Skip to content

Industries · Financial Services

Built to survive your vendor due diligence, not just your procurement process

Financial institutions do not buy disposition on price. They buy it on whether the provider survives third-party risk review — so we have written this page for the people who run that review.

Where we stand

We do not certify your compliance. We produce the evidence you present.

A number of providers in this market advertise "GLBA-compliant ITAD" or imply that engaging them satisfies a regulatory obligation. That is a category error, and your examiners know it. The duty sits with the regulated institution and cannot be outsourced.

What can be outsourced is the work of generating defensible evidence — and that is the actual product.

Serialized inventory. Per-device sanitization records. Documented custody transfers. Downstream accountability. A facility your auditors can walk through on two days' notice. Those artifacts are what your risk committee, your internal audit function and your examiners are asking for when they ask about media disposal.

Third-party risk

Answers to the questions your TPRM team will ask

Published up front, so your assessment starts from facts rather than a discovery call.

Scope of certification
R2v3 (C2026-02018) and RIOS (C2026-02020), both current through March 2029, covering downstream vendor management, logical data sanitization, and testing and repair of used electronics.
Where processing occurs
Our own 70,000 sq ft facility at 1000 Spinks Road, Lewisville, Texas. Not brokered, not subcontracted.
Right to audit
Facility walkthroughs and records reviews on 48 hours' notice for compliance officers and designated third-party auditors.
Evidence granularity
Erasure certificates issued per device, not per batch, with serial, method, operator, station, timestamp and validation hash.
Physical access control
Single-entry / single-exit control from a dedicated security desk, AI-enabled camera coverage on every door with real-time anomaly detection, and auto-locking doors that cannot be propped without triggering an alert.
Personnel
Background-checked production staff trained on ITAD chain-of-custody protocols; dedicated security and compliance personnel on every operational shift.
Downstream
Certified downstream recycling chain with manifest documentation, covered under R2v3 Appendix A.
Data environment
Segregated network with dedicated VLAN, NSG isolation, MFA, and jump-host access with full audit trails.

Certificate numbers and validity dates shown above are current as issued by Perry Johnson Registrars. Copies are provided on request during due diligence.

FAQ

What risk and compliance teams ask

Does engaging you make us GLBA or PCI-DSS compliant?
No. The obligation belongs to your institution and cannot be transferred to a vendor — and a provider marketing itself as "GLBA-compliant ITAD" has misunderstood where the duty sits. What we provide is the controls and the serialized documentation your compliance function uses to demonstrate that media disposal met your own policy and your regulators' expectations. We do not certify your compliance. We produce the evidence you present.
Can you complete our third-party risk questionnaire?
Yes. We expect it. Send your SIG, your bespoke vendor questionnaire, or your security assessment and we will complete it during scoping rather than after contracting. The summary above covers most of what these questionnaires ask, and we would rather answer the hard questions early.
Do you carry SOC 2 or ISO 27001?
SOC 2 and ISO 27001 are on our roadmap and we will not claim them before they are held. Our processing and data-sanitization operations are certified to R2v3 and RIOS, both valid through March 2029, and we operate a documented quality, environmental and health & safety management system built to ISO 9001, ISO 14001 and ISO 45001. Where a specific control matters to your assessment, ask and we will describe how it is implemented and evidenced today rather than pointing at a certificate that does not cover it.
How do you handle a distributed branch estate?
Branch closures and ATM or teller-equipment refreshes generate small quantities across many locations, which is where chain of custody usually breaks. We consolidate through tracked multi-carrier logistics and reconcile each location's inbound against its declared manifest, so a discrepancy at one branch is visible rather than absorbed into a portfolio total.
What is your right-to-audit position?
We support it and build for it. Client compliance officers and designated third-party auditors can schedule facility walkthroughs and records reviews with 48 hours' notice. The audit package includes lot-level processing reports, erasure certificate samples, security access log excerpts, and staffing and training records.
Do you subcontract any part of the work?
Processing is performed in our own facility. Downstream recycling of residual material goes to certified partners under our R2v3 downstream vendor management appendix, with manifest documentation — which is a controlled, documented relationship rather than an unmanaged handoff.
What happens to assets that still hold value?
They are tested, graded and remarketed through established secondary-market channels, and the recovery is reported back to you. Security first, value second — the serialized control that satisfies your risk team is the same control that establishes provenance for a resale buyer.

Send us your vendor questionnaire.

We would rather answer the hard questions during scoping than discover a blocker after contracting.