The riskiest part of media disposal is not the erasure. It is the gap between a device being decommissioned and it being processed — sitting in a store room, in a van, on a pallet at somebody else's facility.
On-site work removes that gap. Our engineers bring the equipment to your premises, process the media in front of you, and hand you the certificates before the hardware is released. If a drive fails, it is destroyed on your floor rather than travelling somewhere to be dealt with later.
For regulated environments this is often not a preference but a requirement, and it is the only arrangement where your chain of custody never actually starts, because the media never leaves your control.
The Risks This Removes
The Gap Between Decommission and Erasure
A drive pulled on Monday and collected on Friday spent four days in a cupboard that anybody with a pass could open. Nothing in the certificate covers those four days.
Transport Is the Weakest Link
Once media is in a vehicle it is outside your control and inside somebody else's process. Most disposal incidents happen in that window, not in the erasure.
You Are Asked Whether You Watched
An auditor's question is rarely whether the data was destroyed. It is who saw it happen, and what they signed. A vendor's letter cannot answer that on your behalf.
Air-Gapped Sites Included
The software runs entirely offline — licence activation, erasure, verification and certificate generation all work with no route to the internet. Closed networks and secure facilities are handled with the same process as anywhere else.

Destruction on Your Floor
Where a drive cannot be verifiably erased, or your policy demands physical destruction, it is shredded or degaussed on site. The fragments leave; the data never does.

The Process, Step by Step
We Come to You
Equipment, engineers and boot media arrive at your site on an agreed date. No shipping, no staging, no waiting for a collection slot.
Processed in Front of You
Erasure, verification and destruction all happen on your premises. Your staff can witness the whole run, and video can be recorded on request.
Certificates Before Release
You hold a signed certificate for every asset before any hardware is released for recycling or resale.
What We Can Process on Your Premises
The mobile setup handles the same media as the facility does. Physical destruction is the only part with a size limit, and it is a large one.
Erased in place
- Hard drives, in machines or out of them
- SSDs and NVMe, including M.2
- Laptops and desktops booted from USB or PXE
- Servers and storage arrays
- Phones, tablets and handhelds
- USB drives, SD and CF cards
Destroyed on site
- Hard drives, shredded to fragments
- SSDs and flash, shredded to chip size
- Magnetic degaussing where a drive cannot be written
- Optical media and tape
- Boards holding soldered storage
Environments we work in
- Offices and open-plan floors
- Data halls and comms rooms
- Warehouses and staging areas
- Branch and retail premises
- Sites with no network access at all
- Sites requiring escorted access throughout
Which Arrangement Applies
| Your Situation | What We Do |
|---|---|
| Policy says media may not leave the premises | Everything is erased or destroyed on site; nothing holding data goes into a vehicle |
| Assets are being resold and must stay working | Erase and verify in place, certificates issued before we leave |
| Drives are dead or policy demands destruction | Shred or degauss on site, witnessed, with a per-drive record |
| Machines are still deployed and in use | Booted from USB or PXE and erased in place, out of hours if needed |
| Site has no network and no internet | The process runs entirely offline; certificates are generated locally |
| Volume is too large for one visit | Scheduled across visits, with a running reconciliation between them |
What On-Site Actually Changes
Nothing Leaves Holding Data
The whole point. Assets leave afterwards, empty and certified, or they do not leave at all — the risk window closes before the van arrives.
Your People Watch
Your team, your cameras, your witness signature on the record. That is the answer to the question an auditor actually asks.
Certificates Before We Go
The documents are produced on site as the work completes, not emailed a fortnight later when nobody can remember which batch they covered.
Works Fully Offline
No internet, no uplink, no cloud dependency. Air-gapped sites are a normal environment for this, not an exception.
Erase in Place or in a Bay
Machines can be booted and erased where they stand, or drives pulled and run through a bay — whichever is faster for the volume.
Destruction on Your Floor
For drives that cannot be written or that policy will not allow to survive, the shredder comes to you and you watch it happen.
What You Hold Before We Leave
The same per-asset certificates as any other engagement, plus the thing only on-site work can give you: a record that the media never left your control, signed by somebody of yours who was standing there.
- A certificate per asset, by serial number
- The method applied and the verification result
- The date, the site and the room the work was carried out in
- The operator who ran it and your witness who observed it
- A reconciliation of every asset presented against every certificate issued
- Assets that failed verification and were destroyed instead
- A video record of destruction, where you ask for one
- A digital signature, so an edited certificate no longer validates
- 0 itemsLeave the Building Before They Are Erased
The work happens inside your facility, under your access control and your cameras. Nothing is taken away to be dealt with later.
- 100%Of the Work Can Be Witnessed
Your own staff, your auditor or your client can stand at the bench for the whole run. No part of the process needs to happen out of sight.
- 25 methodsErasure Standards Built In
NIST SP 800-88 Clear and Purge, IEEE 2883, DoD 5220.22-M, BSI, DPDP and twenty more. The software issues what the medium actually supports.
- 1 per assetCertificate, Handed Over on the Day
You hold the evidence before the engineers leave, rather than waiting a week for a report to arrive from somewhere else.
Why Policies Ask for On-Site Work
None of these standards names on-site work as such. What they require is control and evidence over the whole handling of media, which is what on-site work makes straightforward.
NIST SP 800-88 Rev. 2
Distinguishes sanitization carried out under the organisation's own control from media released to a third party — and asks for a higher treatment for the second. Working on site keeps you in the first case.
When it appliesAny policy written against NIST, which is most of them.
ISO/IEC 27001, Annex A
Its controls cover secure disposal and the removal of assets from site, and expect both to be authorised and recorded. On-site work collapses two controls into one evidenced event.
When it appliesOrganisations certified to ISO 27001 or audited against it by a customer.
PCI-DSS Requirement 9
Media holding cardholder data must be secured, its movement controlled and authorised, and its destruction documented. The controls on movement are the ones on-site work removes the need for.
When it appliesAny environment that has processed or stored cardholder data.
HIPAA Security Rule
Requires accountability for hardware and media containing protected health information, including a record of movements. Media that never moves is easier to account for.
When it appliesHealthcare providers, and suppliers handling their equipment.
DPDP Act and GDPR
Both hold you responsible for personal data you pass to a processor. Work done on your own premises under your supervision narrows what you are relying on a third party to have done correctly.
When it appliesAny organisation retiring assets that held personal data.
Government and defence policy
Controlled environments frequently prohibit removable media leaving the site at all, and require destruction to be witnessed and evidenced. That is on-site work by definition.
When it appliesWhere your own security policy, not a general standard, sets the rule.
Where People Go from Here
Chain of Custody
What is recorded at each handover, and why the record starts at the point of collection.
Read moreSAN, NAS and Server Sanitization
On-site decommissioning of arrays and racks, with the system live where it has to be.
Read moreGovernment and Defence
Controlled environments, offline operation and evidence-led workflows.
Read moreFrequently Asked Questions
What do you need from us on the day?
A room with power, access for the equipment, and someone to sign the assets in and out. Everything else comes with us.
Can our compliance team watch?
Yes, and most do. We can also record video of the destruction run and supply it with the certificates.
How many drives can you process in a day?
It depends on the media, the capacity and the standard. Drives run in parallel rather than one after another, so throughput is a function of how many bays are on the job. Tell us the volume and we will tell you the number of days.
Do you work outside business hours?
Yes. Data centre and branch work is frequently done overnight or at weekends to fit the window you have.
Book an On-Site Visit
Tell us the site, the volume and the window, and we will confirm what it takes.

