Local, read-only InfoPath data recovery

Get your data out of InfoPath — and check for yourself that nothing changed.

Microsoft retired InfoPath, stranding years of form data in a dead, unsupported product. XSN Rescue extracts your .xsn templates and their form data safely, under strict controls, and every run writes an integrity report — with a SHA-256 of each file before and after — that anyone can re-check for themselves.

No account, no card, nothing uploaded. The free download opens your own .xsn / .xml read-only, so you see exactly what comes back before you decide. One purchase covers Windows and macOS, up to 25 activated devices, with a 14-day money-back guarantee.

✔ SHA-256 before and after, in the report ✔ Runs in your environment ✔ No data leaves your control
What every run’s report records Illustration
→ Every source file hashed before it is opened
SHA-256, named in the report file by file
before
◇ Opened read-only, hashed again at the end
recorded per file as source_modified: false
after
▤ Records exported
CSV, JSON, HTML · one archival PDF each
per record
◆ Anything it could not recover is named
with the reason, in the same report
stated

This is an illustration of what the report records — not output from a real run, and no figures from one. The real thing is further down the page: a recorded run of the tool itself.

Built for regulated data stewardship
SHA-256 before and after Hash-chained custody packs Nothing leaves your machine Runs on your own computer Read-only, with a SHA-256 before and after
The problem

InfoPath is gone. Your obligations aren't.

InfoPath reached end of support, and Microsoft has confirmed it will be removed from Microsoft 365. The forms stopped being maintained — but the records inside them are still discoverable, still auditable, and still yours to protect.

✕

A dead, unsupported format

No patches, no vendor support, and a shrinking set of tools that can rebuild one of these forms. The file stays readable; what fades is anything that can still make sense of it.

⧗

Years of records, stranded

Onboarding forms, consent records, incident reports, attestations — often thousands of submissions holding regulated data with no clean way out.

⚠

Ad-hoc exports create exposure

Copy-paste and one-off scripts break structure, drop fields, and leave no record of who touched what. That's exactly what an auditor will question.

When an auditor asks whether a record was extracted intact and handled correctly, you need to be able to show them. XSN Rescue is built to close that gap.

Free and manual options included, not just ours — read the InfoPath retirement guides: what happens to your forms after 14 July · how to archive your form data · export & recover .xsn data · an archivist’s checklist · How to archive InfoPath forms as PDF for records retention · Can you still install InfoPath in 2026? An honest answer · How to export InfoPath form data to CSV or Excel · How to open an .xsn file without InfoPath · "InfoPath cannot open a new form" — what each error means, and how to get at your data · Your InfoPath .xml opens as raw XML: the missing-template problem.

How it works

A controlled recovery, start to finish

Four stages, every one of them logged. You keep custody of the data throughout — nothing is done that you can't later show, in order, to a regulator.

1

Discover & inventory

We locate your .xsn templates and associated form data across file shares, SharePoint, and archives, and produce a complete manifest.

Scoped & read-only
2

Extract with integrity

Each template and its records are parsed faithfully — fields, structure, and attachments — and hashed against the source so you can see whether anything changed.

SHA-256 verified
3

See what you are holding

Every field comes out with its label and its type, exactly as the form defined it — so you can see what you are holding and decide how to treat it.

Field catalogue
4

Deliver & record

Data lands as CSV, JSON, readable HTML and one archival PDF per record, with a batch manifest and an integrity report for every run.

Manifest & report
What it does — 30 seconds

A quick look at XSN Rescue.

What the tool actually does: read your .xsn templates and filled-in .xml records locally, recover the field values with their labels, and leave the originals untouched. Captions on — no sound needed.

XSN Rescue — by High Caliber. This is an animated overview of what the tool does — an illustration, not a screen recording of the app. Your original files are only ever read.

The audit trail

A true audit trail — not a log file you have to trust.

