SANITIZE

CertifiedNIST SP 800-88 Rev. 2 · DoD 5220.22-M · IEEE 2883

Data Erasure for Data Centres

Decommission racks and arrays without downtime, and without a shredder.

Decommissioning a rack is not the same problem as wiping a laptop. The drives are SAS or NVMe, many are self-encrypting, some are still in a live array, and the window in which you are allowed to touch any of it is short.

Data Sanitization Pro handles enterprise media natively. Self-encrypting drives get a cryptographic erase rather than a pointless overwrite. NVMe drives get the format or sanitize command the specification actually defines. Loose drives run eight at a time per bench while the rack itself is still being unpicked.

Every drive produces its own certificate. When the pallet leaves your floor, you can say precisely which serial numbers were on it and what happened to each one.

What Goes Wrong

The Risks This Removes

Shredding Everything by Default

Destroying a working enterprise SSD costs the price of the drive and the carbon that made it. Most of them do not need to be destroyed, only proved clean.

Overwriting Self-Encrypting Drives

Writing zeroes over an SED wastes hours and proves nothing. The correct operation is to destroy the key, which takes seconds and is verifiable.

No Chain of Custody off the Floor

Drives pulled into a crate and wheeled out are untracked from that moment. If one goes missing, nobody can say which one.

One Method Applied to Every Medium

A three-pass overwrite is the right answer for a SATA platter and the wrong answer for everything else in the rack. Applied to an NVMe drive it takes hours and still misses the over-provisioned blocks.

Evidence Written After the Fact

A spreadsheet filled in at the end of the day is a recollection, not a record. It cannot be reconciled against the drives, and it is the first thing an auditor discounts.

The Shape Of The Work

Identify, Erase, Verify, Report, Then Decide

Run against every drive that comes off the floor, in this order, so the pallet leaving the building is a pallet you can account for line by line.

  1. 01

    Identify

    Serial, model, interface and whether the drive is self-encrypting. That last one decides everything that follows.

  2. 02

    Erase

    Cryptographic erase for an SED, sanitize for SAS and NVMe, secure erase or overwrite for SATA. The medium chooses, not a default.

  3. 03

    Verify

    The medium is read back afterwards. A drive that cannot be read cannot be verifiably erased, and it is flagged rather than passed.

  4. 04

    Report

    A certificate per drive and a reconciliation list for the rack: every serial pulled, with a status against it.

  5. 05

    Redeploy, Resell or Destroy

    Most working enterprise drives never needed a shredder. They needed proof, and now they have it.

The Right Command for Each Medium

SATA drives take a secure erase or an overwrite. SAS drives take a sanitize. NVMe takes format or sanitize as the specification defines it. Self-encrypting drives take a cryptographic erase. The software identifies the medium and issues what that medium actually supports, then verifies the result.

Close-up of mixed drive types — SAS, NVMe M.2 and 2.5in SSD side by side on a bench

Every Serial Accounted For

Drives are logged as they come out of the rack and reconciled against the certificates produced. The output is a list of serial numbers with a status against each one, which is the document a data centre audit actually asks for.

Reconciliation report — serial number list with erased, failed and pending statuses

Built for the Window You Are Given

Decommissioning is scheduled work with a hard end. Drives run up to eight at a time per bench, so throughput is a question of how many benches you put on the job rather than how long one queue takes. The software runs from bootable media on a machine you already have, which means a second bench is a second USB stick and not a procurement cycle.

Two erasure benches running side by side in a data centre staging area

What Each Medium Actually Takes

The MediumThe Operation, And Why It Is That One
SATA HDDSecure erase, or an overwrite to the standard your policy names. A platter holds data where it was written, so an overwrite genuinely displaces it.
SAS HDD or SSDThe SANITIZE command the SCSI specification defines, issued to the drive itself rather than written across it from outside.
NVMe SSDFormat NVM or Sanitize, as the NVMe specification defines them. The controller reaches the over-provisioned blocks that a host-side overwrite never addresses.
Self-encrypting driveCryptographic erase. The key is destroyed, which renders every block on the drive unreadable in seconds. This is what NIST SP 800-88 calls Purge for this medium.
Presented LUN or volumeVolume-level erasure against the LUN while the array stays in service, so retiring one volume does not take its neighbours offline.
Drive that will not readNothing. A medium that cannot be read cannot be verifiably erased, so it is listed as an exception and routed to physical destruction.

What You Hold When the Pallet Leaves

  • A certificate per drive, carrying make, model, capacity and serial number
  • The method applied to that drive, and why that method was the correct one for it
  • Start time, finish time and the operator who ran the job
  • The verification result — read back and compared, not the drive's own return code
  • A reconciliation list for the rack: every serial pulled, with a status against it
  • The exceptions named separately, with the reason each one could not be erased
  • A SHA-256 signature on every document, so a later edit to one does not go unnoticed
  • Files you keep on your own storage, with no expiry and no dependency on us
  • 25 methodsErasure Standards Built In

    NIST SP 800-88 Clear and Purge, IEEE 2883, DoD 5220.22-M, BSI, DPDP and twenty more. The software issues what the medium actually supports.

  • SEDKey Destroyed, Not Overwritten

    A self-encrypting drive is purged by destroying its key. That takes seconds and is verifiable. Writing zeroes over the ciphertext takes hours and proves nothing.

  • LUNErased with the Array in Service

    Volume-level erasure runs against the presented LUN, so retiring one volume does not mean a maintenance window for everything sharing the hardware.

  • 100%Of Serials Reconciled off the Floor

    Every drive pulled from a rack is matched to a certificate or listed as an exception. Nothing leaves the building unaccounted for.

Questions

Frequently Asked Questions

Can you erase a LUN without taking the array offline?

Yes. Volume-level erasure runs against the presented LUN while the array stays in service, so decommissioning a volume does not mean a maintenance window for everything else on the same hardware.

How are self-encrypting drives handled?

By destroying the encryption key rather than overwriting the ciphertext. This is the method NIST SP 800-88 defines as Purge for SEDs, it takes seconds instead of hours, and the result is verified afterwards.

What about drives that have already failed?

A drive that cannot be read cannot be verifiably erased. Those are flagged for physical destruction and listed separately on the report, so the exception is documented rather than hidden.

Do you work on site?

Yes. Our engineers work inside your facility, under your access controls and your cameras, and nothing leaves the building until you have the certificates.

How do you know a drive is self-encrypting?

The drive is interrogated before anything is written to it, and it reports its own security features. That answer decides the method, which is why the identify step comes first rather than being assumed from the model number on the label.

Can this run without a connection out of the building?

Yes, and in most data centres it does. Licence activation is offline and certificates are written to storage you control. Nothing about the drives processed is transmitted anywhere.

Why not just shred everything and be done with it?

Because most of what comes out of a rack is a working enterprise SSD with years left in it, and destroying one costs the price of the drive plus the carbon that made it. Shredding is the right answer for a drive that cannot be verified. For the rest it is an expensive way to avoid producing evidence.

How long does a rack take?

It depends on the media, the capacities and the standard your policy names — a cryptographic erase is seconds, a multi-pass overwrite of a large platter drive is hours. Benches run in parallel, so the useful question is how many you can put on the job. Tell us the media mix and the window, and we will give you the number of days.

Tell us what you need

Plan Your Next Decommission

Tell us the media mix and the window you have, and we will tell you what it takes.

Goes straight to our engineers. No newsletter, no call centre.