Blog & news

Blog — Data Recovery and Cybersecurity

Technical analyses, prevention tips and data recovery news from the experts at SOS Data Recovery, Swiss laboratory since 2006.

Cybersecurity & prevention
In-depth technical analyses
Expert practical advice
Free diagnosis Estimate your recovery
Free diagnosis Quote within 3 hours Your data stays in Switzerland
Recovering Data from a Mac: Soldered SSD, T2 Chip and FileVault

Recovering Data from a Mac: Soldered SSD, T2 Chip and FileVault

  • September 09, 2026
  • Author : Stéphane Chapuis
  • Updated on:

On a recent Mac, the SSD is no longer a part you remove to read the data elsewhere: it is soldered to the logic board, and its contents are permanently encrypted by the Mac's chip. Without a working logic board and processor, and without the FileVault password, no one can decrypt this data, neither we nor Apple. That is why, on a faulty Mac, recovery almost never involves moving the SSD, but rather repairing the logic board to restore access to the decryption keys it holds.

What follows explains the two major Mac eras, the role of the T2 chip and then the Secure Enclave, what FileVault adds, the Fusion Drive trap, and what really remains recoverable.

Two Mac eras

The first instinct in data recovery is to know which generation of Mac you are dealing with, because everything flows from that.

On older Macs, up to around 2016, the SSD was often a removable part. It had a format close to the M.2 familiar on PCs, but it was in fact a proprietary Apple format. Above all, these machines did not necessarily enforce hardware encryption. In that case, an SSD taken out of the machine remains readable, and recovery resembles that of a conventional drive.

On recent Macs, this is no longer possible. The SSD is soldered directly onto the logic board. You can therefore no longer remove it to read it on another device, and, as we will see, even by desoldering the chips you recover nothing usable as long as the encryption is not lifted. The drive and the machine are now one.

The T2 chip: far more than encryption

On recent Intel Macs, Apple introduced a dedicated chip, the T2. It is often reduced to its encryption role, but it does much more, and understanding this helps grasp why a Mac can fail in a baffling way.

The T2 acts first as the SSD's controller, with permanent hardware encryption of the data. It also hosts the Secure Enclave, the secured area that manages secure boot and Touch ID. It further handles signal processing, for the microphone and camera for example. And it manages part of the machine's power supply.

This last point gives a telling example of a failure. When you plug in the charger, power arrives first at a standard 5 volts, via USB. A communication is then established with the T2, and at a certain point the chip returns the information that allows the logic board to raise the voltage. The dialogue takes place with the charger, essentially to tell it that it may now push 20 volts. If the T2's firmware is corrupted, this transition no longer happens: the machine stays stuck at 5 volts, does not rise to 20 volts, and you end up with a Mac that will not start or will not charge, even though the problem is neither the battery nor the charger.

Apple Silicon, the Secure Enclave and FileVault

With the Apple Silicon chips, the M1, M2, M3 and M4, Apple integrated these functions directly into the main processor. The Secure Enclave is now part of it, and makes any bypassing of the Mac's security features practically impossible. These machines are more resistant in this respect, but this has a direct consequence for recovery.

The contents of the SSD are still encrypted, and the encryption keys are managed by the Secure Enclave, inside the processor. If the processor dies, these keys are lost, and decryption is simply no longer possible. You could technically read the NAND memory chips one by one, but you would obtain only encrypted, and therefore unusable, content.

This is also why you cannot simply move the SSD, on top of the fact that it is soldered. Even imagining that you desolder then resolder the chips onto another board, you change the processor, and therefore the encryption key, and the data stays unreadable. The only way, when the logic board has a problem, is to repair this logic board to make it functional, because it is its components that hold the keys allowing decryption.

FileVault adds yet another layer on top. It is a software protection that stacks onto the hardware protection of the chip. Concretely, if the FileVault key is not provided, it does not release the processor's encryption key. In other words, even with a perfectly repaired machine, without the FileVault password or its recovery key, access to the data stays locked.

Where the keys are, depending on the Mac

Mac generationSSDEncryptionEffect on recovery
Before ~2016Often removable (proprietary format)Not necessarily enforcedRemoved SSD stays readable, like a conventional drive
Intel with T2 chipSolderedHardware via the T2Repair the logic board to access the keys
Apple Silicon (M1 to M4)SolderedKeys in the processor's Secure EnclaveDead processor = lost keys, decryption impossible
With FileVault enabledDepending on the modelAdditional software layerWithout password / recovery key, access locked

The Fusion Drive trap

One particular case deserves attention, because it regularly traps users as well as some repairers: the Fusion Drive. This system no longer exists on recent Macs, but it still equips many machines. Apple introduced it in 2012.

