Frequently Asked Questions
93 questions, answered on the pages that cover them and collected here.
- Home
- Company
- FAQ
Proof, Standards And Compliance
Erasure Standards
Read the pageWhich standard should we use by default?
NIST SP 800-88 Rev. 2 — Clear for media staying inside the organisation, Purge for media leaving it. It is the most widely accepted baseline and it is written for current storage rather than for 1990s drives.
Is DoD 5220.22-M still required?
Rarely by name, but many internal policies still cite it and some customers ask for it, so it is implemented. It runs three passes with verification. NIST superseded it as the reference standard.
Why offer Gutmann at all if it adds nothing?
Because policies still name it. Where a policy says Gutmann, the run has to say Gutmann. The description in the table says plainly that it has no advantage on current drives.
Can verification be turned off to save time?
Not where the standard requires it. On those methods the option is locked and the reason is shown to the operator. Turning it off would mean the run was no longer that standard.
What happens on a self-encrypting drive?
Cryptographic erase destroys the key rather than overwriting sectors. There is no plaintext left to hash, so hash verification is locked off for that method rather than on.
Compliance Guide
Read the pageDoes using this software make us DPDP compliant?
It gives you the erasure and the evidence, which is the part of the obligation that touches storage media. Compliance is broader than disposal, and no software makes an organisation compliant on its own.
How long should we keep the certificates?
For as long as you are answerable for the asset, which is set by whichever framework applies to you rather than by the erasure. They are ordinary PDFs and can be archived with the rest of your evidence.
Our recycler says they wipe drives. Is that enough?
It depends whether they give you a per-device record, and whether the data left your premises before it was erased. Erasing on site, before the asset moves, removes the question entirely.
Is a record valid if the drive was destroyed instead of wiped?
Yes. Destruction is a legitimate outcome and it is the correct one for a drive that cannot be sanitized. What matters is that the record says which happened to which serial number.
Do you claim any certifications yourselves?
Not here. Where the software implements a published standard, that is stated and can be checked against the run itself. Anything held by our services operation is separate from what the software does.
How-To Guides
Read the pageCan I wipe the drive Windows is running from?
Not from inside Windows. Boot the machine from the USB image or over PXE; the drive is then no longer in use and can be erased whole.
How many drives can run at once?
Up to eight, set from the application's Concurrent Sanitization Limit. Each is tracked as its own job, so a failure on one is reported rather than hidden by the others finishing.
Does a free space wipe protect files I deleted last year?
It overwrites the unallocated space those files used to occupy, which is where they still are. It cannot reach a copy that a backup or a shadow copy took at the time.
Is overwriting enough on an SSD?
Not on its own. The controller decides where writes land and can retire blocks that overwriting never reaches. Issue the drive's sanitize or crypto-erase command, then verify it.
Do I need an internet connection?
No. The erase runs offline. A connection is only needed to activate a licence, and offline activation exists for machines that never get one.
Reports & Certificates
Read the pageAre these real exports or mock-ups?
Real exports. Both files are produced by the desktop application in the ordinary way and published unedited. The asset details in them are from our own test hardware.
Do I have to give an email address?
No. Both files are linked directly on this page. There is no form and nothing is recorded when you download them.
Can the PDF be altered after it is issued?
The files are generated with document protection set, and the verification hashes are part of the document. A changed report no longer agrees with the readings it carries.
Can we put our own organization on the certificate?
Yes. The organization, the operator, the approver and the final release team are all recorded on the report from the details set in the application.
Is there a report for a machine that was tested but not wiped?
Yes — that is the second file. The hardware test report is produced by a diagnostic pass on its own and is what you would use to grade a machine for resale rather than to prove erasure.
Media And Services
Hard Disk Drive Sanitization
Read the pageHow many passes do I actually need?
On a modern hard drive, one verified pass renders the data unrecoverable — that is NIST SP 800-88's position. Multi-pass patterns like DoD 5220.22-M exist because some policies still name them, so we support them, but they take longer and add nothing on current media.
Can data be recovered after degaussing?
No. Degaussing destroys the magnetic servo tracks the drive uses to find its own data, so it is not just erased but unusable. That is also why a degaussed drive cannot be resold.
Do you shred on our premises?
