The range

Eight products, two families, one engine

RecoverYantra is data recovery; SakshyaYantra is digital forensics. Every product runs the same tested core; what differs is which workspaces the build contains. Each page lists the workspaces included, what is new in this release, and how the product is supplied.

SakshyaYantra - mark and wordmark SakshyaYantra

Digital forensics

Evidence from the disk to the courtroom: verified acquisition, a hash-chained trail, video evidence with the frame pack, and the draft certificate under S.63(4) of the Bharatiya Sakshya Adhiniyam 2023.

What each product does

Eight products, each built for its job.

Every list below is generated from the catalogue the products are built from, so a card cannot name a workspace the build does not contain. The products are not alternatives to each other: a recovery lab buys the jobs it does, and each product is complete for its own.

RecoverYantra

RecoverYantra Suite

The complete recovery range in one application

Built for Recovery labs, service providers and IT departments that handle every category of case and cannot choose their tools in advance.

19 things it does

  • Recover files from disks, cards and images
  • Ransomware triage and recovery
  • Database row extraction
  • Mailbox recovery (Outlook PST/OST, mbox, Maildir)
  • Image a failing drive
  • Phone acquisition and data recovery
  • CCTV and DVR footage
  • Image a drive over the network
  • Bootable rescue USB
  • Cloud account recovery
  • Repair broken video
  • Secure erase and certificate
  • Detect every connected device, with a report
  • Drone flight log and video telemetry recovery
  • RAID and storage-pool reassembly
  • Chip-off and rig-dump reconstruction
  • Industrial robot and controller incident data
  • Vehicle data recovery
  • Browse the index and extract ticked files and folders
Licence key, sold by the driveExplore Suite
RecoverYantra

RecoverYantra Imager

Check the drive, copy it safely, take the files you need

Built for Technicians and IT staff who image drives and phones before recovery or examination, anyone deciding whether a drive is worth sending to a lab, and anyone who needs one file or folder back without a full recovery.

4 things it does

  • Image a failing drive
  • Create a phone image
  • Detect every connected device, with a report
  • Browse the index and extract ticked files and folders
Free for everyone, no licence keyExplore Imager
RecoverYantra

RecoverYantra Mobile

Get the data off the phone

Built for Data-recovery labs and shops handling phones - locked, dead or with the owner's consent - that need the files off, not a report.

3 things it does

  • Phone acquisition and data recovery
  • Create a phone image
  • Detect every connected device, with a report
Licence key, sold by the driveExplore Mobile
RecoverYantra

RecoverYantra Wipe

Drive sanitisation with verification and certificate

Built for IT teams and organisations that must retire storage with a record proving it was cleared.

1 things it does

  • Secure erase and certificate
Licence key, sold by the driveExplore Wipe
SakshyaYantra

SakshyaYantra Examiner

The computer-forensics bench

Built for Computer-forensics examiners and digital-forensics laboratories - the bench a lab would otherwise run on EnCase, FTK or X-Ways.

24 things it does

  • Recover files from disks, cards and images
  • Database row extraction
  • Mailbox recovery (Outlook PST/OST, mbox, Maildir)
  • Image a failing drive
  • Forensic examination and reporting
  • Detect every connected device, with a report
  • Drone flight log and video telemetry recovery
  • RAID and storage-pool reassembly
  • Chip-off and rig-dump reconstruction
  • Industrial robot and controller incident data
  • Vehicle data recovery
  • Case hub: cases, versions and locks
  • Ask the case (AI observations after a sealed reading)
  • Cross-case lookup
  • Known-file hash sets
  • Foreign image and dump ingest
  • Indexed keyword search
  • Link analysis
  • Memory (RAM) analysis
  • Steganalysis
  • Timeline across artefacts
  • Evidence viewer
  • YARA scanning
  • Browse the index and extract ticked files and folders
Licence key, sold by the driveExplore Examiner
SakshyaYantra

SakshyaYantra Media

Video and image evidence, examined

Built for CCTV and video examiners, image-authenticity analysts and forensic media laboratories - the work a lab would otherwise take to Amped.

19 things it does

  • Image a failing drive
  • CCTV and DVR footage
  • Forensic examination and reporting
  • Detect every connected device, with a report
  • Image and video authenticity examination
  • Case hub: cases, versions and locks
  • Ask the case (AI observations after a sealed reading)
  • Cross-case lookup
  • Evidence export and the draft S.63(4) certificate
  • Footage intake, decode and conversion
  • Media gallery triage
  • Location data
  • Foreign image and dump ingest
  • Media enhancement lab, chain shown
  • Number-plate assistance
  • Recorder registry and intake
  • Redaction under review
  • Frame-exact video review
  • Evidence viewer
Licence key, sold by the driveExplore Media
SakshyaYantra

SakshyaYantra Mobile

Acquire the phone as evidence

Built for Examiners and forensic laboratories acquiring mobile evidence, from a police unit to an enterprise investigation.

