Industries · Financial Services
Built to survive your vendor due diligence, not just your procurement process
Financial institutions do not buy disposition on price. They buy it on whether the provider survives third-party risk review — so we have written this page for the people who run that review.
Where we stand
We do not certify your compliance. We produce the evidence you present.
A number of providers in this market advertise "GLBA-compliant ITAD" or imply that engaging them satisfies a regulatory obligation. That is a category error, and your examiners know it. The duty sits with the regulated institution and cannot be outsourced.
What can be outsourced is the work of generating defensible evidence — and that is the actual product.
Serialized inventory. Per-device sanitization records. Documented custody transfers. Downstream accountability. A facility your auditors can walk through on two days' notice. Those artifacts are what your risk committee, your internal audit function and your examiners are asking for when they ask about media disposal.
Third-party risk
Answers to the questions your TPRM team will ask
Published up front, so your assessment starts from facts rather than a discovery call.
- Scope of certification
- R2v3 (C2026-02018) and RIOS (C2026-02020), both current through March 2029, covering downstream vendor management, logical data sanitization, and testing and repair of used electronics.
- Where processing occurs
- Our own 70,000 sq ft facility at 1000 Spinks Road, Lewisville, Texas. Not brokered, not subcontracted.
- Right to audit
- Facility walkthroughs and records reviews on 48 hours' notice for compliance officers and designated third-party auditors.
- Evidence granularity
- Erasure certificates issued per device, not per batch, with serial, method, operator, station, timestamp and validation hash.
- Physical access control
- Single-entry / single-exit control from a dedicated security desk, AI-enabled camera coverage on every door with real-time anomaly detection, and auto-locking doors that cannot be propped without triggering an alert.
- Personnel
- Background-checked production staff trained on ITAD chain-of-custody protocols; dedicated security and compliance personnel on every operational shift.
- Downstream
- Certified downstream recycling chain with manifest documentation, covered under R2v3 Appendix A.
- Data environment
- Segregated network with dedicated VLAN, NSG isolation, MFA, and jump-host access with full audit trails.
Certificate numbers and validity dates shown above are current as issued by Perry Johnson Registrars. Copies are provided on request during due diligence.
FAQ
What risk and compliance teams ask
Does engaging you make us GLBA or PCI-DSS compliant?
Can you complete our third-party risk questionnaire?
Do you carry SOC 2 or ISO 27001?
How do you handle a distributed branch estate?
What is your right-to-audit position?
Do you subcontract any part of the work?
What happens to assets that still hold value?
Send us your vendor questionnaire.
We would rather answer the hard questions during scoping than discover a blocker after contracting.