SANITIZE

CertifiedNIST SP 800-88 Rev. 2 · DoD 5220.22-M · IEEE 2883

SAN, NAS and Server Sanitization

Retire the array without taking the rest of the rack down with it.

Enterprise storage does not come apart the way a laptop does. Data is striped across many drives by a controller, some of those drives are still serving live volumes, and the window in which you are permitted to touch any of it is short and usually out of hours.

Pulling drives and wiping them individually works, but only once the array is out of service. Where it is not, the volume itself can be erased while the hardware stays in production — the LUN is cleared, the array carries on, and everything else on it is untouched.

Either way, every physical drive that leaves the rack is accounted for by serial number, with its own certificate.

What Goes Wrong

The Risks This Removes

The Array Is Still in Service

Half the storage is being decommissioned and half is running production. Pulling drives to wipe them is not an option, so the work has to happen with the system live.

Drives Come Out of a Stripe

Data is spread across many disks by a controller. A single drive holds fragments of everything and nothing readable on its own — which tempts people into treating it as already safe. It is not.

The Rack Empties Faster Than the Paperwork

Decommissioning moves quickly, and drives leave in trays. Without a serial-level record taken at the rack, reconciling what left against what was destroyed becomes guesswork weeks later.

The Shape Of The Work

Identify, Erase, Verify, Report, Then Decide

Run per drive and per volume, so a rack coming apart still produces a list somebody can reconcile.

  1. 01

    Identify

    Interface, capacity, serial and whether the drive is self-encrypting. That last answer changes the method entirely.

  2. 02

    Erase

    Cryptographic erase, sanitize, secure erase or a volume-level wipe against the presented LUN, chosen by what the medium is.

  3. 03

    Verify

    Read back and checked. A drive that will not read is flagged for destruction rather than passed on a technicality.

  4. 04

    Report

    A certificate per drive and a reconciliation list for the shelf, with a status against every serial.

  5. 05

    Redeploy, Resell or Destroy

    Whatever happens to the hardware next, the evidence was produced before it left the room.

Volume Erasure Without a Maintenance Window

A LUN presented from a live array can be erased in place while the array stays in service. Decommissioning one volume stops meaning an outage for everything sharing the same hardware, which is usually what makes these projects slip.

Storage console showing a LUN being erased while other volumes stay online

Every Serial Reconciled

Drives are logged as they come out of the chassis and matched against the certificates produced. What you get at the end is a list of serial numbers with a status beside each one — erased, failed, destroyed — which is the document a storage audit actually asks for.

Reconciliation sheet matching drive serials to erasure outcomes
How It Runs

The Process, Step by Step

01

Map the Estate

Which arrays, which shelves, which drives, and which of them are still carrying production. Nothing is unplugged before that is written down.

02

Decide In-Place or In-Tray

A volume can be erased while the array stays powered, or drives can be pulled and processed in a bay. Downtime and volume decide which.

03

Log Every Serial at the Rack

Serials are read where the drives are, not after they have been moved. That is the record everything else reconciles against.

04

Erase to Your Standard

Overwrite on magnetic drives, the drive's own sanitize command on SSDs, with several running in parallel.

05

Read It Back

Every drive is verified separately after the erase. A drive that fails is reported as failed and destroyed rather than shipped.

06

Certify and Reconcile

One certificate per drive, plus a reconciliation of every serial that came out of the rack against every document issued.

What We Handle

Enterprise Storage We Process

The controller and the drive type decide the method, not the badge on the front of the rack.

Systems

  • SAN arrays and disk shelves
  • NAS appliances, desktop to rack scale
  • Rack and blade servers
  • Hyper-converged nodes
  • JBOD and expansion enclosures
  • Tape libraries and their cache drives

Drives and interfaces

  • SAS and nearline SAS, single and dual port
  • Enterprise SATA
  • NVMe and U.2 / U.3
  • Self-encrypting drives (SED)
  • FIPS-validated drives
  • Cache and boot modules, including M.2

Configurations

  • Drives pulled from a RAID set
  • Logical volumes and LUNs erased in place
  • Encrypted volumes and pools
  • Hot spares that were never in service
  • Failed drives already swapped out
  • Controller and cache batteries with retained data

What We Handle

HardwareApproach
Live SAN with volumes to retireLUN-level erasure in place, array stays in service
Decommissioned array or shelfDrives pulled and processed on a bench, eight at a time
NAS appliancesErased in place from boot media, or drives extracted
Rack servers with internal drivesBooted from USB or PXE and erased without disassembly
Self-encrypting enterprise drivesCryptographic erase, verified, seconds rather than hours
Failed or unreadable drivesSeparated and physically destroyed, recorded as such
Capabilities

What the Work Gives You

Erase Without a Maintenance Window

Where the array supports it, a volume is erased while the system stays in service, so a decommission does not have to wait for a shutdown slot.

