Inside Our Hacettepe Teknokent Data Recovery Lab: What HDD Platters Reveal Under the Microscope
A transparency gallery from DSET's Hacettepe Teknokent laboratory. An ISO 14644-1 Class 100 equivalent cleanroom, PC-3000 Express, DeepSpar Disk Imager, HDD platter microscope imagery, SSD NAND chip-off, RAID disk cloning, donor parts inventory, Cellebrite UFED, hash verification, and a corporate handover room. How a 99.4 percent success rate is possible. Why Hacettepe Teknokent is a strategic university ecosystem.
Inside Our Hacettepe Teknokent Data Recovery Lab: What HDD Platters Reveal Under the Microscope
The sentence we hear most often in the data recovery business is this: "The drive won't spin up, so everything inside is probably gone." Yet every day in our laboratory at Hacettepe Teknokent, we place under the microscope the platters of drives that others called "finished," and we see what is actually happening inside. This article is not a sales pitch. It is an honest attempt to open our doors and show you the inside of our lab, the equipment we use, the physical damage we encounter, and how we work.
We have been doing this for more than 20 years. To date we have recovered over 20,000 TB of data, and our laboratory success rate is 99.4 percent. These figures are not here to serve as a billboard, they are here to explain the process behind them. We will show you our microscope images, our cleanroom, our donor parts shelves, and our PC-3000 workstations. Because we believe transparency is missing in the data recovery industry. And when transparency is missing, everyone starts inventing their own myths.

Section 1: Inside Our Cleanroom, Everything About Dust
The distance between a mechanical HDD's platter and its read head is on the order of about 3 nanometers. The diameter of a human hair is around 80,000 nanometers. In other words, the air bearing on which the head flies above the platter is roughly one twenty-five-thousandth the width of a hair. This means that a single dust particle drifting through the air can stick to the platter and behave like a blade scraping across the entire surface.
That is why opening an HDD on an ordinary desk is a disaster from a data recovery standpoint. In our laboratory at Hacettepe Teknokent, we do this work at our laminar airflow cleanroom stations. The particle density we target is the equivalent of the international standard ISO 14644-1 Class 100 (Cleanroom Class 100). The official definition of the ISO 14644-1 standard can be found on ISO's own website. This classification requires keeping the number of particles of 0.5 micron and larger per cubic meter of air below a specific threshold.

Why does this standard matter so much? Because in many places that claim to do "data recovery," drives are opened in simple desktop environments, sometimes even next to a window or under the blast of an air conditioner. When a drive enters our lab, we first pass it through our static discharge station. Then our technician puts on a grounded wrist strap, wears gloves, and uses a mask at face level. The drive's cover is removed only under laminar airflow. This is not a detail that can be overlooked, it is a decision that can cut the chance of recovery in half.
Being inside the Hacettepe Teknokent campus gives us one more advantage: floor vibration levels. In industrial estates, beside main roads, or in buildings near underground passages, the precision of microscopy and mechanical repair becomes harder. On a university campus this physical background noise is far lower. For a detailed explanation of our laboratory location and process, you can also review our Ankara data recovery service page.
Let us illustrate the importance of cleanroom standards with an example. A 4 TB Western Digital drive once came to us after passing through another shop that had given up on it. When we placed the drive under the microscope, we saw numerous micro scratches on the platter. These scratches had been made in stages, meaning the drive had been opened more than once in a normal environment. With each opening, new particles settled on the platter, and when the drive was closed and powered up again, those particles were pressed against the platter by the head and dragged across it. As a result, the first recovery attempt cut the chance of success in half. This is why we tell our customers, "If your drive won't spin up, no one should open it. It should only be opened in the right laboratory, in the right environment."
Another component of cleanroom infrastructure is the air change rate. For a Class 100 equivalent room, an hourly air change of 240 to 480 is expected. This means the room's air is filtered roughly four hundred times every hour. Our filters are HEPA H14 class and capture more than 99.995 percent of 0.3 micron particles. Periodic inspections and replacements of the filters are kept on record.
Section 2: PC-3000 Express, the Common Language of the Industry
When you say "PC-3000" in the data recovery industry, everyone is talking about the same thing. It is a hardware and software platform produced by the Russia-based firm ACE Laboratory, used by nearly every professional data recovery company in the world. The official product family and technical documentation are recorded on the manufacturer's site: acelaboratory.com.
For us, the PC-3000 Express is not just a card, it is a surgical instrument set that lets us descend all the way to the firmware level of a drive. We can reach the "service area" of a drive, an area a normal computer never sees. We can directly intervene in parameters such as adaptives, the translator, SMART logs, defect lists, and head map information. These are inner layers that Windows does not know about and that a user's file manager never shows.