The Estate tier records each recovery as a hash-chained evidence pack. Every pack carries a manifest listing each file, its size, its SHA-256 and the chain's root digest — so a recipient can recompute the hashes with standard tools and confirm nothing changed, with none of our software involved. XSN Rescue also includes a verifier that does the same in one step, and it is never licence-gated. If a single entry were altered after the fact, the chain breaks and it shows. This is the evidence you hand to an auditor who asks whether the record left InfoPath intact and unchanged.

⛓

Hash-chained, and checkable

Each event is hashed and linked to the one before it. Any change to any record invalidates every entry that follows.

⚖

A recorded chain of custody

Who did what, to which record, when, and with which result — captured automatically, attributable to a named identity.

↺

Source-to-output provenance

Every extracted record traces back to its original .xsn source and its integrity hash, so nothing is orphaned or unexplained.

⇩

Export-ready evidence

Every run writes a human-readable integrity report you can keep or hand on — it names each file read, its hash before and after, and anything that could not be recovered.

How a custody pack is put togetherIllustration
A batch is opened
Recorded with the identity the run was made under — your own operator, on your own machine.
entry: action · timestamp · operator
Each file is read, hashed and entered
SHA-256 before it is opened and again at the end, recorded file by file.
entry: name · size · sha256
Every entry carries the digest of the one before it
Remove or edit a line and the chain no longer agrees with itself — visibly.
entry: prev_digest → entry_digest
The pack manifest is written
Listing every entry and closing with the chain’s root digest, so a recipient can recompute the lot.
pack-manifest.json · root_digest

This is an illustration of how a pack is structured — the field names are real, the values are not shown, because this is not a real run. For genuine output, see the recovery-report screenshot.

Evidence, not assurances

You shouldn’t have to take our word for it. Neither should your auditor.

The records stranded in InfoPath are often the most sensitive an organisation holds. So the question isn’t whether a tool got them out — it’s whether you can show, afterwards, exactly what happened to them. Everything below is something you can check yourself.

◎

Hashed before, hashed after

Every file is hashed with SHA-256 before it is read and again when the run finishes, and both hashes go in the report. If they match, the record left InfoPath intact. You are not trusting a log entry that says so — your auditor can recompute the hash themselves and see it for themselves.

⌂

It runs inside your boundary because there is nowhere else to run

No service to upload to. No account to create. Your records are never transmitted — so there is no copy of them to intercept, no third party holding them, and nothing of yours for anyone to subpoena from one. That isn’t a policy we promise to keep — it’s the shape of the software. No records, no file contents and no telemetry leave the machine: the app’s own network use is licence activation and a version check, and neither carries anything from your files. Choosing Buy simply opens our checkout in your own browser.

⚿

Your originals are only ever read

Opened read-only, and byte-for-byte identical afterwards. We measure that on the exact build you download — not on a development copy — against real files, before every release, and the measurement ships inside the product with the build’s own hash on it.

▤

Evidence somebody else can re-check

The Estate tier writes hash-chained evidence packs, and every pack contains a machine-readable pack-manifest.json listing every entry, its size, its SHA-256 and a chained root digest — so a recipient can recompute the whole chain with standard tools and none of our software. XSN Rescue also includes a verifier that does the same in one step, and it is never licence-gated. It also re-verifies a corpus later, so you can show nothing drifted between one audit and the next.

What this does not do, said plainly. It does not certify you, and no tool can — whether you meet a framework depends on your lawful basis, your retention schedule and your own processes, not on any software. What it does is document the recovery itself, and hand you evidence anyone can recompute.

Before you extract anything

Know what is in the forms before you open them.

The reason a form library sits untouched for years is rarely the extraction. It is that nobody can approve a bulk export they cannot describe. This turns four thousand unknown fields into a named list you can actually review.

◍

It tells you which fields are likely to hold regulated data

Dates of birth, national insurance and NHS numbers, card and account details, names and contact details — each one named, with the reason it was flagged, in the report, before you export a single record.

