Controller · flash · map · pads · needles · image
How a memory card is recovered, from the reader to the monolith. Every step, in the order the bench takes them, for anyone who has just been asked to format a card.
A memory card is recovered without writing a byte to it. It is imaged on hardware that controls every read; the file tables are rebuilt on the image, or the photographs and video carved from it by their own signatures; a clip cut short by a dead battery is rebuilt from a reference clip; and when the controller has stopped, the flash is read around it, through the chips on a board or the test pads on a monolith, and put back together in software. This page says how each step is done and why, plainly, for anyone whose camera has just said card error and who wants to know what is about to happen to the card before deciding whether to send it.
Rather talk it through? An engineer answers the bench line
0800 6890668
Step one: what is inside, and what fails.
Every memory card is three things. Flash memory, where the data lives, in pages grouped into blocks that wear out as they are written. A controller, a small processor that answers the camera or the computer, translates the addresses they ask for into physical places in the flash, spreads writes across the flash so that no block wears out first, scrambles the data so that no pattern wears the cells unevenly, adds error-correction codes to every page, and keeps spare blocks to replace the ones that fail. And a map, the table the controller keeps in the flash to remember which address lives where. What fails is nearly always the controller or the map, or the file tables the camera keeps on top of both; the flash itself holds what it was given, and the whole of recovery is a way of getting at it when the thing that was supposed to hand it over no longer will.
The package decides how. A CompactFlash card and an older or larger SD card are a circuit board with the controller and the flash as separate chips, and the flash chips can be removed and read directly. A microSD, a modern SD and the smallest USB sticks are monoliths, one sealed block with everything inside and nothing to remove, and the flash is read through the test pads the factory left on the back for its own programming. CFexpress, XQD, CFast and SD Express cards are solid-state drives in a card's shape, with NVMe or SATA controllers and firmware, and are recovered with the SSD bench's tools. The free look reads the card's identity and says which it is.
Step two: the image.
Nothing is done to a card that answers at all until it has been copied. It goes into the reader it needs on a hardware imager that controls how long each read may take and how many times it is retried, never a laptop slot, and is imaged sector by sector with its weak areas last and a map kept of every sector that could not be read. A card that is slow, that drops out, or that has locked itself read-only is imaged the same way in short passes with the power cycled between them, because each pass is a chance to read what the last could not and each cycle is a chance for the controller to come back. Nothing is written to the card, then or later, and every step after this is done on the image.
Step three: the tables, and carving.
A camera, a phone or a dashcam keeps a FAT32 or exFAT file system on the card: tables at the start that say which clusters belong to which file, and directory entries that give each file its name, its dates and its first cluster. A write interrupted by a dead battery tears them, a format rewrites them, a delete marks entries free. On the image, the surviving entries and allocation chains are read and the tables rebuilt where they are damaged, which gives files back with their names. Where the entries are gone, the photographs and video are carved: every JPEG, every CR3 and NEF and ARW and RAF, every MP4 and MOV begins with a signature the bench knows, and each is cut out of the data area from its signature to its end and given its date from the metadata inside it. Carving loses names and keeps everything else, and a card that was formatted and put away comes back nearly whole.
Step four: video.
A camera writes a video's frames as it records and its index, the table that says where each frame is, when it stops. A battery that dies, a card that halts, a drone that hits the ground before the end leaves a file full of good frames that no player will open. On the image, the frames are found and the index rebuilt from a reference clip recorded by the same camera at the same resolution and frame rate, which is why the form asks for one; with it, the clip plays. Fragmented video, where a camera scattered a clip across a card already half full, is reassembled from its parts when the tables survive and is the hardest case when they do not.
Step five: chip-off, on a board.
When the controller on a CompactFlash card, an older SD card or a USB stick has stopped, the flash chips on its board are desoldered and read on a programmer, which gives the raw contents of every page. The raw dump is not the card: it is scrambled with the controller's key, interleaved with error-correction data, and laid out in the controller's own page and block order, with the map somewhere inside it. The bench's software knows the schemes the common controllers use and solves each in turn, descrambling, correcting, reordering, rebuilding the map, until a virtual card emerges that a file system can be read from. Then step three begins again on the virtual card.
Step six: the monolith, through the pads.
A microSD has no chips to remove. On the back, under the coating, are rows of tiny test pads the factory used to program the card, and they connect to the flash inside. The coating is removed with care, each pad is identified against a database of known pinouts for that make and generation or mapped by hand with a probe, and a needle adapter or fine wires are connected to the pads that matter, between fifteen and twenty on a typical card by one recovery house's count. Through them the raw flash is read out around the dead controller, and the dump is solved as in step five. SanDisk, Samsung, Phison and Silicon Motion each have their own scrambling, error correction and page ordering, and SanDisk's flash speaks its own interface; the tools the trade uses, PC-3000 Flash with its needle boards, Rusolut's VNR, Flash Extractor, carry the databases and the solvers. A snapped card is the same job on the surviving pads, provided the flash die inside is whole; a die cracked through is beyond anyone, and the bench can usually tell under magnification at the free look.
Step seven: the cards that are drives.
CFexpress, XQD, CFast and SD Express cards are NVMe or SATA solid-state drives with their own firmware and their own translation tables, and a body that stops recognising one after a firmware update has a handshake fault with the data unchanged. The bench talks to the controller in its own firmware modes where it can, and reads the flash and rebuilds the translation where it cannot, with the SSD bench's tools. They are priced in the top band for that reason.
What cannot be done.
A full format on Windows, which writes zeros over the whole card. Footage a dashcam's loop has overwritten. A flash die cracked through. A card adopted as internal storage by an Android phone that has died or been reset, because it is encrypted to the phone and Android says it cannot be mounted elsewhere. A BitLocker or encrypted drive without its key. Whatever was written past the real capacity of a counterfeit, which was never stored. Each is found at the free look and said plainly, and on most jobs no data means no bill.
How long it takes.
Imaging a card that reads takes hours; a failing card imaged in passes takes a day or two. Rebuilding tables and carving takes a day; rebuilding video longer where there are many clips. Chip-off and monolith work takes days, most of them in solving the dump. A card that reads is usually 3–5 days at the bench after the free look, a monolith or a PCIe card 5–10 days at the bench, and the figure says which yours is.
The questions that come up first.
Is anything written to my card?
No. It is imaged and every step after that is done on the image, with files carved or tables rebuilt on the copy. The original goes back to you untouched.
Why can recovery software not do what the bench does?
Software reads a card only while the controller presents it to the computer as a drive. It cannot reach the flash behind a dead controller, cannot descramble a raw dump, cannot measure a counterfeit, and every scan of a weak card is thousands of reads of its weakest blocks. On a card that reads cleanly, software is a fair first step, on an image.
Can you recover a snapped microSD?
If the flash die inside is whole, yes, through the surviving test pads. If the die has cracked through, no, and the free look says so with nothing to pay.
Does any of this cost me anything to find out?
No. The free look identifies the card, measures its real capacity and reads its state, and one figure follows in writing: £149 + VAT if a reader sees it, £299 + VAT if none does, from £449 + VAT for the PCIe cards.
Now you know what the bench is about to do.
Send the form with the card, the device and what it says, and the first look tells you which of these your card needs, and what it would cost.