DF Sentinel · Floppy, Legacy & Modern Media Imaging for Archives

Archival-grade imaging for floppy disks, hard drives and any media at risk.

Floppy disks, hard drives and born-digital collections don't degrade gracefully — they work, and then one day they don't. Whether it's a shelf that's sat untouched for decades or a drive that arrived yesterday, DF Sentinel reads it safely, verifies exactly what's on it, and produces a defensible record of the process.

Built by a working Belfast forensics lab — over a decade of complex data recovery and forensic casework, turned into a product your own team can run. Ready to ship today.

Software ready to ship Software write-blocked by default Fully offline — air-gap ready Real support from real technicians
DF Sentinel forensic imaging software on a laptop, connected to the DF Sentinel floppy disk reader with a 3.5 inch floppy disk ready for acquisition
DF Sentinel's floppy disk reader and imaging software, ready to acquire a 3.5″ disk.
Born-Digital Doesn't Mean Safe

The real risk in “we'll get to it eventually.”

Somewhere in almost every university archive, special collections department or records management office, there's a shelf holding media nobody has opened in years. Floppy disks from a research project that wrapped up before some of your current staff were born. Drives handed over with a donor deposit. A memory card from a digitisation project that lost its funding halfway through.

This is born-digital material — created digitally in the first place, with no paper original to fall back on. It doesn't degrade gracefully. It works, and then one day it doesn't — and by then, the hardware needed to read it has often stopped existing outside a handful of specialist labs.

Most archives already know this. What's usually missing isn't awareness — it's a safe, repeatable, properly documented way to act on it, without a standing digital forensics team on staff or an outsourced vendor relationship for every accession that turns up.

  • The hardware disappears first. Long before a floppy disk fails, the drives capable of reading it vanish from ordinary IT inventories. A working floppy, Zip or Jaz drive isn't something a university helpdesk stocks anymore.
  • File-system obsolescence, not just file-format obsolescence. Preservation planning focuses on whether a document will still open in twenty years — but there's an earlier problem: can the operating system mount the disk at all?
  • “We opened it once and it looked fine” isn't evidence. Without hashing, provenance metadata and structural validation at the point of capture, there's no way to prove a file hasn't altered — or to catch quiet corruption.
  • Physical media degrades on its own schedule, not yours. Magnetic media doesn't wait for a grant cycle or a staffing gap. The realistic window is measured in years, not decades — and it's already closing.
The Gap

Why typical approaches fall short.

Most institutions currently handle this one of three ways, and each has a real gap.

Gap: no proof

Ad Hoc IT Tools

A well-meaning member of staff plugs a drive into a lab machine and copies the files across. Works fine for a healthy modern drive — and fails immediately for a damaged sector, an unsupported file system, or a floppy disk. No hashing, no audit trail, no structural validation, so even a successful copy can't later be proven accurate.

Gap: cost & control

Outsourcing Every Batch

Gets the job done properly, but it's expensive per accession, introduces turnaround delays, and — for sensitive collections — means physical media leaves the building. Doesn't scale for institutions receiving regular legacy-media donations, and builds no in-house capability.

Gap: data leaves you

Cloud & Upload-Based Platforms

An increasingly common model: upload the image, or run the case management in someone else's cloud. Your collection — often embargoed, donor-restricted or personal — then sits on infrastructure you don't control, needs its own data-processing agreement, and stops being reachable the moment the subscription lapses or the connection drops.

Gap: wrong profession

Litigation-Grade Forensics Tools

Tools like FTK Imager handle raw sector-level imaging well, but they're designed around evidentiary workflows for legal and investigative contexts, and typically assume digital forensics training most archive and library staff haven't had reason to acquire.

There's a gap between “consumer tool that can't handle real legacy media” and “professional forensic suite built for a different profession entirely.” That gap is where DF Sentinel sits. Every piece of what it does — write-blocking, raw imaging, format identification, integrity validation, reporting — exists somewhere as its own separate open-source utility or point tool. What doesn't exist elsewhere, as far as we've found, is all of it guided and combined into one workflow a non-specialist can run start to finish, backed by one team you can actually call. So we built it.

