Skip to content

Company · Certifications

The certificate matters less than the scope printed on it

Providers rarely lie about certification. They routinely let buyers assume a scope broader than the one they hold. So here is ours, in full, including the parts that do not flatter us.

How to read this page

Every certificate answers one narrow question. Know which one.

A certification is a third party's attestation that a defined set of activities, at a defined site, met a defined standard on a defined date. It is not a general endorsement, and it does not travel beyond the scope line.

So when you evaluate any disposition provider — us included — ask for the certificate, read the scope, check the site address, and check the expiry.

Those four checks eliminate most of the ambiguity in this market. A certificate held by a parent company does not automatically cover the facility your assets are actually going to, and a scope that covers logical data sanitization does not cover physical destruction.

Current certifications

What we hold, and what it covers

Both certificates name our Lewisville, Texas facility — the site where your assets are actually processed.

R2v3

C2026-02018

Responsible Recycling Standard, Version 3

R2v3 is the standard most enterprise buyers treat as the threshold requirement for a disposition provider. It governs how reusable equipment is evaluated and tested, how data-bearing media are handled, and how material that cannot be reused moves through a documented downstream chain rather than disappearing into a broker network.

Certifying body
Perry Johnson Registrars, Inc.
Validity
Issued 25 March 2026 · valid through 20 March 2029
Scope
Downstream Vendor Management · Logical Data Sanitization · Testing and Repairing of Used Electronics
Appendices
Appendix A — Downstream Recycling Chain
Appendix B — Data Sanitization (logical only)
Appendix C — Test and Repair

RIOS

C2026-02020

Recycling Industry Operating Standard

RIOS is an integrated quality, environmental and health-and-safety operating standard for the recycling industry. Where R2v3 asks whether the right things happen to the material, RIOS asks whether the management system around it is real — documented procedures, corrective action, competence, and continual improvement.

Certifying body
Perry Johnson Registrars, Inc.
Validity
Issued 25 March 2026 · valid through 24 March 2029
Scope
Downstream Vendor Management · Logical Data Sanitization · Testing and Repairing of Used Electronics

Microsoft Authorized Refurbisher

Authorizes us to install genuine, licensed Microsoft operating systems on refurbished PCs, so remarketed machines leave with a valid licence rather than a compliance problem for the next owner.

A documented QEHS management system

Our quality, environmental and health & safety management system is built to ISO 9001, ISO 14001 and ISO 45001, with controlled documentation, defined review cycles and integrated training. Current certificate copies are provided on request during due diligence.

Full disclosure

What we do not hold

Published because you will ask, and because a provider who only lists strengths has told you nothing you can act on.

SOC 2
On our roadmap. We will not claim it before it is held. Where a specific control matters to your assessment, ask and we will describe how it is implemented and evidenced today.
ISO 27001
Also on the roadmap, and also not claimed. Our information-security controls — segregated network, MFA, least privilege, encryption at rest and in transit — are described honestly on request rather than implied by a certificate we do not have.
e-Stewards
Not currently held. A facility normally certifies to R2 or to e-Stewards; we certify to R2v3.
NAID AAA
Not held. If your policy specifically requires a NAID AAA certified provider for media destruction, tell us during scoping rather than after contracting — it is a legitimate requirement and we would rather you knew now.

FAQ

Questions about certification

Are you ISO certified?
We operate a documented quality, environmental and health & safety management system built to ISO 9001, ISO 14001 and ISO 45001. Current certificate copies are supplied directly during due diligence rather than published here, because a certificate image on a web page tells you nothing about whether it is still in force. Ask us for the current copies and read the dates yourself — that is the correct way to verify any provider, including us.
Why does the certificate scope matter so much?
Because certificates are issued for specific activities, and buyers routinely assume a broader scope than the one that was granted. Our R2v3 certificate carries Appendix B for data sanitization, and that appendix covers logical sanitization. A provider certified for logical sanitization is not thereby certified for physical destruction. We would rather state that plainly than let you infer something the certificate does not say.
Can we see the actual certificates?
Yes. Certificate copies, the audit report summary, and our management-system documentation are all part of the due-diligence package. If your third-party risk process needs them before a scoping call, ask and we will send them.
Who issued your certifications, and can we verify them independently?
Perry Johnson Registrars, Inc. of Troy, Michigan, an accredited certification body. R2 certificates are also listed by SERI, the standard's authority, so you can verify a provider's status without relying on the provider's own website. We encourage that.
Does hiring a certified provider make our organization compliant?
No, and be suspicious of anyone who implies otherwise. HIPAA, GLBA, PCI-DSS and FERPA obligations belong to your organization and cannot be transferred to a vendor. What a certified provider gives you is the controls and the serialized documentation your compliance function uses to demonstrate that disposal met your own policy.
What happens if you lose a certification mid-contract?
You would be told. Certification status is a contractual representation, not a marketing detail, and a lapse changes what we are permitted to do with your material. Any provider unwilling to commit to notifying you of a certification change is telling you something.
Do your downstream partners have to be certified too?
Yes — that is the point of R2v3 Appendix A. Downstream vendors are qualified, documented and manifested, and the chain is auditable beyond our own four walls. A responsible-recycling claim that stops at the provider's loading dock is not a claim about anything.

Ask for the certificates.

Current copies, the audit summary and our management-system documentation go out during due diligence, not after contracting.