hash-chained audit log
  • Ed25519-signed manifests
  • skyfire-verify CLI tool
  • SQLite case database
  • Case number + examiner fields
  • Output bundle for court submission

Government / Enterprise

Custom

per seat / annual

For law enforcement, government agencies, and enterprise security teams.

  • Everything in Professional
  • Volume licensing
  • Priority support and SLA
  • Compliance documentation package
  • Dedicated onboarding
  • Custom deployment options
Contact us →

Pricing finalised at launch. Personal pricing verified against $29. Professional and Government pricing reflects forensic capabilities and use case.

Also in FamilyCloud

Recovery runs continuously inside FamilyCloud.

FamilyCloud users get continuous protection — point-in-time restore, ransomware detection, automatic healing. Recovery is already running. No extra setup.

Learn about FamilyCloud →