About Me

Hi, I’m Nico — a decade of real casework, turned into a product.

Nico, founder of Data Forensics Ltd

DF Sentinel wasn't designed by a software house guessing at what archives need, and it wasn't drafted on a whiteboard. It comes from more than a decade of hands-on work at Data Forensics — complex data recovery and forensic casework across every kind of failed, damaged and obsolete media that walks through a working lab's door.

The product itself grew out of training we delivered for a local Belfast university and its archivists. Sitting with the people who actually handle the collections — seeing their backlog, their workflows, their procurement realities — shaped every design decision that followed.

That matters, because these tools weren't tested in a lab simulation. They've been proven in a real forensic environment, under real conditions, with real media — including the awkward, half-failed, decades-old media that theory tends to skip over, and hardened through multiple rounds of rigorous internal engineering review, with nearly 2,900 automated tests run on every release. When you license DF Sentinel, you also get the people behind it: real support from the technicians who built and use it. You're not left alone with a download. Read more about the lab and the team behind it.

10+ years of complex data recovery & forensic casework Nearly 2,900 automated tests on every release Grew out of training delivered to Belfast archivists

— Nico · Founder, Data Forensics Ltd

The Product

Four jobs, one defensible record.

DF Sentinel 2.0 is an all-in-one hardware-and-software product for reading legacy and modern storage media, verifying its contents, and generating an exportable record of the process. It's continuously developed and refined as environments change and new requirements come up.

01

Imaging

The imaging engine — DF Sentinel Keep — reads media at the raw sector level for a true bit-for-bit copy, capturing deleted, hidden and system files along with everything else, not just what a normal file browse would show. Hashing runs as it goes, without ever asking the operating system to mount the volume, so HFS+, EXT2/3/4 and other unsupported file systems don't block capture. For floppy disks specifically, see how floppy disk imaging works.

02

File Inventory

DF Sentinel Catalogue, powered by PRONOM (the UK National Archives' own format-identification registry), enumerates every file and identifies type by inspecting content and structure directly, rather than trusting a possibly-wrong extension. Effectively a ready-made digital asset register.

03

Integrity Validation

DF Sentinel Integrity Check runs dual modern hashing (SHA-256 and SHA-3-256) during acquisition, plus MD5 and SHA-1 kept for cross-checking against older tools' records — alongside per-format structural validators. Damaged, truncated or misidentified files are flagged at the point of capture, not years later.

04

Reporting & Audit

DF Sentinel Registrar writes every device read, every hash, every flagged file to an append-only activity log in normal operation, with sealed-case verification designed to expose any subsequent alteration. Exports to CSV, JSON and HTML.

Offline By Design

No cloud. No uploads. No phone-home.

Most tooling in this space now assumes a network — you upload the disk image, or the case management lives in someone else's cloud, or the licence quietly checks in with a server before it will run. DF Sentinel does none of that.

Every stage — intake, imaging, file inventory, integrity validation, reporting — happens on the machine in front of you. Nothing about your collection is transmitted anywhere. There's no cloud service to procure, no account to create and no third-party data-processing agreement to negotiate, because there is no third party.

That includes licensing: the software doesn't call home to verify itself. Pull the network cable out, or install it on a permanently isolated workstation in a secure room, and every function behaves exactly the same. For material under embargo, donor restriction, commercial confidentiality or data-protection constraints, that's often the difference between being able to process it in-house and not being allowed to touch it at all. More on offline & air-gapped use.

No uploads. Media and images stay on your own storage, inside your own building.
No telemetry. Nothing about your files, your usage or your collection is reported anywhere.
No licence phone-home. No activation server, no periodic check-in, no expiry by disconnection.
Air-gap ready. Runs indefinitely on a workstation that has never been connected to a network.

If your institution needs to demonstrate controlled processing of sensitive material, this is the part that supports it: offline processing and the audit trail together provide technical evidence for your institution's controlled-processing policy, not just a claim to take on trust.

Inside DF Sentinel

What running it actually looks like.

Six real screens from the application — from opening a case through to the report at the end.

