Taking work now — the first look is freeWhole sets posted in from anywhere in the UK, or handed in at ten drop-off pointsQuicker still, give us a ring:0800 6890668
RARRAID Array Data Recovery 0800 6890668 Price my job
RAR / Controllers and hosts / Intel RST, RSTe and VROC

Intel RST · RSTe · VROC · IMSM · md126 · md127 · Option ROM · TA 000016228

Intel RST, RSTe and VROC array recovery. Chipset and CPU RAID, with metadata Linux reads as md126 and a RAID 5 advisory of its own.

Intel's RAID comes in three names for one idea: Rapid Storage Technology on desktop and workstation chipsets, RSTe on the server chipsets that came before, and Virtual RAID on CPU on Xeon Scalable platforms, where the RAID runs on the processor and the NVMe drives hang off its lanes. All three write Intel Matrix Storage Manager metadata near the end of each member, which Linux's mdadm reads as an external container, md127, with the volumes inside it as md126 and up; Windows reads it through the Intel driver, and the Option ROM at boot reports volumes as Normal, Degraded, Failed or Rebuild. Intel's own technical advisory 000016228 described a data-loss condition on RSTe-managed RAID 5 volumes under heavy I/O that became degraded, and noted that RSTe was folded into VROC. They arrive here from workstations and small servers, RAID 0 and 5 on SATA behind a chipset, RAID 1 boot pairs, and VROC RAID 5 and 10 on NVMe in Xeon servers. A set of two to four members is £500 + VAT upwards after the free look, fixed in writing, 5–10 days at the bench.

Free first lookOne fixed figure in writingNo data, no bill on most jobsReturn postage paid

Rather talk it through? An engineer answers the bench line
0800 6890668

Power down. Label every slot before a drive comes out. Do not rebuild, do not force a drive online, do not import or clear a foreign configuration, do not initialise, and do not run chkdsk, fsck, zpool import -F or mdadm --create on the members. A rebuild reads every sector of every survivor and writes to the replacement; each of the commands writes to the drives. On images, all of them are reversible. On the originals, none of them is.

Models and versions we see.

Which level is it →
Family Models or versions Metadata, defaults and notes
RST (chipset)Z170 to Z790, H- and Q-seriesSATA and NVMe · IMSM
RSTe (server chipset)C602, C612, C620 with Intel RAIDSATA/SAS · IMSM · TA 000016228
VROCXeon Scalable with VMD; Standard and Premium keysNVMe RAID 0, 1, 5, 10 · IMSM
Linux viewmd127 container, md126 volumemdadm --examine --metadata=imsm

What tends to go wrong on an Intel RAID.

IMSM and md126Linux reads Intel's metadata as an external container, md127, with the RAID volumes inside it appearing as md126. mdadm --examine reads it; the layout and strip are in it. A --create on the members writes a native superblock over it, and the volume is a reconstruction.
The RSTe RAID 5 advisoryIntel's technical advisory 000016228, on its support site with a page date of 2017 and a review date of 2025, described a potential data-loss condition on an RSTe-managed RAID 5 volume with heavy I/O that became degraded, and noted that RSTe software is no longer available because it was folded into VROC. A degraded RSTe RAID 5 under load is a set to image, not to rebuild.
BIOS updates and the Option ROMA BIOS update that resets the SATA mode from RAID to AHCI makes every member a raw drive with Intel metadata at its end, and Windows offers to initialise them. Setting the mode back usually restores the volume; initialising does not.
VROC keys and firmwareVROC needs a hardware key or a licence, and a server rebuilt without it, or with different VMD firmware, may not present the volume. The metadata on the NVMe members is readable on the bench regardless.

Intel RST, RSTe and VROC symptoms, and how long each gives you.

Not listed? Describe it on the form →
Packing it and posting it: power down, photograph the controller's screen or export its log, and write the slot number on each drive with a marker before it comes out of its carrier. Send every member of the set, including the one that failed first; it holds the stripes the rebuild never reached. Each drive travels in an anti-static bag inside its own padding, in a box with nothing able to move. Send the controller if it was replaced or holds an encryption key; otherwise it stays. Insure the parcel for what the data is worth, use a tracked service, and know that the posting address is not printed anywhere on this site; it arrives by email in reply to the form, with a booking sheet to print; the sheet inside the parcel is what matches it to your enquiry when it is opened. Or hand the sealed parcel in at the nearest of ten drop-off points, your name on the outside and the sheet inside; say where you are on the form and it comes by email. We pay the postage home either way. The whole of it is written up on the guide to packing and posting.

What the message means on an Intel RAID.

Describe yours to us →
What you see The usual reason Where that leaves you
Volume Degraded in the Option ROMA member outImage it before Rebuild
Volume FailedToo many members outEvery member imaged; assembled from the IMSM metadata
Members shown as raw disks after a BIOS updateSATA mode changedSet it back; do not initialise
md126 will not startContainer found; volume refusedRead the IMSM metadata from images
Virtual or logical disk degradedA member out; still readableImage the weak drives before rebuilding
Virtual or logical disk failed or offlineToo many members outEvery member imaged; set reassembled from images
Foreign configurationMetadata the controller does not claimDo not clear; import only with every member present
Predictive failure on a survivorThresholds crossedStop; image before any rebuild

From the parcel arriving to your files going back.