Yes. Our mobile unit works on your site, under your supervision, and nothing leaves the building. You receive a certificate per drive and, if you want it, a video record.
What about drives still inside laptops and servers?
We can erase in place by booting the machine from USB or PXE, or extract the drives and process them in a bay. Whichever is faster for the volume you have.
Solid State Drive Sanitization
Read the pageWhy not just overwrite an SSD several times?
Because it does not reach the reserve blocks and it wears out the drive. Multi-pass overwriting on flash gives you a shorter drive life and no additional assurance. NIST SP 800-88 says the same thing.
Is cryptographic erase really enough?
On a properly implemented self-encrypting drive, yes — the data was only ever stored as ciphertext, and destroying the key leaves nothing that can be decrypted. It is NIST's defined Purge method for SEDs. We verify afterwards regardless.
What if the drive refuses the sanitize command?
Some older or firmware-locked drives do. Those are flagged and physically destroyed instead, with the reason recorded on the report. We do not fall back to an overwrite and call it done.
Can you erase soldered storage in a laptop?
Yes, for eMMC and UFS we boot the machine and sanitize the embedded device in place. Where the controller does not support it, the board is destroyed instead.
Flash Storage Sanitization
Read the pageCan a USB stick be securely wiped at all?
Sometimes. Better-quality devices implement a sanitize command and can be verifiably erased. Many cheap ones cannot, and for those the only defensible answer is destruction. We test rather than assume.
What about SD cards from cameras and dashcams?
Same treatment. They are handled as flash media, tested for a real erase capability, and destroyed if they do not have one.
Is there a minimum quantity?
No. We process single devices as readily as a crate of them, and the certificate is per device either way.
Do you handle encrypted USB drives?
Yes. Hardware-encrypted drives can usually be cleared by destroying the key, which is fast and verifiable. Software-encrypted volumes are treated as ordinary media.
Mobile Phone and Tablet Sanitization
Read the pageIs a factory reset enough on a modern phone?
On a current encrypted handset it is usually effective, because the key is discarded. It still tells you nothing about whether it worked. Certified erasure adds the verification step and the document — which is what you actually need when a device leaves your control.
Do you handle both Android and iOS?
Yes, both, along with tablets on either platform. Method depends on the storage and the platform rather than the brand.
What happens to locked devices?
They are separated and reported. A device tied to an account cannot be processed or resold legitimately, and we will not pretend otherwise.
Can you erase before we hand devices back on lease?
Yes, and this is the right time to do it. Once the handset is back with the leasing company, the certificate is the only record you hold.
SAN, NAS and Server Sanitization
Read the pageCan you work inside our data centre?
Yes. Our engineers work on your floor, under your access control and your cameras, and no media leaves the building until you hold the certificates.
How do you handle RAID sets?
Data is striped, so erasing one member proves nothing about the set. We erase every member drive and reconcile the serials against the array configuration, so the whole set is accounted for.
Do we have to take the array offline?
Not for volume-level erasure. If the whole array is being retired then it comes out of service anyway, and drives are processed in bulk.
What about drives under warranty that must go back?
Cryptographic erase or a verified sanitize leaves the drive functional and returnable. You keep the certificate; the vendor gets a working drive with nothing on it.
Digital Storage Device Sanitization
Read the pageDo these devices really hold sensitive data?
Routinely. Footage, biometric templates, location histories and cached documents are all personal data under the DPDP Act and GDPR, and all of them sit on devices that are usually disposed of informally.
What if the device has no erase function?
Many do not. In that case the storage is removed and processed separately, or the device is destroyed. Which one happened is recorded.
Can you work on devices still installed?
Yes. For fixed installations such as CCTV and access control our engineers work on site, so the units do not have to be shipped anywhere.
Do printers and copiers need this?
Yes, more than most people expect. Office multifunction devices keep an internal drive holding images of everything scanned, copied and printed, often for years.
On-Site Sanitization
Read the pageWhat do you need from us on the day?
A room with power, access for the equipment, and someone to sign the assets in and out. Everything else comes with us.
Can our compliance team watch?
Yes, and most do. We can also record video of the destruction run and supply it with the certificates.
How many drives can you process in a day?
It depends on the media, the capacity and the standard. Drives run in parallel rather than one after another, so throughput is a function of how many bays are on the job. Tell us the volume and we will tell you the number of days.