For example, a drive spins up but is not recognized by the BIOS. In most places the verdict is "the board is bad, let's swap the PCB." When we connect to the drive on the PC-3000, we see that the firmware's translator module is actually corrupted. The PCB is fine, the motor is fine, the heads are fine. Only the drive's internal address translation table has gone astray. With the PC-3000 we can rebuild it and make the drive accessible again. This work cannot be done with a desktop screwdriver and thermal paste.
We explain some of the work we do with the PC-3000 on a process-by-process basis in our data recovery guide. Especially in scenarios where "the drive reports a SMART error but still spins up," the range of firmware-side solutions is far wider than users imagine.
We want to underline one point: buying a licensed PC-3000 and receiving its training is a serious investment. ACE Lab provides every subscriber with annual updates, modules for new generations of drive families, and forum access. So you have every right to ask a place that claims to own a PC-3000 for its version information. An old, un-updated PC-3000 will not recognize a new generation Seagate or Western Digital drive.
A scenario we frequently encounter on the PC-3000 is the "SA read error." The SA, or service area, is the special region where the firmware modules a drive holds internally reside. The user can never see this area. When the SA is corrupted, the drive cannot even reach normal sectors, because it needs these modules to know where each sector is. On the PC-3000 the SA modules are listed and backed up one by one, and corrupted modules are replaced with modules from a donor drive. These operations require a firmware family library, and each family is unique. The firmware module library we have accumulated over the years is also part of our PC-3000 investment.
Another practical point is the "head map editing" we perform via the PC-3000. If 2 of an HDD's 8 heads are damaged, we temporarily disable those two heads through the PC-3000 and image the drive using only the 6 healthy heads. This way, the data read by the healthy heads is moved to a safe copy, and then in a separate stage we replace the damaged heads with a donor head stack and pull the remaining data as well. Unlike the "let me fix everything in one pass" approach, this two-stage method raises the success rate considerably.
Section 3: DeepSpar Disk Imager, the Other Side of the Industry's Coin
Just as the PC-3000 is powerful on the firmware side, the DeepSpar Disk Imager (DDI) is a device specialized in "extracting data from unreadable drives." The manufacturer is the Canada-based firm DeepSpar, and the official product documentation can be reached at deepspar.com.
The distinguishing feature of the DDI is this: when a normal computer cannot read from a drive, it gets stuck repeatedly on the same sector and exhausts the drive. If the drive is already dying, this exhaustion can kill it entirely. The DeepSpar Disk Imager, on the other hand, precisely tracks which sectors can be read and which resist. It starts with the areas that read easily, then comes back to the stubborn blocks. The technical term for the "extract data without killing the drive" strategy is exactly this.

A typical scenario we run with the DDI is this: a Samsung SSD or a traditional HDD comes in with unreadable bad sectors inside. The customer has not taken a backup, and nothing has been written over it. With the DDI we "image the drive sector by sector." Our goal is not to read the drive but to physically transfer a copy of the drive onto another donor drive. All subsequent recovery attempts are performed on this safe image rather than on the original drive.
For the peculiar behaviors of Samsung SSDs, you can also see our Samsung SSD data recovery guide. Because the TRIM command, wear leveling, and garbage collection processes in SSDs behave very differently from HDDs, we use the DDI together with the PC-3000 SSD module.
The DDI also produces a concrete report for the customer: how many sectors were read fully, how many partially, and how many could not be read at all. This report is not just for our own archive, it is also evidence for the customer's insurance claim, expert witness file, or corporate audit.
Another critical feature of the DeepSpar Disk Imager is "head selective imaging," that is, head-selective cloning. Because an HDD contains multiple heads, if one of them is damaged, attempting to read the track written by that head can lock up the entire process. With the DDI we first clone only the tracks of the healthy heads. We then extract the damaged head's tracks in a separate session, after a donor part has been installed if necessary. This strategy lets us give the customer a concrete result like "85 percent of the data is complete, 15 percent partial" instead of saying "all the data is lost."
We also use the DDI for SSD cloning. The difference between SSDs and HDDs is this: in an SSD there is no concept of a bad sector, there are "ECC uncorrectable" errors instead. The SSD controller flags faulty blocks internally and does not surface them to the user. The DDI's SSD module interprets these controller responses and reports at which LBA real data loss occurred. This is indispensable for giving an objective answer to the question "how much can be recovered" in SSD data recovery.
Section 4: How a Head Crash Looks Under an HDD Platter Microscope
Now we have reached the section that gives this article its title. What do we see when an HDD platter is placed under the microscope? To answer that, we first need to understand how an HDD gets damaged.
While mechanical HDDs operate, the heads fly above the platter. When the drive takes an impact, when there is a power outage, or when the head is worn out, the head can crash into the platter. We call this event a "head crash." In the instant of the crash, within a thousandth of a second, the upper magnetic coating of the platter is scraped away by the head. Beneath the platter, the aluminum or glass substrate remains.