✓

A first pass for your review, and it says so

It reads field names and types, not the values inside them. So it will find a field called dateOfBirth, and it will not find a date of birth typed into a field called notes. Treat it as the pass that makes a manual review possible, not one that replaces it — that is exactly what it is for.

⌂

It writes nothing and changes nothing

Flagging only reads the form’s own field catalogue. Your originals are opened read-only, as always, and are byte-for-byte identical afterwards.

Scope & compatibility

What it recovers — and what it honestly doesn’t.

We separate what the tool does from what it doesn’t, so there are no surprises. The right-hand column is stated plainly rather than glossed over.

Today

Recovers today

  • ✓.xsn form template (CAB) → solution name & version
  • ✓.xsd schema → field catalogue (name, type, path)
  • ✓.xml form data → every filled-in value
  • ✓Attachments → decoded from base64 back into real files
  • ✓.xsl views preserved in the HTML rendering
  • ✓Export → CSV · JSON · HTML + archival PDF per record + estate-inventory report + recovery report
Stated plainly

Not recovered (stated honestly)

  • —Code-behind (managed code/script) — not executed
  • —External data connections & user-role logic
  • —Digital signatures — surfaced, not cryptographically verified
  • —Archival PDF uses a standard Latin font (no font embedding) — out-of-set characters are marked [U+XXXX] and counted; the JSON export preserves the exact text as read from the file

Which InfoPath forms? XSN Rescue parses the open XML and CAB structure of InfoPath files directly, so it opens filled-in forms and templates from the InfoPath 2010 / 2013 era — the versions most SharePoint form libraries and share drives are still holding today — and will also open data from other InfoPath versions. Every run writes a recovery report saying exactly what it found, so you can see what came out.

On the XSL views: XSN Rescue does not execute the template’s XSL. It lays the recovered fields out itself, as a readable HTML table of labels and values, and preserves each of the template’s XSL view transforms verbatim beside it — so the original view definition is kept with the data rather than re-rendered. Conditional formatting, script and ActiveX/managed-code behaviours are therefore not reproduced. The recovered data table is what the tool is for — and the report on every run states what it read and what it could not.

◆

SHA-256 before and after

Each source file is hashed before it is opened and again after it is closed, and both hashes go in the report. If the two agree, the original was not altered — and anyone can recompute them without our software.

§

Read-only, and recorded

Every run writes a dated report naming which files were read, what was recovered, what could not be, and the read-only mode used.

⚑

Your records never leave your machine

There is no service to send records to and no account to create. No records, no file contents and no telemetry leave the machine — the app’s own network use is activating your licence key and asking our site whether your version is still supported, and neither carries anything from your files. Choosing Buy simply opens our checkout in your own browser. Recovery itself runs with the network down.

⚖

Hash-chained custody record

Each entry carries the hash of the one before it, so a removed or edited line breaks the chain visibly. Every pack carries a manifest of each file, its SHA-256 and the chain’s root digest, so a recipient can recompute it with standard tools and none of our software; the verifier that does it in one step is included and never licence-gated. It is tamper-evident, not cryptographically signed — we say which, because an auditor will ask.

Built for the audit

SHA-256 before and after, in a report your auditor can recompute themselves.

XSN Rescue was designed backward from the question a regulator actually asks: is this record complete, is it unaltered, and was it handled correctly? Every feature exists to answer that question.

Every run
writes a dated report you keep
0
records leave your environment
SHA-256
on every source file, before and after
Pricing

Buy it once. No subscription, ever.

One flat price for your whole organisation — no per-seat counting, and no subscription for reading your own forms. Most organisations need Standard. Estate and Enterprise exist for records under audit and for groups covering several entities.

XSN Rescue Estate

£999

one-time payment · no subscription, ever

one organisation · up to 25 devices

Everything in Standard, plus a governance layer for an estate under scrutiny: eDiscovery and subject-access search across your whole recovered corpus with a methodology report, ongoing re-verification so you can show nothing has drifted between audits, hash-chained auditor evidence packs with a free verifier anyone can check, and an automation licence to run it headless on a schedule (open XSN Rescue on that computer at least once every 21 days to keep the licence current).