Prefer to click around yourself? Try the live simulator — no install required.

DF Sentinel dashboard showing active cases, device safety status and recent activity
Dashboard — active cases, device safety and recent activity at a glance.
DF Sentinel case explorer showing the ingest checklist and case-confidence gauge for an open case
Case workspace — the ingest checklist and case-confidence gauge for a case in progress.
DF Sentinel imaging wizard confirming the correct device before write-blocking is applied
Imaging wizard — confirm the right device is selected before a single sector is read.
DF Sentinel device safety screen showing every connected device write-blocked automatically
Device Safety — every connected device is write-blocked automatically the moment it appears.
DF Sentinel acquisition progress screen with live stage checklist, byte-level progress and read log
Acquisition in progress — live stage checklist, byte-level progress and read log.
DF Sentinel preservation report showing a verdict-first summary with full technical detail underneath
Preservation report — a verdict-first summary, with the full technical record underneath.
What A Typical Engagement Looks Like

From accession to defensible record.

Institutions usually bring DF Sentinel in as a standing in-house capability, or as a focused project to clear a specific backlog. Either way, the workflow follows the same shape.

01

Consultation & scoping

We understand what you're holding — media types, approximate volume, condition and timeline — and recommend which engagement model fits your situation and budget cycle.

02

Intake

Each item of media is logged as a case — who it came from, what it is, any context that arrived with it — establishing the audit trail before a single sector is read.

03

Imaging

Media is connected to the appropriate reader and imaged at the raw sector level, with hashing running throughout. Bad blocks and read errors are logged, not silently skipped.

04

Inventory & validation

DF Sentinel builds the file inventory from the completed image and runs integrity validation, flagging anything damaged, truncated, or misidentified.

05

Reporting

A case report (CSV, JSON or HTML) documents exactly what was imaged, what was found, and what needs follow-up, alongside the append-only audit log. See a sample report.

06

Handover

The verified image, file inventory, and JSON sidecar metadata move into whatever your institution already uses for long-term storage — standard, interoperable containers, not a proprietary lock-in.

Software · Hardware · Training

Start with a conversation, not a price list.

No two archives look the same, so it all starts with talking to us about your requirements — media types, volume, condition, timeline. We don't publish a price list because we can't responsibly guess what's on your shelves before we know what it actually is: 3.5″ and 5.25″ floppies, Zip and Jaz disks, CDs and DVDs, external hard drives, SD and memory cards, or a NAS box nobody's powered on in years all carry a different scope. That mix is what drives the cost, not a generic rate card. From there, DF Sentinel comes in whichever shape fits — the underlying software, forensic guarantees and reporting stay identical throughout.

Ready to ship

Software Licence

License DF Sentinel and run it against equipment you already have — often the fastest way to start. Software imaging of hard drives, SSDs and USB media works out of the box, and every licence comes with real support from the technicians who built it.

Ready to ship

3.5″ Floppy Reader Bundle

Our own floppy controller hardware bundled with the software as a single tested package — purchase outright and get a legacy floppy workflow running immediately. 5.25″ and Zip/Jaz reader hardware is in development.

Built to order

Custom Imaging Workstation

A dedicated, custom-built machine specified for the job — higher-grade components and ECC error-correcting memory — configured and tested around your specific collection and reading-room workflow.

Per requirement

Customisation & Integration

We can't predict every working environment — so the software was designed from the start to allow for integrations. Repository, cataloguing or accessioning system integration, customer-specific outputs, even integrating other hardware components: if your workflow needs it, we're happy to scope and build it.

Training for your staff is part of any engagement — delivered by the same people who run this media in a working lab, grounded in your actual collection rather than a generic slide deck.

Requirements & Licensing

What you need to run it.

The practical answers procurement usually asks for first. Full technical specifications.