The idea was to combine two drives: a fast but low-capacity SSD, and a large mechanical hard drive to store a lot of data. The Mac distributes the files more or less intelligently between the two, keeping on the SSD what is used often, for speed, and relegating to the mechanical drive what is heavier, rarer or less called upon. From the user's point of view, all this appears as one and the same volume.

The problem is that the two drives form an inseparable whole. If one of the two fails, SSD or mechanical drive, both must be repaired and recovered to reconstruct the data, because the files are distributed between them. Yet, very regularly, a customer brings us a single device, convinced there is only one, because they saw only one drive in their machine. A quick analysis, once the device is repaired, then reveals that it was in fact a Fusion Drive, and that the second half is missing. On an older Mac, the first precaution is therefore to check that there is not an SSD and a hard drive combined as a Fusion Drive.

What really remains recoverable

Let us be clear on a point that some competitors keep vague: no, you do not recover everything on a recent Mac. When you are promised a guaranteed recovery whatever the state of the machine, be wary. If the processor is faulty, the hardware encryption keys are lost, and no laboratory in the world will decrypt this data. Apple does not recover it either.

On the other hand, a large share of failures does not touch the processor itself. When a faulty recent Mac is entrusted to us, with its soldered SSD, we first proceed with the repair of the logic board. Very often, the problem lies at the board's power supply, a frequent case on MacBook Pro for example. We repair this part and make the logic board functional again, which allows the machine to start, unlock and decrypt its drives. Only then do we make a perfect bit-for-bit copy, on which we extract the data.

The prevention lesson is simple: on a Mac, the soldered SSD is a single point of failure, and a backup is essential as on any computer. The two basic tools are Time Machine, for a backup on an external drive, and iCloud Drive, for synchronisation. And if you use FileVault, carefully note your password and your recovery key: without them, even a repaired machine will keep your data under lock.

What to remember

On a recent Mac, the SSD is soldered to the logic board and the contents are encrypted by the chip, T2 on Intel models, Secure Enclave built into the processor on Apple Silicon M1 to M4. The decryption keys live inside this processor. If the processor dies, they are lost and the data can no longer be recovered; this is why moving or desoldering the SSD leads nowhere, and why recovery goes through repairing the logic board. FileVault adds a software layer: without its password, even a repaired machine stays locked.

Two instincts follow from this. First, be wary of anyone promising to recover everything on a recent Mac, because a dead processor means lost keys. Second, back up, with Time Machine and iCloud, and keep your FileVault credentials. And beware of the Fusion Drive on older Macs: two drives form only one, they must be dealt with together.

Frequently asked questions

Can you remove the SSD from a recent Mac to read the data elsewhere?

No. On recent Macs, the SSD is soldered to the logic board and its contents are encrypted by the chip. Even by desoldering the memory chips, you change the processor, and therefore the encryption key, and the contents stay unreadable. Recovery goes through repairing the original logic board.

What happens if the Mac's processor is dead?

On an Apple Silicon (M1 to M4), the encryption keys are managed by the Secure Enclave, inside the processor. If the processor is dead, these keys are lost and decryption becomes impossible. No laboratory can then recover the data, and neither can Apple.

What is the T2 chip for on an Intel Mac?

The T2 does not only encrypt the SSD. It also serves as a storage controller, hosts the Secure Enclave (secure boot, Touch ID), manages the signal processing of the microphone and camera, and drives part of the power supply. A corruption of its firmware can, for example, block the voltage rise from 5 to 20 volts and prevent the Mac from starting or charging.

I have forgotten my FileVault password, can you still recover my data?

No, unless you have the FileVault recovery key. FileVault is a software layer that adds to the hardware encryption: without the password or the recovery key, the processor's key is not released, and access stays locked even on a repaired machine.

What is a Fusion Drive and why does it matter?

A Fusion Drive, introduced by Apple in 2012, combines a fast SSD and a mechanical hard drive into a single volume, with the files distributed between the two. The two drives are inseparable: if one fails, both must be dealt with to reconstruct the data. Many customers bring only one, without knowing that a half is missing.

How do you back up a Mac properly?

With the two basic tools: Time Machine for a backup on an external drive, and iCloud Drive for synchronisation. Since the soldered SSD is a single point of failure, a backup is essential. If you use FileVault, also keep your password and your recovery key.

Available 24/7

Data emergency? We respond immediately.

In the event of critical data loss or a server failure, our on-call team responds urgently, including weekends and public holidays.