Buy Estate — £999

Compare Estate and Enterprise in full →

XSN Rescue Enterprise

£1,995

one-time payment · no subscription, ever

group-wide · 100 activations

Everything in Estate, licensed across a whole group rather than one organisation: 100 activations on your group’s key, so separate entities or sites can each install without buying again. Need a separate key per site, so one can be withdrawn without affecting the others? Tell us before you order and we’ll set it up that way.

Buy Enterprise — £1,995

Buying for an organisation that can’t pay by card? Email support@highcaliberapplications.com before you buy.

Each tier is a superset — nothing is held back from a lower one to sell a higher one. Every export format, decoded attachments, the estate-inventory report and the SHA-256 integrity receipt all stay in Standard at £499. Estate and Enterprise only add artefacts, licensing and paperwork on top. All three run entirely on your own computer, read-only on your originals. See the full Estate and Enterprise detail.

System requirement: the app runs on Windows 10 and 11 (64-bit) and on macOS 10.15 or later, on both Intel and Apple silicon — one universal Mac download. One purchase covers both platforms; there is no separate Windows licence to buy, and both installers are in your account the moment you buy.

Comes with a 14-day money-back guarantee. If it doesn’t do what this page says for your files, tell us and you get a full refund — email support@highcaliberapplications.com (refund policy). Sold by High Caliber Trading Ltd, registered in England & Wales, company no. 13118124.

Microsoft’s support for InfoPath Forms Services ended on 14 July 2026. In Microsoft 365 the service has been removed and new responses cannot be submitted. On SharePoint Server it still runs — unsupported, unpatched, and expected to fail as browsers and updates move on. Either way, the responses you already hold are XML you can open — but what they mean lives in the .xsn template, and your attachments are still encoded inside them. Open one and you get values without their labels, with a document sitting in the middle of it as base64.

The question you will be asked is not whether the data came out. It is: is this record complete, was it altered, and how do you know? That is the question this was built backwards from — the hashes, the read-only opening of your originals and the custody chain exist so you can answer it with a document rather than an assurance.

High Caliber Trading Ltd
FAQ

Straight answers.

Why £499?

Because it’s priced against the alternative, not against an app. One licence covers your whole organisation, up to 25 devices, with no renewal — so compare it with someone spending a fortnight extracting forms by hand, or with having to explain an uploaded HR file to your data-protection lead. And you don’t have to take our word for it: download it free, run it on your own records, and pay only if it works. If it doesn’t do what this page says for your files, tell us within 14 days and you get a full refund.

What if I have thousands of files?

That’s the normal case, and it’s what the tool is built for. Point it at a folder, and it works through everything it finds, then gives you an estate-inventory report: how many templates, how many records, how much data, and which files didn’t parse and why. Nothing is skipped quietly — every file appears in the report with its outcome.

What if it can’t read my forms?

You’ll know before you pay — that is exactly what the free download is for. Open your own .xsn / .xml and see what comes back, on your own machine, with nothing uploaded. And if you have already bought: if it doesn’t do what this page says for your files, tell us within 14 days and you get a full refund.

Will it change my original .xsn or .xml file?

No. It opens your file read-only — to read it, never to write to it. Your original is left exactly as it was, and every recovery report records source_modified: false for each file so you can check for yourself. Exports are saved as separate files.

Do I need InfoPath or a Microsoft 365 subscription to use it?

No. XSN Rescue reads the files directly on your own machine. You don’t need InfoPath installed, and you don’t need any Microsoft 365 licence or subscription.

Does it upload my files anywhere?