Do you work outside business hours?
Yes. Data centre and branch work is frequently done overnight or at weekends to fit the window you have.
Chain of Custody
Read the pageWhat does the custody record actually contain?
Asset serial and your reference, collection date and location, seal numbers, every handover with signatures and timestamps, and the processing outcome. It reconciles line for line with the certificates.
Can we avoid transport altogether?
Yes — on-site processing means the media never moves. Custody documentation still applies within your own premises.
What happens if a seal is broken on arrival?
The consignment is quarantined, you are notified, and the discrepancy is recorded. It is not processed until it is resolved.
How long are records retained?
Certificates and custody records are retained for the period your policy requires, and you receive your own copies regardless.
Certificate of Destruction
Read the pageDoes the certificate expire?
No. It records something that happened on a date. It stays valid indefinitely, including after you stop using our software or services.
Can it carry our branding?
Yes. For resellers and service providers the certificate carries your logo and company details, so the document your client files is yours.
How would anyone know if it had been altered?
The document is locked against editing and copying when it is generated, and it carries the drive's own hashes. A letter asserts that a drive was wiped; this records the readings the run took and lets them be compared.
Can we see one before committing?
Yes — sample certificates are published in full, with no form to fill in. Both of our competitors make you register first; we do not think you should have to.
Sectors
Data Erasure for Enterprise IT
Read the pageDoes this work without an internet connection?
Yes. Licences can be activated offline and the software runs entirely on your own network. Certificates are generated and stored locally. This is how most government and defence deployments run.
Can we match certificates to our asset management system?
Yes. Asset tag and custom fields are captured at erasure time and appear on the certificate, so records line up with your CMDB or ITAM tool without manual reconciliation.
What happens to a drive that fails erasure?
It is marked as failed on the report and excluded from the pass list. A drive that cannot be verifiably erased should be physically destroyed, and the report tells you exactly which ones those are.
How many machines can one operator handle?
One machine runs up to eight drives at once, set from the Concurrent Sanitization Limit. The bigger multiplier is booting over the network: one operator starts erasure across a whole floor of workstations from a single console.
Data Erasure for ITADs and Recyclers
Read the pageHow is it licensed for a processing floor?
Per device erased, not per seat or per machine. You can run it on as many stations as you like and pay for the drives you actually process. Licences do not expire.
Can we put our own branding on the certificate?
Yes. Certificates carry your logo and company details, so the document you hand back to a client is yours rather than ours.
Does it handle SAS and enterprise drives?
Yes — SATA, SAS, NVMe, M.2, mSATA and PCIe, including self-encrypting drives, where cryptographic erase is issued rather than an overwrite.
Can erasure data go into our ERP?
Reports export as CSV and PDF for import into ERP and inventory systems, so certificate data does not have to be re-keyed.
Data Erasure for Data Centres
Read the pageCan you erase a LUN without taking the array offline?
Yes. Volume-level erasure runs against the presented LUN while the array stays in service, so decommissioning a volume does not mean a maintenance window for everything else on the same hardware.
How are self-encrypting drives handled?
By destroying the encryption key rather than overwriting the ciphertext. This is the method NIST SP 800-88 defines as Purge for SEDs, it takes seconds instead of hours, and the result is verified afterwards.
What about drives that have already failed?
A drive that cannot be read cannot be verifiably erased. Those are flagged for physical destruction and listed separately on the report, so the exception is documented rather than hidden.
Do you work on site?
Yes. Our engineers work inside your facility, under your access controls and your cameras, and nothing leaves the building until you have the certificates.
How do you know a drive is self-encrypting?
The drive is interrogated before anything is written to it, and it reports its own security features. That answer decides the method, which is why the identify step comes first rather than being assumed from the model number on the label.
Can this run without a connection out of the building?
Yes, and in most data centres it does. Licence activation is offline and certificates are written to storage you control. Nothing about the drives processed is transmitted anywhere.
Why not just shred everything and be done with it?
Because most of what comes out of a rack is a working enterprise SSD with years left in it, and destroying one costs the price of the drive plus the carbon that made it. Shredding is the right answer for a drive that cannot be verified. For the rest it is an expensive way to avoid producing evidence.
How long does a rack take?