What do we infer when we see this mark under the microscope? First, the geometry of the mark tells us the center of the crash. If the mark is circular and at a certain radius of the platter, the head was jammed at that radius. Second, the depth of the mark matters. A surface scrape means only part of the magnetic layer is gone. In that case it may still be possible to read some of the data. If the mark has cut all the way down to the aluminum, we have lost that track entirely.
Third and most importantly, we look at whether there is "magnetic dust" scattered across the platter. The crashed head particles travel across the platter. Even if you install a new head stack on the drive, the new head will also crash as long as that dust remains. This means the platter requires careful cleaning under laminar airflow. Sometimes platter cleaning is a 2 to 3 day process in its own right.

The most common mistake we see on the customer side is this: when an HDD starts making noise, when a crackle or clicking sound appears, people try to power up the drive again and again. Each power-up crashes the head into the platter once more. Every time you give the drive power, you compound the damage. The most important thing to do before bringing a noisy HDD to our lab is to shut it down immediately and not touch it.
Another case type we see in the microscope images is "stiction." Stiction is a condition where the heads cannot retract to the parking zone when the drive is powered off. The heads remain stuck to the platter. When the drive is powered up again, the motor tries to spin but the stuck heads drag across the platter, wearing out both the motor fuse and that part of the platter. In these cases, opening the drive and manually moving the heads to the parking zone is an operation that requires a microscope and special tweezers. If this operation is attempted outside laminar airflow, both the heads and the platter are lost completely.
The platters themselves also age over time. The magnetic coating of drives made in the early 2000s was thicker and more durable than that of modern drives. In return, density was also lower. In modern high-density drives the magnetic layer on the platter is much thinner and therefore more sensitive to mechanical stress. For this reason, the damage pattern under the microscope of modern drives with a density above 1 TB differs from that of older drives. Our technicians have learned through experience what behavior to expect for which manufacturer, which year, and which density.
Section 5: The SSD NAND Chip-Off Process, What Happens at Our BGA Reflow Bench
If HDDs have platters, SSDs have NAND chips. When an SSD dies electrically, when the controller chip burns out, when there is a short circuit on the board, the data is in fact still sitting inside the NAND chips. The task is to separate these chips from the board and read them with special readers. We call this process "chip-off forensics."
The chip-off process is not simple. NAND chips are soldered to the board using BGA (Ball Grid Array) technique. That is, there are dozens of tiny solder balls under the chip and they are invisible. To separate the chip from the board we apply controlled heat, and during this process we must neither burn the chip nor deform the PCB beneath it. That is why we have an infrared reflow station.

