CertifiedNIST SP 800-88 Rev. 2 · DoD 5220.22-M · IEEE 2883

  • Home
  • Services
  • On-Site Data Erasure & Data Sanitization Services

On-Site Data Erasure & Data Sanitization Services

Secure Data Erasure, Data Wiping & Media Destruction at Your Location

Keep data-bearing devices under your control until the required data erasure, sanitization or destruction process is completed.

When computers, servers, storage devices and other IT assets are retired, the physical movement of unprocessed media can create another point of exposure.

Our on-site data erasure and data sanitization services are designed for organizations that want to securely process data-bearing assets at their own facility before reuse, resale, recycling, return or retirement.

We support controlled workflows for hard drives, SSDs, NVMe drives, laptops, desktops, servers, storage media and other supported devices.

Depending on the asset and project requirement, the process can include:

  1. Data Erasure
  2. Verification
  3. Certification

or

  1. Physical Destruction
  2. Verification
  3. Certificate of Destruction

The objective is simple:

Keep control of the asset. Secure the data. Document the result.

  • On-Site Data Erasure
  • Secure Data Wiping
  • Data Sanitization
  • Media Destruction

Book an On-Site Service | Request a Quote

On-Site Data Erasure & Data Sanitization Services

Why On-Site Data Erasure Matters

Your Data Does Not Have to Leave Your Facility First

Many organizations retire devices long before the storage inside them is processed.

A server can remain powered down in a data center.A laptop can wait in an asset room.A hard drive can sit in a storage cage.An SSD can be prepared for recycling.

The important question is:

Has the data actually been sanitized before the asset leaves your control?

With on-site data sanitization, supported data-bearing media can be processed at your location.

This reduces the need to transport unprocessed storage and helps organizations maintain stronger physical control during the sanitization stage.

Reduce Unnecessary Data Movement

On-site data wiping services can be especially useful during:

  • IT asset retirement
  • Hardware refresh
  • Server decommissioning
  • Data center relocation
  • Storage replacement
  • Office relocation
  • ITAD projects
  • Refurbishment
  • Resale preparation
  • Secure recycling

Maintain Better Visibility

On-site processing allows your IT, security, compliance or asset-management team to remain involved in the process.

Where the project requires it, processing can be observed or witnessed according to the site's procedures.

What Is On-Site Data Sanitization?

On-site data sanitization is the controlled process of securely removing information from data-bearing media at the organization's own facility.

The exact sanitization method depends on:

  • Media type
  • Storage technology
  • Device condition
  • Information sensitivity
  • Organizational policy
  • Intended disposition

A professional workflow can involve:

  1. Identify
  2. Select Method
  3. Erase
  4. Verify
  5. Certify

For media that cannot be reliably sanitized through the required process, physical destruction may be selected where appropriate.

This distinction is important:

Data Erasure: Removes stored information while retaining the physical media.

Physical Destruction: Makes the physical media unusable or destroys the storage medium.

Both can form part of a broader media sanitization and disposal program.

On-Site Data Erasure Services

Our on-site data erasure services can support different types of storage and IT assets.

On-Site Hard Drive Data Erasure

Securely process supported HDDs using an appropriate hard drive data erasure or data wiping method.

Suitable for:

  • SATA HDDs
  • Enterprise HDDs
  • Desktop hard drives
  • Laptop hard drives
  • Server HDDs
  • Removable hard drives

On-Site SSD Data Erasure

Supported SSDs can be processed according to the storage technology and available sanitization capabilities.

This can include SSDs used in:

  • Laptops
  • Desktops
  • Workstations
  • Servers
  • Enterprise storage

On-Site NVMe Data Erasure

For supported NVMe media, the sanitization approach should consider the device's actual capabilities, firmware and connection environment.

On-Site Laptop & Desktop Data Wiping

Devices can be processed at the location where they are installed or stored.

For suitable systems, boot-based workflows can be used when the active operating system should not be relied upon to erase its own system drive.

On-Site Server Data Erasure

Process supported server storage during:

  • Server retirement
  • Data center decommissioning
  • Hardware upgrades
  • Storage replacement
  • Infrastructure refresh

On-Site Removable Media Erasure

Supported removable storage can include:

  • USB flash drives
  • SD cards
  • Memory cards
  • CF cards
  • Other supported removable media

On-Site Data Destruction Services

Software-based erasure is not suitable for every storage device.