It depends on the media, the capacities and the standard your policy names — a cryptographic erase is seconds, a multi-pass overwrite of a large platter drive is hours. Benches run in parallel, so the useful question is how many you can put on the job. Tell us the media mix and the window, and we will give you the number of days.
Data Sanitization for Government and Defence
Read the pageCan the software be used on a classified network?
It runs fully offline. Nothing is reported back and nothing is sent out. Licence activation has an offline path, so the machine never needs a route to the internet at any stage.
Which standard should we apply?
NIST SP 800-88 Rev. 2 selects the method from the medium rather than applying passes for their own sake. Where local policy names DoD 5220.22-M or HMG IS5, those are implemented and recorded by name on the certificate.
How is the certificate protected from tampering?
Each certificate carries the drive's SHA-256 hash from before the run and after it, and the PDF is generated with editing and copying disabled. What an assessor checks is that the two hashes agree with the outcome the document claims.
Do you support on-site destruction as well as erasure?
Yes. Where policy requires physical destruction, we shred on your site under your supervision and issue a certificate of destruction per asset.
Data Erasure for Banking and Finance
Read the pageDoes this satisfy PCI-DSS media destruction requirements?
PCI-DSS requires cardholder data to be rendered unrecoverable and the process to be documented. Certified erasure with per-asset verification and a signed certificate addresses both parts. The certificate names the method and the verification result.
What does the DPDP Act require on disposal?
Personal data must be erased once the purpose for holding it is served, and a data fiduciary must be able to demonstrate compliance. Per-device certificates are how that demonstration is made for retired hardware.
Can we erase without the hardware leaving the branch?
Yes. The software boots from USB and needs no network. Erasure and certificate generation both happen on site, before anything is moved.
How long are certificates valid?
Indefinitely. A certificate records something that happened on a date; it does not expire, and it stays valid even if you stop using the software.
Data Erasure for Healthcare
Read the pageIs deleting files or formatting a drive enough?
No. Both remove the index that points at the data and leave the data itself on the medium, where ordinary recovery software will find it. Sanitization overwrites or purges the medium and then reads it back to confirm the result.
Does certified erasure satisfy HIPAA?
HIPAA requires PHI to be rendered unusable, unreadable or indecipherable, and points to NIST SP 800-88 for the methods. Clear or Purge under that guidance, verified and documented per device, meets that requirement.
Can you erase clinical devices that will not boot normally?
Yes, provided the drive itself is readable. The software boots independently of whatever is installed on the machine, which is what makes it usable on imaging consoles and analysers running embedded or unsupported systems. If the drive has genuinely failed it is flagged for physical destruction instead.
What about devices leased from a supplier?
Erase before the device goes back and keep the certificate. Once the hardware is with the supplier, that record is the only thing you still hold, and it is the one that answers a later question.
Do you handle destruction as well?
Yes. Where a drive cannot be erased, or your policy requires destruction regardless, we shred on your site and issue a certificate of destruction per asset.
Data Erasure for Education and Research
Read the pageCan this run overnight without staff present?
Yes. PXE-booted erasure runs unattended across the machines you target and reports results when it finishes. Most institutions run it during a break or overnight.
Does it work on Chromebooks and mixed fleets?
It boots independently of the installed operating system, so mixed Windows, Linux and Chrome fleets are handled the same way. Media type determines the method, not the OS.
What about machines being donated?
Erase and certify first, then redeploy. The certificate is what protects the institution if a donated machine is later found to hold data — and the diagnostic grade tells you whether it is worth donating at all.
Is there pricing for education?
Licences are per device erased, which suits a refresh cycle better than per-seat licensing. Talk to us about volumes and we will size it against your refresh plan.
Data Erasure for MSPs and Resellers
Read the pageCan we resell this under our own brand?
Certificates and reports carry your branding. Talk to us about partner terms if you want to go further than that.
How do licences work across multiple clients?
Licences are consumed per device erased and can be used across any number of clients and machines. Reports can be filtered by client so each one gets only their own evidence.
What support do partners get?
Direct access to the engineers who build the software, deployment help for PXE and boot media, and assistance with client-facing documentation.
Is there a minimum commitment?
No seat minimums. You buy device licences and use them when you need them; they do not expire.
Still Not Answered
Ask it directly. If it turns out others are asking the same thing, it ends up on this page.
See Sample Certificates