RAID-Aware Handling

A drive out of a stripe is treated as holding data, because it does. Every physical disk is processed and certified on its own terms.

The Right Command per Drive

A mixed shelf gets mixed treatment: overwrite on magnetic media, the drive's own sanitize on flash, cryptographic erase on a self-encrypting drive.

Serial-Level Reconciliation

The list read at the rack and the list of certificates are checked against each other. A drive that is on one and not the other is found now, not at audit.

Parallel Throughput

Multiple drives per machine, each tracked as its own job, so a shelf is not processed one disk at a time.

Witnessed On Site

The whole process can run in your data hall, under your cameras, with nothing leaving the floor.

What You Receive

What You Hold When the Rack Is Empty

Two documents that refer to the same list of serial numbers: a certificate for each drive, and the reconciliation that proves none of them went missing between the rack and the report.

  • Make, model, capacity and serial number of every physical drive
  • The enclosure, shelf and slot the drive came out of
  • The sanitization method applied, and whether the drive was self-encrypting
  • The verification read and its result, per drive
  • Drives that failed verification, and the destruction that followed
  • Where a volume was erased in place, the volume or LUN identifier
  • A reconciliation of every serial removed against every certificate issued
  • A digital signature, so an edited certificate no longer validates
  • LUNErased with the Array in Service

    Volume-level erasure runs against the presented LUN, so retiring one volume does not take everything else on the same hardware offline.

  • 25 methodsErasure Standards Built In

    NIST SP 800-88 Clear and Purge, IEEE 2883, DoD 5220.22-M, BSI, DPDP and twenty more. The software issues what the medium actually supports.

  • SEDKey Destroyed, Not Overwritten

    Enterprise SSDs are usually self-encrypting. Destroying the key is the method NIST SP 800-88 defines as Purge for that medium, and it takes seconds.

  • 100%Of Serials Reconciled off the Floor

    Drives are logged as they leave the rack and matched against the certificates produced. The output is a serial list with a status against every line.

Standards & Compliance

The Standards Behind an Enterprise Erase

These are the published procedures the work follows. They are not certifications held by this company.

NIST SP 800-88 Rev. 2

Chooses between Clear, Purge and Destroy by media type and by where the asset is going. In a mixed shelf that means different drives legitimately get different treatment, and the report has to say which got what.

When it appliesThe default reference for data centre decommissioning.

IEEE 2883-2022

Covers magnetic and flash media in one standard, which is what a modern array actually contains, and is stricter about proving the result.

When it appliesMixed estates, and policies written in the last few years.

ISO/IEC 27001, Annex A

Its controls on secure disposal and on the removal of assets from site expect a documented chain from the rack to the certificate — the reconciliation, not just the wipe.

When it appliesOrganisations certified to ISO 27001, and most enterprise customers auditing a supplier.

PCI-DSS Requirement 9

Media holding cardholder data must be destroyed or rendered unrecoverable when it is no longer needed, with the disposal itself documented and controlled.

When it appliesAny array that has held cardholder data, including one that only cached it.

DPDP Act and GDPR

Both require personal data to be erased once its purpose ends, and both expect evidence. Neither names a technical method, which is why the method chosen has to be defensible on its own.

When it appliesAny estate holding personal data of people in India, the EU or the UK.

DoD 5220.22-M

A multi-pass overwrite pattern still named in many internal policies. Supported where a policy requires it, though on a modern drive one verified pass achieves the same result in a fraction of the time.

When it appliesWhere your own policy or a customer contract specifies it in writing.

Questions

Frequently Asked Questions

Can you work inside our data centre?

Yes. Our engineers work on your floor, under your access control and your cameras, and no media leaves the building until you hold the certificates.

How do you handle RAID sets?

Data is striped, so erasing one member proves nothing about the set. We erase every member drive and reconcile the serials against the array configuration, so the whole set is accounted for.

Do we have to take the array offline?

Not for volume-level erasure. If the whole array is being retired then it comes out of service anyway, and drives are processed in bulk.

What about drives under warranty that must go back?

Cryptographic erase or a verified sanitize leaves the drive functional and returnable. You keep the certificate; the vendor gets a working drive with nothing on it.

Tell us what you need

Plan a Decommission

Tell us the media mix and the window you have, and we will tell you what it takes to fit inside it.

Goes straight to our engineers. No newsletter, no call centre.