A damaged, inaccessible, failed or technically unsuitable drive may require physical destruction according to the organization's policy and required disposition method.

Where applicable, on-site data destruction services can include physical destruction of supported media such as:

  • Hard drives
  • SSDs
  • Flash storage
  • Tapes
  • Optical media
  • Other approved storage media

Potential service terminology includes:

On-Site Hard Drive Destruction

On-Site HDD Shredding

On-Site SSD Destruction

On-Site Media Destruction

Secure Media Destruction

The appropriate destruction technique depends on the physical media, project scope and required outcome.

A destruction certificate should not be confused with a software-generated erasure certificate.

On-Site Data Destruction Services

Our On-Site Data Sanitization Process

  1. 01

    Site Preparation

    Before the project begins, the required assets, access conditions, processing area and project requirements are established.

    For enterprise projects, the asset manifest can be used to define the scope.

  2. 02

    Asset Identification

    Each supported device or storage medium is identified.

    Relevant information can include:

    • Manufacturer
    • Model
    • Serial Number
    • Capacity
    • Interface
    • Asset ID

    This helps establish an asset-level record.

  3. 03

    Select the Sanitization Method

    The sanitization method is selected based on the storage technology, information sensitivity organizational policy and intended outcome.

  4. 04

    Perform Data Erasure

    The selected secure data erasure process is performed on supported media.

    For suitable systems, USB or PXE-based boot workflows can support system-drive sanitization outside the active operating system.

  5. 05

    Verify the Result

    The completed operation is verified through the applicable verification process.

  6. 06

    Physical Destruction Where Required

    If the media cannot be reliably sanitized or physical destruction is required by policy, an appropriate destruction process can be used where included in the service scope.

  7. 07

    Documentation & Certification

    The result is documented and associated with the relevant asset.

    This creates a traceable relationship:

    1. Asset
    2. Sanitization/Destruction
    3. Verification
    4. Certificate

On-Site Hard Drive, SSD & NVMe Sanitization

Different storage technologies require different considerations.

HDD

Hard disk drives use magnetic recording media and can be processed through appropriate supported logical erasure methods.

SSD

Solid-state drives use flash storage and may implement controllers, wear-leveling and other internal mechanisms that make media-specific sanitization important.

NVMe

NVMe devices use a different protocol and expose device capabilities through the NVMe interface.

For these reasons, secure data erasure should be selected according to the actual media rather than using one method for every device.

NIST SP 800-88 Rev. 2 similarly emphasizes selecting appropriate sanitization techniques and controls based on media and information sensitivity.

On-Site Data Erasure for Data Centers

Data centers often contain large volumes of data-bearing equipment.

Our on-site data center data erasure services can support projects involving:

  • Server HDDs
  • Server SSDs
  • NVMe drives
  • Storage systems
  • Enterprise storage media
  • Retired servers
  • Decommissioned infrastructure

Typical workflow:

  1. Decommission
  2. Identify
  3. Erase
  4. Verify
  5. Certify
  6. Release

For large projects, asset-level processing can help your team reconcile the final sanitization status against the original equipment inventory.

On-Site Data Erasure for Data Centers

On-Site Server Decommissioning & Data Destruction

Server retirement involves more than disconnecting equipment.

Storage may remain inside:

  • Rack servers
  • Tower servers
  • Blade servers
  • Storage servers
  • Database servers
  • Virtualization hosts
  • Backup systems

A structured server data erasure service can address the storage media before equipment is reused, resold, recycled or retired.

Where software-based sanitization cannot produce the required result, physical destruction may be considered according to project policy.

On-Site Server Decommissioning & Data Destruction

On-Site ITAD Data Erasure

IT Asset Disposition (ITAD) projects frequently involve large quantities of data-bearing assets.

These may include:

  • Laptops
  • Desktops
  • Workstations
  • Servers
  • HDDs
  • SSDs
  • NVMe drives
  • Mobile devices
  • Removable storage

On-site processing can provide a workflow such as:

  1. Asset Intake
  2. Identification
  3. Data Erasure
  4. Verification
  5. Certification
  6. Disposition

This can help ITAD providers, recyclers, refurbishers and enterprise asset teams maintain better control over unprocessed storage.

