Most disposal disputes are not about whether data was destroyed. They are about whether it can be shown. A vendor's letter covering a consignment does not answer a question about one laptop, and an email saying the job is done answers nothing at all.
Every asset we process produces its own certificate. It names the device by serial, states the standard applied and the number of passes, records who ran it and when it started and finished, and reports the result of the verification read-back that followed.
The document is hashed and signed. A certificate that has been edited will not validate, which is the property that makes it evidence rather than a claim.
The Risks This Removes
One Letter for a Whole Consignment
A note saying 200 drives were destroyed cannot answer a question about drive number 147. Audits and incidents are always about one asset, which is the one thing a consignment letter cannot address.
A Document Nobody Can Check
If a certificate can be edited in a word processor after the fact, it proves only that somebody had a word processor. Evidence has to be verifiable by someone who was not there.
Written After the Fact
A document typed up later records what somebody remembered, not what the machine did. The gap between the two is exactly where mistakes and omissions live.
Generated by the Process, Not After It
The certificate is written from what the erasure actually did, at the moment it did it. Nothing is typed in afterwards, which removes both the transcription errors and the opportunity for anything to be adjusted later.

Filed the Way Audits Ask for It
Certificates export individually or as a batch, with CSV alongside for your records system. Filter by date, site, client or asset reference. When an assessor asks about one serial number, the answer is a search rather than a project.

The Process, Step by Step
The Asset Is Identified
Make, model, capacity and serial are read from the device itself. Everything on the certificate hangs off that identification being correct.
The Method Is Recorded as It Runs
The standard, the pass count and the command issued are captured by the process, not typed in afterwards.
Verification Is Recorded Separately
The read-back and its result are their own entry. Pass, fail, or could not be attempted — all three are real outcomes and all three appear.
The Document Is Generated
Produced by the run that did the work, at the moment it finishes, carrying what actually happened rather than what was planned.
It Is Hashed and Signed
A digital signature over the contents. Change a character afterwards and the signature stops validating, which is the property that makes it evidence.
It Is Reconciled and Handed Over
Every certificate is checked against the list of assets received before anything is sent back to you.
What Makes This a Document You Can Rely On
One per Asset
Not one per pallet, per consignment or per invoice. The unit of the document is the unit an auditor asks about.
Generated by the Process
The run that erased the drive is what writes the certificate, at the moment it finishes. Nothing is transcribed, so nothing is transcribed wrongly.
Signed, so Edits Show
The contents are hashed and signed. An altered certificate fails validation instead of passing quietly, which is the whole difference between a record and a claim.
Failures Appear Too
A drive that did not verify is on its own certificate as failed. A set of documents where everything succeeded is not more reassuring, it is less.
It Names the Method
The standard applied and the command issued, not the word 'wiped'. On flash especially, that line is what an auditor is actually reading.
You Can Read One First
Sample certificates are published in full, with no form in front of them, so you can check the document against your own framework before you commit to anything.
What Each Certificate Records
- Device serial number, model and capacity
- Your own asset reference or tag, where supplied
- The erasure standard applied, named in full
- Pass count and the pattern used
- Start time, end time and total duration
- Operator identity and processing location
- Post-erase verification result — pass or fail, with the sampling method
- Outcome where erasure was not possible, and what was done instead
- The drive's SHA-256 hash from before the run and after it
What Is on the Certificate
Enough for somebody who was not present to establish which device was processed, what was done to it, whether it worked, and who is accountable — and to tell whether the document has been altered since.
- Make, model, capacity and serial number of the asset
- Your own asset reference, where you supplied one
- The sanitization standard applied, and the number of passes it ran
- The exact operation issued, which matters most on flash media
- The verification result: passed, failed, or not attempted, and why
- Where the asset was destroyed instead, the method of destruction
- Start and finish time, the operator, and the site
- A certificate reference, and a signature that fails if the document is edited
- SHA-256Signature on Every Certificate
The report is hashed and signed as it is written, so a certificate altered after the fact no longer verifies.
- 9 fieldsRecorded on Every Certificate
Make, model, capacity, serial, method, start time, finish time, operator and result. Every one of them is checkable against the asset itself.
- 1 per assetCertificate, Never One per Batch
A pallet-level report proves a pallet was handled. It does not answer the question an auditor asks, which is about one specific machine.
- 0 expiryThe Certificate Does Not Lapse
It records something that happened on a date; it is not a licence. It stays valid for as long as you need to keep it.
What Standards Say About the Record
The recurring theme is that sanitization is not finished when the data is gone. It is finished when it has been verified and documented.
NIST SP 800-88 Rev. 2
Treats verification and documentation as part of the sanitization process, and asks the record to identify the specific media, the method used and the person responsible. Its own appendix is effectively a certificate template.
When it appliesAny disposal programme written against NIST, which is most of them.
IEEE 2883-2022
Requires the outcome to be verified rather than inferred from a command completing, and the verification itself to be recorded.
When it appliesRecently written policies, and mixed magnetic and flash estates.
ISO/IEC 27001, Annex A
Its secure disposal control expects a documented, repeatable process. At audit that is demonstrated with the documents, not with the procedure.
When it appliesOrganisations certified to ISO 27001 or audited against it.
PCI-DSS Requirement 9
Media holding cardholder data must be rendered unrecoverable and the destruction documented — an unevidenced destruction does not satisfy it.
When it appliesAny environment that has held cardholder data.
GDPR, Article 5(2)
The accountability principle: you must be able to demonstrate compliance, not merely achieve it. For a retired asset, the certificate is the demonstration.
When it appliesAny organisation holding personal data of people in the EU or UK.
DPDP Act, 2023 (India)
Requires erasure once the purpose has ended. Where a regulator or a customer asks you to show it happened, a per-asset record is what answers.
When it appliesAny organisation processing personal data of people in India.
Where People Go from Here
Sample Certificates
The actual PDFs the software produces, published in full. No form, no email address.
Read moreWhat Belongs on a Data Erasure Certificate
The longer version, for anyone who has to judge a vendor's document against their own framework.
Read moreChain of Custody
The record that says which asset, whose it was, and who held it — the certificate's other half.
Read moreFrequently Asked Questions
Does the certificate expire?
No. It records something that happened on a date. It stays valid indefinitely, including after you stop using our software or services.
Can it carry our branding?
Yes. For resellers and service providers the certificate carries your logo and company details, so the document your client files is yours.
How would anyone know if it had been altered?
The document is locked against editing and copying when it is generated, and it carries the drive's own hashes. A letter asserts that a drive was wiped; this records the readings the run took and lets them be compared.
Can we see one before committing?
Yes — sample certificates are published in full, with no form to fill in. Both of our competitors make you register first; we do not think you should have to.
Download a Real Sample
The exact PDF your auditor receives, with nothing removed. No form, no email address.
See Sample Certificates
