A hard drive stores data as magnetic patterns on spinning platters. Deleting a file removes the pointer to it, not the pattern, which is why a formatted drive gives up its contents to any recovery tool in an afternoon.
Overwriting works on this kind of medium, because every addressable sector can actually be written to. That is what we do: overwrite the full drive to the standard your policy names, read it back to confirm, and issue a certificate carrying the drive's serial number.
Where a drive is dead, encrypted beyond reach, or your policy simply demands destruction, we degauss or shred instead — on your site if you prefer — and the certificate says so.
The Risks This Removes
Formatting Is Not Erasure
A quick format rewrites the index and leaves the data untouched. A full format is better but still leaves remapped sectors readable.
Dead Drives Get Ignored
A drive that will not spin up cannot be wiped, so it ends up in a drawer. The data on it is still perfectly readable in a lab.
One Certificate for a Pallet
A single document covering a whole pallet cannot answer a question about one drive on it. An audit only ever asks about one drive on it.
Identify, Erase, Verify, Report, Then Decide
The same five steps every time, in this order. It is the order that makes the last one safe.
- 01
Identify
Make, model, capacity and serial read off the drive itself, not off the label or the asset list.
- 02
Erase
Secure erase or an overwrite to the standard your policy names, applied across every addressable block.
- 03
Verify
The medium is read back and compared with what the wipe claimed to write. A mismatch fails the drive.
- 04
Report
A signed certificate for that drive, with the serial number on it, so it can be matched to the asset later.
- 05
Reuse, Resell or Destroy
The drive can be redeployed, sold or scrapped, and there is a document behind whichever you chose.
Overwrite, Then Prove It
The pass pattern comes from the standard you choose — NIST SP 800-88 Clear, DoD 5220.22-M three or seven pass, or one of twenty-two others. Afterwards the drive is read back and sampled. A drive that does not verify is reported as failed, never quietly passed.

Degaussing and Shredding on Site
For drives that cannot be written to, magnetic degaussing destroys the pattern and the servo tracks with it — the drive is unusable afterwards, which is the point. Shredding reduces the platters to fragments. Both happen in front of you if you want them to.

The Process, Step by Step
Tell Us What You Have
Rough count, drive sizes and whether the drives are still in machines. That is enough to price the work and decide whether it happens on your floor or in our facility.
Collect or Come to You
Drives are logged against their serial numbers at the point they change hands, sealed if they are travelling, and signed for at every handover.
Identify Every Drive
Make, model, capacity and serial are read from the drive itself. A drive that reports nothing is set aside for destruction rather than guessed at.
Erase to Your Standard
The overwrite or secure-erase command your policy names is issued across every addressable block, with several drives running at once.
Read It Back
Verification is a separate read of the drive after the erase, compared against what the pass claimed to write. A mismatch fails that drive.
Certify and Hand Over
One signed certificate per drive, plus a single reconciliation list so every serial you handed over is accounted for on paper.
Hard Drives and Interfaces We Process
If your drive is not in this list, it is worth asking — the list names the common cases, not the limits.
Form factors
- 3.5in desktop and server drives
- 2.5in laptop drives
- Slim 7mm and 15mm 2.5in drives
- External and portable USB drives
- Drives still fitted inside a laptop or workstation
Interfaces
- SATA and eSATA
- SAS, single and dual port
- Legacy IDE and PATA
- SCSI on older server hardware
- USB and Thunderbolt enclosures
Special cases
- Self-encrypting drives (SED)
- Drives locked with an ATA password
- Drives with unwritable bad sectors
- Drives that no longer spin up
- Drives pulled from a RAID set
Which Method Applies
| Situation | What We Do |
|---|---|
| Drive is healthy and being resold or redeployed | Overwrite to your chosen standard, verify, certify |
| Drive is healthy but policy forbids reuse | Overwrite, then degauss or shred, certify both |
| Drive will not spin up or is not detected | Degauss and shred — erasure cannot be verified on it |
| Self-encrypting drive (SED) | Cryptographic erase, verified, then overwrite if required |
| Drive has bad sectors that cannot be written | Flagged on the report and physically destroyed |
What the Work Actually Gives You
Sector-Level Overwrite
Every block the drive will report is written, not just the space the file system says is free. Free-space wiping leaves the rest of the drive alone, which is why we do not use it for disposal.
Verification as a Second Read
The drive is read back after the erase and compared. This is a different thing from trusting the return code the drive gave when it said it had finished.
Parallel Processing
Several drives run at once per machine, each tracked as its own job, so one drive failing never hides inside a batch that otherwise finished.