On-Site Data Erasure for Reuse, Resale & Recycling

Reuse

Sanitize previous data before a device is assigned to another user or department.

Redeployment

Erase stored information before moving equipment between offices, branches, facilities or regions.

Refurbishment

Sanitize data before used equipment enters a refurbishment workflow.

Resale

Complete the required data erasure and retain the resulting certificate before the asset changes ownership.

Return

Sanitize leased or returned equipment before it leaves organizational control.

Recycling

Process the data-bearing media before it enters downstream recycling or recovery.

Retirement

Complete the approved sanitization or destruction process and retain the relevant documentation.

Witnessed On-Site Data Erasure & Destruction

Some organizations require their representatives to observe the sanitization process.

On-site service can support controlled observation according to site procedures and project scope.

Where physical destruction is included, the organization may also arrange for destruction to be witnessed and documented.

This can be useful for:

  • Security teams
  • Compliance teams
  • Internal auditors
  • Government organizations
  • Financial institutions
  • Healthcare organizations
  • Enterprise asset managers
  • ITAD customers

The documentation should identify the assets and the actual process performed.

Data Erasure Verification & Certificates

A completion message is not the same as a useful audit record.

A professional data erasure certificate should be connected to the specific asset and sanitization process.

Relevant information may include:

  • Manufacturer
  • Model
  • Serial number
  • Capacity
  • Interface
  • Asset ID
  • Erasure method
  • Processing status
  • Verification result
  • Processing date
  • Operator information
  • Project reference

This creates an evidence chain:

  1. Physical Asset
  2. Processing Record
  3. Verification Result
  4. Certificate

For physical destruction:

  1. Physical Asset
  2. Destruction Record
  3. Verification/Witness Record
  4. Certificate of Destruction
Data Erasure Verification & Certificates

Secure Offline Data Erasure

Some organizations operate in environments where internet connectivity is restricted or prohibited.

Supported offline data sanitization workflows can be useful for:

  • Air-gapped environments
  • Secure data centers
  • Government facilities
  • Restricted processing areas
  • Enterprise security zones
  • Sensitive asset rooms

The exact deployment depends on the technical environment and service requirements.

Secure Offline Data Erasure

Global On-Site Data Sanitization

Organizations managing IT assets across different countries often need a consistent sanitization process that can be incorporated into their global asset lifecycle.

A globally oriented on-site data erasure program can support:

  • Multi-site hardware refresh
  • International ITAD
  • Global data center projects
  • Regional asset retirement
  • Cross-border equipment replacement
  • Corporate device redeployment
  • International refurbishment programs

The underlying policy should remain consistent while local legal, contractual, access, privacy and disposal requirements are handled for each location.

Where personal information is involved, requirements vary by jurisdiction. For example, the GDPR includes storage-limitation and security principles and provides a right to erasure in specified circumstances.

On-site sanitization can support an organization's controls, but it does not by itself establish legal compliance with every jurisdiction.

Data Sanitization Standards & Compliance

NIST SP 800-88 Rev. 2

The current NIST media-sanitization publication is SP 800-88 Rev. 2, finalized September 26, 2025.

It describes media sanitization as a process intended to render access to target data infeasible for a given level of effort and focuses on appropriate sanitization techniques and controls based on information sensitivity and media characteristics.

ISO/IEC 27001

ISO/IEC 27001 is an international standard for information security management systems. Organizations may incorporate asset handling, disposal and information-protection controls into their ISMS.

PCI DSS

For organizations subject to PCI DSS, electronic media containing cardholder data must be destroyed or have the data rendered unrecoverable when the media is no longer needed, subject to the applicable requirements.

GDPR

GDPR includes principles relating to storage limitation, security and erasure of personal data in specified circumstances.

Standards vs Methods

These should not be mixed together:

Standard / Guideline

Defines requirements, guidance or a framework.

Sanitization Method

Performs the technical data-erasure operation.

Verification

Checks or documents the result.

Certificate

Records the completed operation for the specific asset.

When Software-Based Erasure Is Not Enough

Not every storage device can be successfully sanitized through software.

