SANITIZE

CertifiedNIST SP 800-88 Rev. 2 · DoD 5220.22-M · IEEE 2883

Certified Data Erasure by Sector

The same platform, configured for the way each regulated industry actually retires hardware — and for the evidence each of their auditors asks for.

The erase is the same everywhere. What differs by sector is everything around it: who is allowed to touch the asset, whether it may leave the building, how long the record has to be kept, and which regulator will eventually ask to see it.

These pages exist because those differences change the process rather than the paperwork. A hospital cannot hand a machine to a courier the way an office can; a bank's retention rules outlive the hardware; a data centre decommission is measured in racks and cannot stop the aisle beside it.

What Goes Wrong

The Risks This Removes

A Policy Written for Paper

Most retention and disposal policies predate the storage they now govern. They say records must be destroyed and are silent on what destruction means for a self-encrypting drive, which leaves the person doing the work to invent a standard.

The Auditor Asks a Different Question

Every sector's auditor asks the same thing in their own words — show me this asset. A process that produces batch summaries answers none of them.

Scale Changes the Method

What works for twenty laptops does not work for two thousand. Beyond a certain count the job stops being about erasing and starts being about tracking, and a process that has not planned for that loses assets.

Which Sector Page Applies

  • Enterprise IT — endpoint and server retirement with an audit trail that survives the asset
  • ITAD and recyclers — high volume, per-unit evidence, and resale grading in the same pass
  • Data centres — rack and array decommissioning without stopping the floor
  • Government and defence — the stricter standards, and destruction where erasure is not accepted
  • Banking and finance — retention rules that outlast the hardware, and regulator-ready records
  • Healthcare — patient data on equipment that cannot always leave the site
  • Education — mixed estates, shared devices and constrained budgets
  • Managed service providers — doing this on behalf of clients who will be audited themselves
Questions

Frequently Asked Questions

Is the software different per sector?

No, and that is deliberate. The platform is one product; what changes is the standard chosen, the verification depth and how the records are retained. A sector-specific build would mean sector-specific bugs.

We are regulated by more than one body. Which standard do we use?

The strictest of them, which is usually the simplest answer to defend. The software records which standard was applied, so meeting the highest bar satisfies the others without running the job twice.

Can we do this ourselves rather than as a service?

Yes — most sector pages describe both. Organisations that retire hardware continuously usually license the software and run it in-house; those with occasional bulk decommissions usually prefer the service.

Tell us what you need

Which of These Is You?

Tell us the sector and the rough volume and we will point you at the right page — or answer directly.

Goes straight to our engineers. No newsletter, no call centre.