Work we have closed →
01

Logged the day it lands, and the first look costs nothing Free

A case number goes on the parcel and a number on every member the day it is opened, matched to the slot you wrote on it. Each member goes on the imager its interface needs, never on a controller, and its metadata is read before a sector is: the level, the order, the stripe size, the event counts that say which member is current and which dropped out first. An engineer settles what has happened to the set and how much of it can honestly be read back. Back to you come two things together: a straight note of what is liftable and what is not, plus one figure, fixed and written down. Accept it, or decline and owe us nothing.

Nothing to pay for lookingA single figure, put in writingNo rebuilds, no imports, no initialise
02

Every member imaged, including the one that failed first

Every drive in the set is imaged sector by sector, weak areas last, on hardware that controls every retry, with a map of what could not be read kept for each. Members with failed heads go to the clean bench first; that is the drive site's work and the same bench does it. The drive that dropped out first is imaged too, because it still holds every stripe written before it dropped, and a rebuild that stalled part-way never reached them.

Sector by sector, weak areas lastThe first-dropped member included
03

The geometry, from the metadata or from the parity

Where the controller's metadata survives on the members, the order, stripe size, parity rotation and data offset are read from it. Where it was cleared or overwritten, they are recovered from the data: parity across the members at the same offset should XOR to zero on a consistent stripe, which confirms the level and finds the stale member; where parity lands says the rotation; entropy at stripe edges and the file system's own anchors give the stripe size, the order and the start.

Metadata first, parity secondOrder, stripe, rotation, offset
04

Assembled in software, and repaired on the virtual volume

The set is put together from the images in software, with nothing written to any of them: the current members in, the stale member used only to fill holes a survivor could not give. The file system is checked and repaired on a copy of the virtual volume, VMFS and CSV volumes opened and the virtual machines' disks extracted, databases repaired where they need it. The originals are not touched again.

Nothing written to the imagesVirtual machines and databases opened
05

You see the file list before you pay

What was recovered is listed for you first, and only then does a bill exist. Approve the list and it is invoiced; turn it down and it is not — and where nothing has come back, most jobs carry no charge at all. Recovered data travels home on fresh media bought in for your job, with the postage at our end. Your case is not closed until you have opened the files on a machine of your own.

No charge until you accept the figureFresh media, supplied with the job5–10 days at the bench

From the bench

  • Do not initialise a member Windows cannot read. It has Intel metadata at its end and a BIOS that forgot RAID mode.
  • Say whether it was RST, RSTe or VROC, and the platform. The metadata is the same family; the tools differ.
  • A degraded RSTe RAID 5 under load is Intel's own documented risk. Image before rebuilding.
  • Export the controller log first. It is the best record of what failed when, and the bench reads it.
  • The drives are the job; the controller is context. Send it if it was replaced or holds an encryption key.
  • Keep the first-dropped drive. It holds the stripes the rebuild could not compute.

One job, followed all the way through.

UK · RAR-2026-0629JOB LOGGED ✓

A workstation's four-drive Intel RST RAID 5 that lost a member, kept running under load for a week, and lost the volume when a BIOS update reset the SATA mode and a colleague initialised one drive in Disk Management

All four drives came in. The initialised drive had a new partition table over the first sectors and its IMSM metadata intact at the end; the failed member was imaged after a head swap. The IMSM metadata gave a 64KB strip and the order, parity across the images proved them, and the set was assembled from the three current members with the failed member's image filling the initialised drive's overwritten start. The NTFS volume mounted from the virtual array.

99.9% of the volume recovered6 days here, and back by post
Illustrative example — replace with a genuine case

What helps, and what harms.

Do this much first

  • Export the log and photograph the screen
  • Power down and label every slot
  • Send every member
  • Tell us the controller, the level, the stripe size if known, and what was tried

What sets us back

  • Rebuilding with a second drive flagged
  • Clearing a foreign configuration
  • Forcing failed drives online
  • Deleting and recreating the virtual disk

Questions answered before you commit.

Linux shows my Intel RAID as md126 and md127. What are they?

md127 is the container holding Intel's metadata; md126 is the RAID volume inside it. mdadm --examine --metadata=imsm reads them. Do not --create on the members.

My BIOS update turned my RAID into separate disks. Is the data gone?

No. The SATA mode was reset from RAID to AHCI. Set it back and the volume usually returns; do not initialise the disks meanwhile.

What did Intel's RSTe RAID 5 advisory say?

That a potential data-loss condition existed when an RSTe-managed RAID 5 volume with heavy I/O became degraded, and that RSTe was folded into VROC. A degraded RSTe RAID 5 should be imaged, not rebuilt under load.

What does it cost?

£500 + VAT upwards for a set of two to four members after the free look, fixed in writing.

Nothing gets worse while it is powered down.

Looking at it is free. Back comes a list of what opened and what did not, together with a single price to finish, set down in writing while you are still free to say no. On most jobs an invoice only follows the data. Until that list reaches you, leave the server off and the drives in their slots.

0800 6890668