After removing the chip, the job is not over, the real work is just beginning. Because a NAND chip in its raw form does not contain a readable file system. In these chips, manufactured according to JEDEC standards, data is distributed according to the controller's "Flash Translation Layer" (FTL) algorithm. So the pieces of a 1 GB file may be written to physical blocks far apart from one another. JEDEC standards define the technical specifications of flash memory and are the common language of the industry.
After the chip-off we have the raw bit dump of the NAND. This must be reassembled according to the controller's algorithm. ECC corrections, scrambling, interleaving, wear leveling tables... All of this is solved through reverse engineering. That is why chip-off is not a matter of "I removed the chip and the data came out," it is "I removed the chip, now I am in a three-week process of making sense of the data."
NAND chip-off can also come into play in phone and tablet data recovery processes, especially in water-damaged or burned devices. We occasionally use this approach in our iPhone data recovery and Android device processes, but our first preference is to extract the data with logical methods without damaging the device.
Another layer we encounter in SSD data recovery is the encryption applied by modern manufacturers. Many modern SSDs ship with hardware encryption (Self-Encrypting Drive, SED). That is, the data is written to the NAND already encrypted, and the key is stored inside the controller. This means that when the controller burns out, the key can be lost. So in modern SSD recovery, rescuing the controller or obtaining the key externally is a different area of expertise from HDD recovery. Our chip-off workflow takes this difference into account: taking the raw dump of the NAND is not enough, the controller responses must also be analyzed.
On Apple devices, NAND chip-off is almost entirely useless. Because the Secure Enclave key lives inside the silicon and cannot be extracted. So on devices like the iPhone, chip-off is not an option, and logical and backup-based solutions are the only path. On Android devices the situation varies by manufacturer. On devices with Samsung Knox active, hardware encryption again comes into play. On older or mid-range Android devices, chip-off is still a viable method.
Section 6: The RAID Disk Cloning Station, Reading Four Drives in Parallel
The most frequent job from corporate customers is the recovery of RAID arrays. RAID 0, RAID 1, RAID 5, RAID 6, RAID 10, RAID 50, RAID 60... The math of each is different. But they all share one property: the first thing to do is to take an exact copy of all of them without independently intervening on any single drive.
For this we have a 4-drive parallel cloning station. We can clone 4, or even up to 8 drives in parallel at the same time. This not only saves time, it also preserves the "temporal consistency" of the RAID set. In a RAID 5 array, if one drive failed seventy days ago and another failed yesterday, we see the two drives with different time stamps. We do not want to lose these stamps during cloning.

We have written separately and in detail about RAID 5 data recovery, but here we want to emphasize this: the most common customer mistake in RAID recovery is starting a "rebuild." A drive fails, a spare is installed, and the system automatically tries to rebuild the RAID. If a second drive is also tired and that drive crashes during the rebuild, the RAID 5 array dies completely. On the RAID sets that come to our lab, we first allow no write operation on any drive. Read only, clone only.
After cloning is complete, the original drives are placed in a secure safe. All analysis, array reassembly, parity calculation, and data extraction are performed on the copy drives. When we hand over to the customer, we even return their original drives in the same condition they arrived in. This is not a practical preference, it is a matter of principle.
The technical problems we encounter in RAID recovery fall into these categories: controller changes with miscalculated parity, RAID metadata corrupted in the raw disk header, incorrectly determined stripe size, and loss of disk order. Each of these requires a separate solution approach, and none of them fits the "one-click rebuild" template.
Section 7: Our Donor Parts Inventory, Why We Still Keep 2010 Models
One of the sights you will see when you visit our laboratory is our donor parts shelves. Here we keep spare parts for thousands of HDD and SSD models produced since the 2010s: PCB boards, head stack assembly units, motor parts, platter templates, and in some cases complete dead drives.

Why? Because in HDDs even the same model can carry a different firmware version, a different PCB revision, and a different head stack design across different production batches. Manufacturers such as Western Digital, Seagate, Toshiba, Hitachi, and HGST hold calibration data called "adaptives" between the PCB and the platter. When the PCB is replaced without transferring this adaptive data, the drive will not work, and in some cases it can even cause physical damage to the platter.
This is why the search for a "donor drive" requires detail not just at the "same model" level but at the level of "same production week, same PCB revision, and if possible the same head map ID." That is why we have grown our donor inventory over the years. For some old 2.5 inch laptop drives, since production has been discontinued, there are parts that now remain only on our shelves.
When we perform a PCB transfer from a donor, a ROM chip transfer is also done. Desoldering the ROM chip from the old PCB and soldering it onto the donor PCB guarantees that the calibration data stays with the correct drive. This operation is done under the microscope at a hot air soldering station and usually takes 30 to 45 minutes.
A head stack transfer is a far more delicate job. To remove the heads from the platter without damage, a special tool called a head comb is used. The heads are pulled to the parking zone without touching the platter, the comb is placed, and then the head stack assembly is removed as a single piece. The donor drive's head stack is removed the same way and installed in the patient drive. This entire process is a matter of minutes of precision under the cleanroom, with gloved hands.
Section 8: Mobile Device Digital Forensics, Cellebrite UFED Touch
Data recovery no longer means only HDDs and SSDs. Phones, tablets, smartwatches, drones, vehicle computers... They all contain data and they can all generate a recovery request. That is why we also have a Cellebrite UFED Touch in our laboratory. Cellebrite is the most widely used mobile extraction platform in the world in both digital forensics and corporate data recovery.