Operating system
A native Windows application, tested on Windows 10 and Windows 11.
Where it runs
Entirely on your own machine — offline and local, no cloud service to procure and no data leaving the building.
Internet connection
None required, at any point — including licensing. Runs happily on a permanently air-gapped workstation. How that works.
System requirements
Moderate — ordinary workstation hardware is enough to get started. For high volumes or continuous imaging we'll spec a machine around your actual throughput rather than sell you more than you need.
Reader equipment
Runs against equipment you already have, our supplied reader bundle, or a custom-built workstation — your choice.
Licensing
Flexible, and shaped around what you actually need — scale, duration and engagement model are all discussed rather than fixed. Talk to us and we'll fit it to your budget cycle.
Deployment
No installer required — unzip and run, including from a USB stick on an examination or reading-room machine.
File systems read
NTFS, exFAT, FAT12/16/32, ext2/3/4, HFS+/HFSX, APFS, ISO9660, UFS — across MBR and GPT partition schemes.
Built On Forensic Principles

The guarantees that run through the whole product.

The same rigour used in forensic evidence handling, applied to the legacy-media problem — because that's the standard this lab already works to every day. A software block is reported as exactly that, never dressed up as hardware-grade: we'd rather tell you what the product couldn't do than round a claim up.

DF Sentinel Guardsoftware write-blocking, verified by attempt — every device is blocked by default, and on request the software attempts a real write and shows it being refused, rather than asking you to just trust it. Floppy disks go further: the read path issues no write commands at all, so they're read-only by physics, not just by software policy
Offline and local by design — no telemetry, no cloud, no licence phone-home
Before-and-after hash verification (fixity checking) proves an image matches its source
Standard, interoperable evidence containers — RAW/DD today, E01 and AFF4 planned
Bad-block and read-error handling on every read — and device imaging (HDD, SSD, USB) resumes from its last verified checkpoint if interrupted, re-authenticating what's already copied before continuing
Provenance from the first read — custody and handling events documented from intake, not reconstructed afterward
When Software Isn't Enough

The last resort, in the same building.

Imaging software assumes the media still basically works. Sometimes it doesn't — and that's where the rest of the lab comes in.

DF Sentinel assumes working media. Our lab doesn't have to.

DF Sentinel is built for media in working condition or with minor damage — that's the honest scope of any imaging tool. Behind it sits Data Forensics' full recovery lab, handling the failures software can't touch: seized drives, head crashes, degraded platters, fire and water damage, failed RAID and NAS arrays, media nothing else will read. If a disk in your collection is beyond software, it isn't beyond help — the same team simply takes it further, in-house, with the same chain of custody. DF Sentinel and the lab were built as one system from the start, not two products that happen to share a name.

Recovery services
DF Sentinel licence holders get preferential rates on full lab recovery. If something in your collection turns out to need physical intervention, you're not starting a fresh commercial relationship from scratch — talk to us and we'll price it as an existing customer.
Sectors

Who uses DF Sentinel.

  • University & academic archives
  • Special collections & reading rooms
  • Records management offices
  • Research data management teams
  • Institutional repositories
  • Academic libraries
  • Libraries, museums & memory institutions
Frequently Asked Questions

Questions from archivists and records teams.