No. Recovery runs entirely on your own computer, with no upload and no account — the recovery engine contains no networking code. No records, no file contents and no telemetry leave your machine. The app’s own network use is licence and version information: checking your licence key (at activation, and again at each app launch to re-confirm it), and reading a small version list on our own website before an export, so a withdrawn build can tell you to update — that check fails open if our site is unreachable. The licence check sends your licence key and a device identifier (a one-way hash, not your name and not your file names); the version check only fetches a file and sends nothing about you, your files or your machine beyond the ordinary web request itself. Neither sends your files or their contents. Choosing Buy simply opens our checkout in your own browser.

What if the machine is offline, or on a restricted network?

Activating your licence needs an internet connection once — the licence server has to register the activation, so there is no offline or air-gapped activation route. After that the app re-confirms the key each time it launches, and if it can’t reach the licence server it carries on working for up to 21 days from the last successful check, so a firewall, an outage or a spell off the network doesn’t stop you. The version check before an export fails open: if our website is unreachable, the export goes ahead. Recovery itself never needs a network at all.

Which versions of InfoPath does it work on?

It reads filled-in forms and templates from the InfoPath 2010 / 2013 era — the versions most organisations still hold. Because it parses the open XML and CAB structure directly rather than relying on a specific InfoPath build, it also opens templates and data from other versions. Every run writes a recovery report telling you exactly what it found.

What exactly can it recover?

From an .xsn template: the solution name/version, the field catalogue (name, type, dotted path) from the XSD, and the XSL views. From a form-data .xml: every filled-in leaf value, including repeating and nested sections. Attachments inside a form are decoded from base64 back into real files (a Word or Excel document comes out as a valid .docx/.xlsx). It exports all of that to CSV, JSON and HTML, plus one self-contained archival PDF per recovered record, an estate-inventory report over every form in that folder, and a recovery report.

What can’t it recover?

Form code-behind (managed code/script), external data connections and user-role logic are not executed or recovered — only the data and static layout. Digital signatures are surfaced as fields but not cryptographically verified. The archival PDF uses a standard Latin font, so out-of-set characters are marked [U+XXXX] and counted (the JSON export preserves the exact text as read from the file). The recovery report states this per file.

Does it crack passwords or bypass protection?

No — and it doesn’t need to. InfoPath forms aren’t encrypted. The tool reads files you already own and have the right to access; it performs no password cracking and no DRM circumvention.

Is there a Windows version?

Yes. XSN Rescue runs on Windows 10 and 11 (64-bit) and on macOS 10.15 or later (one universal download for Intel and Apple silicon). One purchase covers both — after you buy, both installers are in your account, so you can put it on a Mac and a PC without buying twice. The Windows installer is code-signed under High Caliber Trading Ltd.

Is this a Microsoft product?

No. It’s independent and not affiliated with, endorsed by, or connected to Microsoft Corporation. “Microsoft” and “InfoPath” are trademarks of their owner, used here only to describe the file formats this tool reads.

Get started

Recover your InfoPath records while something can still make sense of them.

Start with the free download. It opens your own .xsn files, names the fields that look like they hold regulated data, and shows you what a recovery would produce — before you pay anything and without writing to your originals. If it cannot read your forms, you have lost nothing.

Runs on your own machine · Your records never leave it · Originals opened read-only · 14-day money-back guarantee
Questions first? Ask us a question.

Independent — not affiliated with Microsoft. XSN Rescue is an independent recovery tool. It is not affiliated with, endorsed by, sponsored by, or connected to Microsoft Corporation. “Microsoft” and “InfoPath” are trademarks of Microsoft Corporation, referenced here solely to describe the file formats this tool reads (nominative use). InfoPath is a discontinued Microsoft product; this page states its published retirement date as honest context and creates no false urgency. The tool works only with files you already own and have the right to access; it performs no DRM removal, password cracking, or circumvention of technical protection. All product and file-format names are the property of their respective owners.

Keep in touch

Want to hear as it grows?

No spam, ever. Unsubscribe any time.

We keep your address to answer your enquiry about XSN Rescue and nothing else.