The work we can do with the UFED falls into four main categories: logical extraction (the data the phone normally shows), file system extraction (including app databases), physical extraction (raw memory dump), and advanced extraction (for locked devices). Each requires different legal and technical conditions.
The point we want to emphasize here is this: in mobile device data recovery, customer consent and ownership verification are non-negotiable for us. We require the person bringing the phone to prove they are the owner, and if they are not the owner, to present a power of attorney. Otherwise we do not accept the job. This is both a legal and an ethical requirement.
On iPhones, some extraction methods do not work because of the Secure Enclave. In these cases we resort to side paths such as a logical backup (via an iTunes/Finder backup) or restoring from iCloud. On the Android side, because of the greater diversity of manufacturers, a different approach may be needed for each device. For more information about our mobile device processes, you can review our iPhone data recovery page.
Section 9: Hash Verification and Chain of Custody, the Ethics of Data Recovery
Data recovery is not merely about bringing data back. It is about being able to prove, while bringing the data back, that the data remains faithful to the original, that no bits were lost, and that no manipulation took place. That is why every one of our job files includes a hash verification step.
The process works like this: when the customer brings the drive, at the moment of the first cloning we take SHA-256 and MD5 hash values from both the original drive and the clone. These values enter the record and become a signed copy with the customer. All subsequent operations are performed on the clone. For the delivered data we again produce a hash value and give it to the customer. So the customer can cryptographically verify the relationship between the data we deliver and the original.

This process keeps us aligned with international digital evidence acceptance guidelines, foremost among them NIST SP 800-88 "Guidelines for Media Sanitization." NIST SP 800-88 is actually about media sanitization, but it also details the principles of media integrity and verification. The inverse of data recovery, the data-protection side, requires the same discipline.
Chain of custody is critical especially in expert witness and legal processes. From the moment a drive enters the laboratory, who did what, when, and with which equipment is all recorded. Even which safe the drive was physically held in is logged. This way, when requested by a court, we can present a report. For details about our expert witness report processes, you can review our structure of an expert witness report page.
A question customers often ask is: "While you recover my data, do you see it too?" The answer must be honest: technically the technician has theoretical access, but our company policy and contracts strictly prohibit examining the content of the data. Only to verify file integrity and readability, certain files (usually standard office or media files) are opened on a sample basis, and no other intervention is made. All laboratory computers operate in compliance with our KVKK and confidentiality policies.
Section 10: The Corporate Handover Room, Encrypted Drive Transfer
We have a separate handover room for corporate customers. The reason is not just comfort, it is confidentiality. When a corporate customer brings in a drive, the content of that drive may be that organization's trade secret. Customer records, financial data, source code, customer contracts, personnel files... It is not professional for this information to change hands in front of other corporate customers.