Do we need in-house digital forensics expertise to use this?
No. DF Sentinel is designed so that archive, library, records management, and collections staff can run it directly, with the forensic-grade guarantees (read-only access, hashing, structural validation, audit logging) built into the workflow rather than left to the operator's judgement.
Do we have to buy hardware to get started?
No. If you already have working floppy drives, card readers, or drive enclosures, you can license the software on its own. Starting from nothing, we offer a supplied hardware bundle, fixed-term loaner or rental hardware, or a fully custom-built dedicated workstation — whichever fits your budget cycle and volume.
Can you build something specific to our collection?
Yes. Our custom-built workstation option is configured and tested against your actual media formats, volume, and workflow rather than a generic specification. If your holdings are unusual, tell us during scoping and we'll build around it.
What happens with media that has a file system Windows can't read?
It doesn't matter at the imaging stage. DF Sentinel images at the raw sector/block level without asking the operating system to mount the volume, so HFS+, EXT2/3/4, and other unsupported or legacy file systems don't block capture. File-system parsing happens afterward, against the completed image — covering NTFS, FAT, exFAT, EXT2/3/4, HFS+, ISO9660 and more.
Is this just for floppy disks, or does it cover other media too?
Floppy disks are what we're best known for, but they're one part of a broader product. The same raw, sector-level imaging path handles hard drives, SSDs, USB sticks, SD and memory cards, CDs and DVDs, Zip and Jaz disks, and drives pulled from external enclosures or NAS boxes — whether it's decades old or was dropped off yesterday. Not sure what you're holding? Tell us what's on the shelf and we'll tell you what's possible.
What if our media isn't on your list, or nobody's dealt with it before?
Tell us what it is. A lot of what this lab does day to day is figuring out orphaned or unusual formats other people have given up on — that's not something a general IT department can typically pick up quickly, because it took real, sustained R&D to build reliable readers for genuinely obscure media in the first place. If something we haven't built support for yet turns up, we scope it as part of the engagement rather than turning it away — and if a job runs into trouble mid-way, the same team you started with is who you call, not a different vendor.
Can this handle media with physical damage or read errors?
Yes — DF Sentinel handles bad blocks and read errors during imaging, logging exactly where and how a read struggled rather than failing the entire job or silently skipping the problem. Device imaging (hard drives, SSDs, USB media) is also resumable: if a session is interrupted, it picks up from its last verified checkpoint and re-checks the already-copied data against its recorded hashes before continuing, rather than trusting it blindly. Floppy disks are small enough to simply re-read from scratch if a job is interrupted.
Does anything leave our building or network during processing?
No — nothing, at any stage. Processing is fully offline and local: no telemetry, no cloud dependency, and no licence check-in with our servers either. The software runs identically with the network cable removed, so it can sit on a permanently air-gapped workstation. Nothing about a collection's contents leaves your building unless a member of staff deliberately exports it.
Will the output work with our existing digital preservation system?
DF Sentinel produces standard evidence containers (RAW/DD today, with E01 and AFF4 planned) alongside a JSON sidecar of device identity, timestamps, operator, and hashes — built to be interoperable with the systems most institutions already run, including Archivematica and BitCurator-based workflows.
How is this different from sending media to a specialist data recovery vendor?
Outsourcing works, but it's per-batch expensive, introduces delays, and can mean sensitive collections leaving the building. DF Sentinel is built to become an in-house capability instead — something your own team can run repeatedly, with the same forensic rigour a specialist vendor would apply.
Can we start small and scale up later?
Yes. Many institutions start by licensing the software against borrowed or rented hardware to clear an initial backlog, then move to a supplied bundle or dedicated workstation once they know their ongoing volume. The reporting, audit trail, and evidence format stay consistent throughout.
Get In Touch

Tell us what you're holding.

There's no price list to request and no sales sequence to enter. This goes straight to the lab, and a real person reads it.

Prefer not to fill in a form? Email, call, or open your own mail app — whichever's easiest reaches the lab directly.

Email us Opens your mail app 028 9543 8520
Not sure what to put? Rough answers are genuinely fine.
  • An estimate is fine — “about three boxes” tells us as much as an exact count.
  • If you don't know what the media is, say so. Unlabelled disks are normal.
  • Mention anything visibly damaged, mouldy, or previously opened.
  • If you're working to a grant deadline or retention date, tell us the date.
About you
What media are you holding?

Tick everything that might apply — including anything you're unsure about.

What are you interested in?
Anything else
Goes straight to the lab. We usually reply within one working day.

What happens to this. Your details are used for one thing only — replying to this enquiry. We don't run a newsletter, we don't add you to a mailing list, we don't pass anything to third parties, and you'll never get marketing from us as a result of sending this. Privacy policy.

Part Of Data Forensics Ltd

Explore the lab behind DF Sentinel.

DF Sentinel is one product from a working Belfast digital forensics and data recovery lab — the same people, the same standards, applied across everything below.

From a box of old disks to a verified collection

Talk to us about your backlog.

The enquiry form above is the quickest route — it reaches the lab directly. If you'd rather email, call, or just open your own mail app, these work equally well.

Email us Opens your mail app 028 9543 8520

No newsletters, no mailing lists, no marketing follow-up — whichever way you get in touch.