WeRecoverData

Enterprise Storage Data Recovery

Enterprise arrays fail differently from servers and workstations. The drives are frequently healthy while the array's own structures — pools, aggregates, chunklets, parity groups, distributed objects — are what has been lost. WeRecoverData evaluates these platforms at the layer where the failure actually occurred, then reconstructs upward through the file systems, virtual machines and databases that depend on them.

Each vendor uses a different on-disk architecture, and the differences matter more than the hardware. A Dell EMC dynamic pool, a NetApp WAFL aggregate, an HPE 3PAR chunklet layout, an IBM DRAID pool, a Hitachi parity group, a Purity log-structured volume and a vSAN object tree all require distinct reconstruction methods. Identifying the platform and its generation accurately is the first stage of every evaluation.

Most enterprise cases are multi-layer. Recovering the LUN or aggregate is only the beginning; the requested data usually lives inside VMFS datastores, VMDK or VHDX files, NTFS, XFS or ext4 file systems, Oracle or SQL Server databases, Exchange stores, or clustered file systems such as GPFS and Lustre. Those layers are reconstructed after the storage layer is resolved.

Work is performed on images, not on the original media. Original drives are treated as evidence-grade sources, documented in their original slot order, and are not written to during evaluation or recovery.

Cases involving encrypted arrays, self-encrypting drives or external key managers require the key material and key manager configuration alongside the media. Without them, an encrypted pool cannot be interpreted regardless of the physical condition of the drives.

Platforms by Vendor

What Not To Do Before an Evaluation

Our Evaluation and Recovery Process