Further assessment may be required if a device:

  • Is not detected
  • Has severe read/write failures
  • Has controller problems
  • Has firmware limitations
  • Is physically damaged
  • Cannot complete the selected process
  • Cannot provide the required verification result
  • Uses an unsupported connection path

A failed operation should never be reported as a successful data erasure.

Where the required sanitization cannot be achieved, the organization can evaluate another approved disposition method, including physical destruction where appropriate.

When Software-Based Erasure Is Not Enough

Why Choose On-Site Data Sanitization?

Data Stays Under Your Control

Process data-bearing assets at your facility before they leave your custody.

Secure Data Erasure

Use a controlled process for supported storage media.

Verification

Record the result of the completed operation.

Asset-Level Documentation

Connect each processed asset with its sanitization result.

Certificates

Generate documentation for completed erasure or destruction activities.

HDD, SSD & NVMe Support

Address different storage technologies using appropriate workflows.

Data Center Ready

Suitable for server rooms, data centers and infrastructure retirement projects.

ITAD Ready

Support reuse, resale, refurbishment, recycling and retirement workflows.

Offline Capability

Suitable for controlled environments where normal internet access is restricted.

On-Site Destruction

Where included and technically appropriate, physical media destruction can be performed at the customer's location.

Who Uses On-Site Data Erasure Services?

Enterprise IT Departments

For device refresh, redeployment and asset retirement.

Data Centers

For server and storage decommissioning.

ITAD Providers

For secure processing before resale, refurbishment or recycling.

Refurbishers

For sanitizing used devices before entering the next lifecycle.

Government Organizations

For controlled handling of sensitive data-bearing equipment.

Financial Institutions

For secure retirement of storage containing business and customer information.

Healthcare Organizations

For controlled disposal and reuse of data-bearing IT assets.

MSPs & Managed Service Providers

For secure device retirement across customer environments.

Hardware Resellers

For data sanitization before second-hand equipment changes ownership.

Frequently Asked Questions

What is an on-site data erasure service?

An on-site data erasure service securely processes data-bearing devices at the customer's location rather than requiring unprocessed storage to be transported elsewhere first.

What is the difference between on-site data erasure and on-site data destruction?

Data erasure removes the stored information while preserving the physical device when suitable.

Physical data destruction destroys the storage medium.

The appropriate approach depends on the media, device condition, information sensitivity and disposal policy.

Can you erase hard drives on site?

Supported HDDs can be processed on site using an appropriate secure data-erasure workflow.

Can SSD and NVMe drives be erased on site?

Supported SSD and NVMe devices can be processed according to their storage technology and available sanitization capabilities.

Can laptops be erased at our office?

Yes, supported laptops can be processed at the customer location. Suitable boot-based workflows can be used where system-drive sanitization requires an external environment.

Can servers be sanitized inside a data center?

Yes. On-site data erasure can be used for supported server and storage media during decommissioning and infrastructure replacement.

Can data erasure be performed without internet access?

Supported offline sanitization workflows can be used in restricted or isolated environments.

Can our team witness the process?

On-site processing can allow authorized customer representatives to observe the work according to the site's procedures.

Do you provide data erasure certificates?

Yes. Completed sanitization activities can be documented with asset-level processing and verification information.

What happens when a hard drive cannot be erased?

A failed or inaccessible storage device should not be certified as successfully erased. The organization can evaluate another approved disposition method, including physical destruction where appropriate.

Is on-site data erasure suitable for ITAD?

Yes. On-site processing can be particularly useful for ITAD, refurbishment, recycling, resale and large enterprise asset-retirement projects.

Is on-site data sanitization automatically NIST compliant?

No. On-site is a service-delivery model, while NIST SP 800-88 Rev. 2 provides media-sanitization guidance. The applicable sanitization method and controls must be selected according to the media, information sensitivity and organizational program.

Do you provide worldwide on-site data erasure?

On-site requirements depend on the project location, scope, equipment, access conditions and service coverage. International organizations can use the same structured sanitization model across locations, with local requirements incorporated into the project.

Tell us what you need

Keep Your Data On-Site Until It Is Securely Erased

With professional on-site data erasure and data sanitization, supported assets can be processed, verified and documented at your facility.

Goes straight to our engineers. No newsletter, no call centre.