SANITIZE

CertifiedNIST SP 800-88 Rev. 2 · DoD 5220.22-M · IEEE 2883

Standards, Guides and Sample Reports

The evidence behind the claims — which standards the software implements, how they map to the regulations you are audited against, and what a real certificate looks like before you buy one.

Most of what is written about data erasure online is a vendor explaining why its own method is the correct one. These pages are the opposite: what the standards actually say, which of them the software implements, and where each is and is not appropriate.

The standards page is generated from the erase engine's own register rather than typed by hand, so what the site claims and what the software does cannot drift apart. The sample certificates are real files produced by the software, downloadable without a form.

What Goes Wrong

The Risks This Removes

Standards Quoted as Slogans

DoD 5220.22-M appears on almost every erasure product sold. The document it names was withdrawn from that role years ago, and NIST SP 800-88 replaced the thinking behind it. Knowing which to ask for matters more than knowing which sounds authoritative.

Compliance Mapped by Assertion

Saying a product is GDPR compliant means nothing on its own — the regulation does not name a wipe method. What can be shown is which article an erasure record satisfies and what it has to contain to do so.

Certificates You Cannot See Before Buying

A certificate is the thing you are actually paying for, and most vendors will only show one after a sales call. The real ones are on the reports page.

What Is Here

  • Erasure standards — the full register the software implements, with what each pass actually does
  • Compliance guide — DPDP, GDPR, HIPAA, PCI-DSS and R2v3, and what each expects of a disposal record
  • How-to guides — step by step for the media people most often ask about
  • Reports and certificates — real sample PDFs, no form and no email gate
Questions

Frequently Asked Questions

Which standard should we be asking for?

For most organisations, NIST SP 800-88 — it is current, it distinguishes Clear from Purge from Destroy, and it is written around the media rather than around a number of passes. Where a regulator names something else, use that.

Are more passes safer?

On modern drives, no. Single-pass overwrite is sufficient on a platter, and on flash the number of passes is largely irrelevant because the controller decides which cells are written. Passes are a poor proxy for assurance; verification is the real one.

Do I have to give an email address for the sample certificates?

No. They are on the reports page as ordinary downloads. Putting the one piece of evidence a buyer wants behind a form is how the rest of this industry works and it is not how this site does it.

Tell us what you need

Something Not Covered Here?

Ask directly. A question about a standard usually gets a better answer than a page can give.

Goes straight to our engineers. No newsletter, no call centre.