Degaussing and Shredding
For drives that cannot be written to at all. Degaussing destroys the magnetic servo tracks — the drive is unusable afterwards, which is the point of it.
Serial-Level Reconciliation
The list you handed over and the list of certificates you receive are the same list of serial numbers, checked against each other before handover.
On-Site or in Facility
The same process either way. On site nothing leaves the building; in facility the drives travel under seal and are logged on arrival.
What You Hold When the Job Is Done
Not a letter covering a consignment. One document per drive, plus the record that ties the whole batch back to the assets you handed over — which is what an auditor asking about a single serial number actually needs.
- Make, model, capacity and serial number of the drive
- The sanitization method applied, named, with its pass count
- Whether verification passed, failed or could not be attempted
- Start and finish time, and the operator who ran it
- Your own asset reference where you supplied one
- A chain-of-custody entry for every handover the drive went through
- A digital signature, so an edited certificate no longer validates
- 25 methodsErasure Standards Built In
NIST SP 800-88 Clear and Purge, IEEE 2883, DoD 5220.22-M, BSI, DPDP and twenty more. The software issues what the medium actually supports.
- 8 at onceDrives Erased in Parallel
The Concurrent Sanitization Limit takes 1, 2, 4 or 8 drives per machine and ships on 4. Each drive is tracked as its own job, so one failure never hides behind the others finishing.
- 100%Of Erased Drives Read Back
Every sector the wipe claims to have written is read back and compared. A mismatch fails the drive rather than quietly passing it.
- 1 per driveCertificate, Serial Number and All
Model, capacity, serial, method, start and finish time, operator and result, on its own document, per drive.
The Standards a Hard Drive Erase Is Run Against
These are the published procedures the work follows. They are not certifications held by this company, and the page does not present them as any.
NIST SP 800-88 Rev. 2
The United States guideline that splits sanitization into Clear, Purge and Destroy, and picks between them by what the media is and where it is going. Clear is a single verified overwrite; Purge is the stronger treatment for media leaving your control.
When it appliesThe default reference for most organisations, and the one most auditors will ask about by name.
DoD 5220.22-M
A three-pass or seven-pass overwrite pattern from the old US defence industrial manual. It is still widely named in internal policies, so it is supported — but on a modern hard drive it takes several times longer than a single verified pass and does not make the data any less recoverable.
When it appliesWhere your own policy or your customer's contract names it specifically.
IEEE 2883-2022
A newer sanitization standard that defines Clear, Purge and Destruct for both magnetic and flash media, and is stricter than NIST about proving the result rather than assuming it.
When it appliesWhere a policy has been written recently, or where mixed magnetic and flash media are handled under one rule.
DPDP Act, 2023 (India)
India's data protection law. It requires personal data to be erased once the purpose it was collected for has ended, and expects you to be able to show that it was.
When it appliesAny organisation processing personal data of people in India, whatever sector it operates in.
GDPR, Article 17
The right to erasure. It obliges you to delete personal data on request and to demonstrate that you did — which for a retired drive means a record naming that drive, not a statement of policy.
When it appliesAny organisation holding personal data of people in the EU or UK, wherever the hardware physically sits.
ISO/IEC 27001, Annex A
The information security management standard. Its controls on media handling and secure disposal expect a documented, repeatable process — the document, not the intention.
When it appliesOrganisations certified to ISO 27001, or being audited against it by a customer.
Where People Go from Here
Solid State Drive Sanitization
The same job on flash, where overwriting is the wrong tool and the drive has to be commanded instead.
Read moreOn-Site Sanitization
The version of this work where the drives never leave your building at all.
Read moreCertificate of Destruction
What is on the document you receive, and why a per-asset certificate is the only kind that answers an audit.
Read moreFrequently Asked Questions
How many passes do I actually need?
On a modern hard drive, one verified pass renders the data unrecoverable — that is NIST SP 800-88's position. Multi-pass patterns like DoD 5220.22-M exist because some policies still name them, so we support them, but they take longer and add nothing on current media.
Can data be recovered after degaussing?
No. Degaussing destroys the magnetic servo tracks the drive uses to find its own data, so it is not just erased but unusable. That is also why a degaussed drive cannot be resold.
Do you shred on our premises?
Yes. Our mobile unit works on your site, under your supervision, and nothing leaves the building. You receive a certificate per drive and, if you want it, a video record.
What about drives still inside laptops and servers?
We can erase in place by booting the machine from USB or PXE, or extract the drives and process them in a bay. Whichever is faster for the volume you have.
Send Us One Drive First
We will process it, send you the certificate, and you can decide about the other four hundred.

