SANITIZE

CertifiedNIST SP 800-88 Rev. 2 · DoD 5220.22-M · IEEE 2883

Data Sanitization for Government and Defence

Standards-bound destruction, offline operation, and evidence for every asset.

In government and defence, the question is rarely whether the data is gone. It is whether you can demonstrate that it is gone, to a standard someone else has written down, months after the fact.

Data Sanitization Pro implements the methods those standards name — NIST SP 800-88 Rev. 2 Clear and Purge, DoD 5220.22-M, IEEE 2883, HMG IS5 and others — and records which one was applied to which serial number, when, by whom, and with what verification result.

The software runs entirely offline. Licence activation, erasure, verification and certificate generation all work with no route to the internet, which is what a closed network requires.

The Shape Of The Work

Identify, Erase, Verify, Report, Then Decide

The whole chain runs inside your perimeter. No step needs a route out of the building.

  1. 01

    Identify

    The media on the device are enumerated locally. Nothing about them is sent anywhere, because there is nowhere for it to be sent.

  2. 02

    Erase

    The method your standard names, whether that is NIST SP 800-88 Purge, DoD 5220.22-M or one of the twenty-three others.

  3. 03

    Verify

    A read-back of the medium, on the machine, with the result recorded as part of the run.

  4. 04

    Report

    A signed certificate written to your own storage, hashed with SHA-256 so a later change to it is detectable.

  5. 05

    Reuse, Transfer or Destroy

    Downgrade the asset, move it between classifications, or send it for destruction with the record already in hand.

Runs with No Route Out

Offline licence activation, certificates kept on your own machine and nothing reported back. Nothing about the devices you process is transmitted anywhere, because there is nowhere for it to be transmitted to.

Air-gapped workstation — no network cable, erasure software running full screen

Evidence That Survives Scrutiny

Each certificate carries the drive's hash from before the run and after it, and the PDF is locked against editing and copying. The record states the standard, the pass count, the start and end time, the operator and the post-wipe verification result — the specific facts an assessor checks.

Certificate detail — SHA-256 hash, standard name, pass count and verification result

Methods Implemented

  • NIST SP 800-88 Rev. 2 — Clear, Purge and Destroy selected by media type
  • DoD 5220.22-M — three-pass and seven-pass overwrite where policy requires it
  • IEEE 2883-2022 — Clear and Purge for modern storage
  • British HMG Infosec Standard 5 — baseline and enhanced
  • German BSI-2011-VS and VSITR multi-pass patterns
  • Cryptographic erase for self-encrypting media, verified after issue
  • 25 methodsErasure Standards Built In

    NIST SP 800-88 Clear and Purge, IEEE 2883, DoD 5220.22-M, BSI, DPDP and twenty more. The software issues what the medium actually supports.

  • 0 outboundConnections Needed to Run It

    Licence activation is offline and certificates are written to your own storage. Nothing about the devices processed is transmitted, because there is nowhere for it to go.

  • SHA-256Signature on Every Certificate

    The report is hashed and signed as it is written, so a certificate altered after the fact no longer verifies.

  • 12 checksIn the Hardware Report

    SMART attributes, reallocated sectors, power-on hours, read and write throughput, memory, battery and thermals, graded against thresholds you set.

Questions

Frequently Asked Questions

Can the software be used on a classified network?

It runs fully offline. Nothing is reported back and nothing is sent out. Licence activation has an offline path, so the machine never needs a route to the internet at any stage.

Which standard should we apply?

NIST SP 800-88 Rev. 2 selects the method from the medium rather than applying passes for their own sake. Where local policy names DoD 5220.22-M or HMG IS5, those are implemented and recorded by name on the certificate.

How is the certificate protected from tampering?

Each certificate carries the drive's SHA-256 hash from before the run and after it, and the PDF is generated with editing and copying disabled. What an assessor checks is that the two hashes agree with the outcome the document claims.

Do you support on-site destruction as well as erasure?

Yes. Where policy requires physical destruction, we shred on your site under your supervision and issue a certificate of destruction per asset.

Tell us what you need

Discuss a Closed-Network Deployment

We will walk through offline activation, evidence handling and the standards your policy names.

Goes straight to our engineers. No newsletter, no call centre.