SANITIZE

CertifiedNIST SP 800-88 Rev. 2 · DoD 5220.22-M · IEEE 2883

Digital Storage Device Sanitization

The devices that never made it onto the asset register still hold data.

Every organisation has storage it does not think of as storage. The CCTV recorder in reception holds months of footage. The biometric reader holds fingerprint templates. The conference-room display remembers what was cast to it, and the vehicle tracker remembers everywhere the vehicle went.

None of these usually appear on an IT asset register, so none of them get a disposal process. They get replaced by whoever installed them, and the old unit leaves with its storage intact.

We treat them as what they are. The device is identified, its storage is located, and it is either erased and verified or destroyed — with a record either way.

What Goes Wrong

The Risks This Removes

It Is Not on the Asset Register

The recorder in reception, the reader at the door, the printer with a hard drive in it. Nobody bought them as IT, so nobody retires them as IT — they are replaced by whoever installed them and the old unit goes in a van.

The Storage Is Buried Inside

Often there is no visible drive at all: a soldered chip, a card in an internal slot, or storage inside the mainboard. It has to be found before it can be dealt with.

What It Holds Is Worse Than Expected

Months of footage of your premises. Fingerprint templates. Scanned identity documents in a printer's spool. This is often the most sensitive data in a building and the least governed.

The Shape Of The Work

Identify, Erase, Verify, Report, Then Decide

A mixed consignment is where records usually break down. One chain across all of it is what stops that.

  1. 01

    Identify

    Every device logged as it arrives, whatever it is, so nothing is processed without first being written down.

  2. 02

    Erase

    The method appropriate to that medium. A memory card and an eight-bay array do not take the same command.

  3. 03

    Verify

    Read back and compared. Anything unreadable becomes an exception with a reason, never a silent pass.

  4. 04

    Report

    The same document off every device type, so a mixed batch still produces one consistent set of evidence.

  5. 05

    Reuse, Recycle or Destroy

    One decision per device, and a record behind each one of them.

Find the Storage First

The hard part with these devices is not erasing them, it is knowing where the data actually sits — an internal drive, a soldered flash chip, a memory card in a slot nobody opens. We identify the medium before deciding the method, rather than running a reset and hoping.

Device opened on a bench with its storage medium identified and labelled

A Record for Devices That Had None

Most of these units were never on an asset register, which is exactly why they need a certificate. The document establishes that a specific device, identified by serial, was cleared on a specific date — the record that did not exist while it was in service.

Certificate issued against a device serial with method and date
How It Runs

The Process, Step by Step

01

Find the Storage

The device is opened and inspected. What kind of storage it holds, and where, is established before anything else — a guess here is how a card gets missed.

02

Log the Device and Its Media

Both, as separate lines: the appliance by asset tag or serial, and any drive or card inside it by its own serial.

03

Remove Where It Is Removable

A drive or card that comes out is processed as that kind of media, which is faster and gives a stronger result.

04

Erase or Destroy

Removable media is erased and verified. Storage that is soldered or unreachable is destroyed with the board it sits on.

05

Verify What Was Erased

Anything cleared is read back and checked. Anything destroyed is recorded as destroyed rather than described as wiped.

06

Certify Both Lines

The appliance and its media each appear on the record, so the asset you disposed of and the storage it contained are both accounted for.

What We Handle

Appliances and Embedded Media We Handle

The common thread is that none of it looks like a computer, and all of it stores something.

Security and access

  • CCTV recorders (DVR and NVR)
  • IP cameras with onboard cards
  • Biometric readers and attendance terminals
  • Access control panels
  • Intercom and visitor-management units

Office equipment

  • Multifunction printers and copiers with internal drives
  • Scanners with stored job history
  • Video conferencing units
  • Digital signage players
  • Point-of-sale terminals

Instruments and embedded

  • Medical and laboratory instruments with local storage
  • Industrial controllers and HMI panels
  • Vehicle and fleet recorders
  • Test equipment retaining results
  • Any device with soldered eMMC or an internal card

Which Method Applies

SituationWhat We Do
Appliance has a removable hard driveRemove it, overwrite to your standard, verify, certify the drive and the appliance
Appliance has a removable card or SSDRemove it and process it as flash — sanitize command first, overwrite as fallback
Storage is soldered to the boardThe board is destroyed. There is no reliable way to clear it in place
Device will not power onOpened, storage located and destroyed — an erase that cannot run cannot be certified
Device is leased and must go back workingStorage removed and destroyed, replacement fitted where you supply one
No storage found on inspectionRecorded as inspected and no media present, which is itself a useful record
Capabilities

What the Work Gives You

Inspection, Not Assumption

Every unit is opened and looked at. A datasheet that says a model has no storage is not evidence about the unit in front of you.