10 things it does

  • Phone acquisition and data recovery
  • Create a phone image
  • Forensic examination and reporting
  • Detect every connected device, with a report
  • Case hub: cases, versions and locks
  • Ask the case (AI observations after a sealed reading)
  • Cross-case lookup
  • Foreign image and dump ingest
  • Steganalysis
  • Evidence viewer
Licence key, sold by the driveExplore Mobile
SakshyaYantra

SakshyaYantra Enterprise

Evidence, from the disk to the courtroom

Built for Examiners, investigators, incident response teams and forensic laboratories - from a single case to an organisation-wide estate.

39 things it does

  • Recover files from disks, cards and images
  • Database row extraction
  • Mailbox recovery (Outlook PST/OST, mbox, Maildir)
  • Image a failing drive
  • Phone acquisition and data recovery
  • Create a phone image
  • CCTV and DVR footage
  • Image a drive over the network
  • Cloud account recovery
  • Forensic examination and reporting
  • Detect every connected device, with a report
  • Drone flight log and video telemetry recovery
  • RAID and storage-pool reassembly
  • Chip-off and rig-dump reconstruction
  • Industrial robot and controller incident data
  • Vehicle data recovery
  • Image and video authenticity examination
  • Case hub: cases, versions and locks
  • Ask the case (AI observations after a sealed reading)
  • Cross-case lookup
  • Evidence export and the draft S.63(4) certificate
  • Footage intake, decode and conversion
  • Media gallery triage
  • Location data
  • Known-file hash sets
  • Foreign image and dump ingest
  • Indexed keyword search
  • Link analysis
  • Media enhancement lab, chain shown
  • Memory (RAM) analysis
  • Number-plate assistance
  • Recorder registry and intake
  • Redaction under review
  • Frame-exact video review
  • Steganalysis
  • Timeline across artefacts
  • Evidence viewer
  • YARA scanning
  • Browse the index and extract ticked files and folders
Licence key, sold by the driveExplore Enterprise
Common to every product

True of every product.

Properties of the core, so they hold whichever product you run.

Read-only on the source

Recovery never writes to the drive it is reading, and the application refuses to save results onto that drive.

Byte-exact, or reported as damaged

A recovered file is identical to the original or it is reported as damaged. Nothing is padded or truncated to improve the count.

Limits stated in the product

Where something cannot be recovered, the product says so and says why. A weaker method is never substituted for a stronger one in silence.

No dependencies to install

One executable. No runtime, no framework and no third-party packages.

The set piece

One engine underneath every product.

Every build runs the same recovery core and is tested as one codebase. What differs is which workspaces a product contains, so a laboratory buys the job it does and nothing it does not.

  • Byte-exact where it can be checkedA file whose format the engine can check is returned identical to the original or flagged; a file it cannot check is marked unverified. Nothing is padded or truncated to improve the count.
  • Read-only, measuredThe source is fingerprinted before and after a job over the regions a stray write would touch, and the result states its coverage.
  • Standard-library engine, one executableThe recovery products ship as a single Windows executable with no runtime and no packages to install; the forensic family bundles its own libraries inside its installer.
  • Outbound connections blocked by defaultThe products refuse public-internet connections at the socket layer. Loopback and the local network are allowed; the exceptions are named and operator-controlled: an optional model provider (off until switched on) and cloud collection from your own tenant.
One engine: the platter ring seal, lit by the recovery family's saffron and the forensic family's indigo
269
File types recovered by signature
22
File systems parsed by name
52
Database engines identified
0
Bytes written to the source by recovery or imaging

Every figure is read from the build this page was generated from, not from a brochure.

New in 20.54.3.2

Browse first. Recover only what you tick.

The interface reads the index in seconds, says what can come back before anything is written, and hands the files back with their own dates and folders. Every item below is in the shipping build.

Browse first, recover what you tick

The file system index is read in seconds and shown as a tree with deleted entries marked. One file, one folder or a whole volume is recovered on its own; the whole-drive scan stays one click away.

Recovery chances before extraction

The allocation table says whether a deleted file's first cluster now belongs to another file, and the first bytes are checked against the format the name claims. Good, bad, unknown or unchecked, per file, before anything is written.

Original dates restored

Created, modified and accessed times are read from NTFS, FAT, exFAT, ext4, XFS, Btrfs, F2FS and UFS and set on every recovered file, so a recovered photograph is dated when it was taken, not when it was recovered.