The operation performed in our handover room is this: we write the customer's recovered data to the medium the customer requests. Usually this is an external drive encrypted with AES-256 or a corporate NAS. The customer's representative sets the password, and we only ask for a signature on the "I have received the data" record. We do not even keep the password ourselves, because it is not something we should keep.
For some corporate customers we also carry out the destruction of the original drives. This destruction is performed in accordance with NIST SP 800-88 standards. Use of a degausser for magnetic media, controlled physical destruction for SSDs. A destruction certificate is given to the customer, an official document they can present in their audits.
Recovery processes for formatted drives are a topic seen especially often on the corporate side. You can find a separate piece of work we did on this subject in our article can formatted photos be recovered.
How a 99.4 Percent Success Rate Is Possible
As a company we state our laboratory success rate as 99.4 percent. This figure is not the gloss of marketing language. Behind this figure are the following core principles:
First, the preliminary analysis stage being free and honest. When the customer brings the drive, we first examine the state of the drive. If the data is not recoverable, we say so clearly. We do not take jobs on a "let's try and see, it works if it works" basis. So every case we begin is a case whose chance of success has been concretely assessed. This selection feeds the statistic.
Second, investing in the best equipment in the industry. PC-3000 subscription fees, the DeepSpar Disk Imager license, Cellebrite UFED, the BGA reflow station, microscope systems, the ISO 14644-1 equivalent cleanroom infrastructure... These are not small investments. But without these investments the success rate cannot be achieved.
Third, the donor parts inventory. Keeping spare parts for discontinued drives costs both space and money. But when 12 years of a customer's data is at stake, a 12-year-old donor part becomes very valuable to us.
Fourth, training and continuity. The technicians doing this work need to accumulate 5 to 10 years of experience. The same quality cannot be achieved in places with high staff turnover. We grow our team by keeping it for the long term and by participating in international training.
Fifth, ethical boundaries. Some jobs can technically be done but we do not accept them legally or ethically. This volume of refused work may not appear at other companies, but for us it matters in terms of continuity and reputation.
It would be wrong to read the 99.4 percent rate as "we recover every drive by miracle." The correct reading is this: in the vast majority of the cases we begin, we return a concrete result to the customer. The other 0.6 percent are mostly cases beyond the limits of engineering, where the platter has suffered catastrophic damage or the NAND chips have burned out.
Why Hacettepe Teknokent Is Strategic for Us
In the final section we want to talk about our laboratory location. Being inside Hacettepe Teknokent is not coincidental, it is a strategic decision.
First, proximity to the university ecosystem. Being on the same campus as departments such as Hacettepe University's computer engineering, electrical and electronics engineering, and materials engineering creates an opportunity for technical discussion and consultation. In some difficult cases we get independent assessments from academics.
Second, infrastructure quality. In the Teknokent buildings, redundant electrical infrastructure, uninterrupted internet, fiber connectivity, security, and physical access control are provided as standard. Rather than building this infrastructure from scratch, benefiting from the campus infrastructure is both economical and secure.
Third, security. Among our customers are public institutions, financial organizations, defense industry companies, and international firms. These customers scrutinize the laboratory's security standards. The entry control, camera infrastructure, and physical security of the Teknokent campus make passing these audits easier.
Fourth, Ankara's central location. It is relatively easy for drives to reach Ankara from every region of Turkey. Air and road logistics are well developed. For work packages coming from abroad, the proximity of Esenboğa Airport and Ankara's central role for customs processes work in our favor.
We accept visits to our laboratory at Hacettepe Teknokent by appointment. For our corporate customers, showing our processes on site, introducing the equipment, and answering questions both builds trust and, for us, matters for the sake of transparency in the work. If your drive situation is not urgent and you would like to see on site how the work is done, you can make an appointment for a lab visit.
Contact and Lab Visit
If you would like to reach our laboratory at Hacettepe Teknokent in Ankara or make an appointment for a lab visit:
Location: Hacettepe Teknokent, Ankara
Phone: +90 536 662 38 09
Lab Visit: Accepted by appointment. Our corporate customers can have the opportunity to see our technical equipment and processes on site.
Our Other Services:
- Data Recovery Guide
- Samsung SSD Data Recovery
- RAID 5 Data Recovery
- iPhone Data Recovery
- Recovery of Formatted Photos
- Ankara Data Recovery
- Structure of an Expert Witness Report
The biggest fallacy in the data recovery industry is the expectation that "a noisy drive will fix itself in a few hours." In reality, without the right equipment, the right cleanroom, the right donor part, and the right process, data is lost permanently. In our laboratory at Hacettepe Teknokent we sustain this discipline every day. Before bringing your drives, please power them off, do not shake them, do not spin them up at all, and reach out to us. The first minute of your data is the most precious minute.
More than 20 years of experience, over 20,000 TB of recovered data, and a 99.4 percent laboratory success rate are not just numbers, they are a promise renewed in every drive that enters the lab each day. Transparency, ethics, and engineering. That is how we define our work.
Kimliğinizi doğrulayın
Yetkilendirilmiş erişim alanı. Tüm giriş denemeleri kayıt altına alınır.