Two Lines per Asset

The appliance and the media inside it are recorded separately, so a DVR disposed of and the drive that came out of it are both traceable.

Media-Appropriate Method

A hard drive out of a recorder is treated as a hard drive; a soldered chip is treated as something that cannot be cleared. The method follows the medium.

Devices Nobody Owns

These assets usually sit between facilities, security and IT. We take the whole batch and give you one reconciled record for it.

On-Site Processing

Cameras and access control are often exactly what a security policy says cannot leave the building. It does not have to.

Honest Records

Where storage was destroyed rather than erased, the document says destroyed. Those are different claims and should read differently.

Devices We Regularly Process

  • CCTV and DVR/NVR recorders, including the drives inside them
  • IP cameras and body-worn cameras with onboard storage
  • Biometric access readers holding fingerprint or face templates
  • GPS and telematics units from fleet vehicles
  • Smart displays, digital signage and conference-room systems
  • Printers, scanners and copiers with internal drives
  • Point-of-sale terminals and self-service kiosks
  • Industrial controllers and data loggers
What You Receive

What You Hold at the End

A record for the appliance and a record for whatever was inside it. The second is the one that matters at audit, and the one a general disposal note never contains.

  • The appliance by make, model and asset tag or serial
  • What storage was found inside it, with its own serial where it has one
  • Whether that storage was erased or destroyed, and by which method
  • The verification read and its result, where an erase was possible
  • Devices inspected and found to contain no media
  • Start and finish time, and the operator who ran it
  • A digital signature, so an edited certificate no longer validates
  • 25 methodsErasure Standards Built In

    NIST SP 800-88 Clear and Purge, IEEE 2883, DoD 5220.22-M, BSI, DPDP and twenty more. The software issues what the medium actually supports.

  • 100%Verified, or Listed for Destruction

    There is no third outcome. A device is either proved clean or written down as an exception with a reason against it.

  • 0 assumedDevices Passed Without Being Read

    A device nobody could read is not a device nobody needs to worry about. Unreadable media are the ones that go for destruction.

  • 1 per deviceRecord, Whatever the Device Is

    The same document comes off an eight-bay array and a memory card, so a mixed consignment produces one consistent set of evidence.

Standards & Compliance

The Standards That Apply to Embedded Media

These are the published procedures the work follows, not certifications held by this company.

NIST SP 800-88 Rev. 2

Chooses the method by media type and by where the asset is going. For storage that cannot be addressed or commanded, that choice is Destroy — which is the honest answer for most embedded media.

When it appliesThe general reference for appliance and embedded-media disposal.

IEEE 2883-2022

Covers flash storage of the kind soldered into appliances, and is explicit that a result has to be verified rather than inferred.

When it appliesDevices with eMMC or onboard flash, which is most modern appliances.

DPDP Act, 2023 (India)

Requires personal data to be erased when its purpose ends. Footage of identifiable people and biometric templates are personal data, and a fingerprint template is about as personal as it gets.

When it appliesAny organisation running cameras or biometric access in India.

GDPR, Articles 5 and 17

Personal data is not kept longer than necessary, and must be erased on request with evidence. A recorder holding a year of footage of staff and visitors engages both.

When it appliesAny organisation operating such systems in the EU or UK.

HIPAA Security Rule

Requires policies for the disposal of electronic protected health information and the media it sits on — which includes an instrument that stored results locally, not only the hospital's servers.

When it appliesHealthcare providers and their suppliers.

ISO/IEC 27001, Annex A

Its controls on secure disposal apply to any equipment containing storage media, with no exemption for equipment that facilities bought rather than IT.

When it appliesOrganisations certified to ISO 27001 or audited against it.

Questions

Frequently Asked Questions

Do these devices really hold sensitive data?

Routinely. Footage, biometric templates, location histories and cached documents are all personal data under the DPDP Act and GDPR, and all of them sit on devices that are usually disposed of informally.

What if the device has no erase function?

Many do not. In that case the storage is removed and processed separately, or the device is destroyed. Which one happened is recorded.

Can you work on devices still installed?

Yes. For fixed installations such as CCTV and access control our engineers work on site, so the units do not have to be shipped anywhere.

Do printers and copiers need this?

Yes, more than most people expect. Office multifunction devices keep an internal drive holding images of everything scanned, copied and printed, often for years.

Tell us what you need

Audit What You Are Missing

We will walk your site and list the devices holding data that nobody has been tracking.

Goes straight to our engineers. No newsletter, no call centre.