The recorder view

A recorder disk opens on its vendor index: cameras down the left, time across, play from the disk, cut from-to, download, extract one camera, enhance, capture a frame, report. In every product that carries CCTV.

The Imager takes files, not only images

Check, image and browse a drive free; tick files and folders and extract them. A key is asked for at the first export from a source and never before.

Folder layout and long names kept

A narrowed recovery keeps the ticked folder layout instead of being flattened into Photos and Documents. NTFS Win32 long names win over the DOS 8.3 name, and exFAT sub-folders are walked.

Ex01 and AFF4 images read as sources

Alongside raw dd, .img, .iso and E01, an image can now be read from an EnCase Ex01 or an AFF4 container and recovered from exactly as from any disk image. Output stays raw or E01, hashed on read and verified after write.

Filesystem-aware imaging with an entropy map

Imaging can copy only the areas the file system marks in use and read the rest as an entropy map, so an almost-empty or already-encrypted drive is imaged in a fraction of the passes a full sector copy would take. The full copy stays available.

Hardware-RAID metadata and assembly

A RAID array is reassembled from its own DDF and vendor controller metadata where it is present, so level, order and stripe size do not have to be guessed; the parameters can still be set by hand when the metadata is gone.

Licensing

Offline. Bound to one machine. Sold by the drive.

No account, no activation server, no update check. A use is one drive or image, however many files come off it. The Imager has no key at all.

The seal: a machined ring with one notch, the mark of a key bound to one machine

A key for one machine

Every key is bound to the machine code shown in the product. It is verified offline with the public key in the build. No account and no activation server: the key is checked on this computer.

Sold by the drive, not the file

A use is one source - a drive or an image. The first time files leave the product from that source, one use is spent; the same source is free afterwards, however many files or sessions.

RecoverYantra Imager needs no key at all

Checking a drive, imaging it, browsing its index and taking the files you need all cost nothing and need no key, ever - it is free for everyone.

Keys through the partner portal

A partner submits the machine code and the number of uses; the key is issued from an offline keygen and appears on the partner dashboard. The product never talks to the portal.

Keys are issued to approved partners through the partner portal. The partner programme.

Questions

The questions people ask before they buy.

Is it safe to run on the drive I need to recover?

Yes. The source is opened read-only, so RecoverYantra can never change or worsen it. Recovered data is always written to a separate destination you pick. The safest move after data loss is to stop using the drive and image it first, and the tool guides you through exactly that.

Do you upload my data anywhere?

No. The tool runs entirely on your machine and does not need the internet at all. A key is signed offline for one machine's code, so it works on an air-gapped bench. Outbound public-internet connections are blocked by default at the socket layer. Your data stays with you.

How is a licence counted?

By the drive, not by the file. A use is one source, a drive or an image. The first time files are saved from that source, one use is spent; the same source is free afterwards, however many files or sessions. RecoverYantra Imager is the one exception: it needs no licence key at all, ever, for checking, imaging, browsing, saving files or ingesting a dump.

Do I have to recover the whole drive?

No. The file system index is read in seconds and shown as a tree with deleted entries and their chances marked. Tick a file, a folder or a volume and only that is read and written, in its own folders with its own dates. The full scan of every byte stays one click away for what the index no longer knows.

Can you break ransomware encryption?

No, and we say so. Modern ransomware with strong encryption and a key only the attacker holds cannot be broken by anyone. What the product does is often larger than people expect: it finds shadow copies and backups, recovers the originals many strains forget to erase, salvages readable text from partly encrypted documents, and identifies strains with known weaknesses or leaked keys.

What about physically damaged drives?

We have our own lab. A failing but readable drive is imaged carefully and recovered from the image. Mechanical damage (clicking heads, seized spindle) goes to the clean room. We tell you which situation you are in rather than risk making it worse.

Does it handle SSDs and TRIM?

Yes, with the limit stated. On many SSDs, TRIM permanently clears deleted data soon after deletion, so nothing can bring it back. The tool detects this and tells you, instead of running a scan that was never going to find anything.

Can it open a locked phone?

It runs every public acquisition method in-house: checkm8 on A5 to A11 iPhones, Qualcomm EDL with a loader, MediaTek BootROM, rooted ADB, and the backup routes. A modern device with no public vector, such as an A12 or later iPhone before first unlock, is not opened by any public method; the product names the method that would reach it and what it needs, and never pretends otherwise.

Windows, Linux, clicks or command line?

Windows 10 and 11 with a graphical application and a command line; the command line also runs on Linux. The same engine sits under both.