Resources
Every provider claims chain of custody. Few can show you where theirs breaks.
The phrase appears on every ITAD website in the industry. What distinguishes providers is not whether they use it, but whether they can describe the specific points at which custody is most likely to fail — and what stops it failing there.
The premise
A chain with a gap is not a chain
Chain of custody means an unbroken, documented record of who held each asset, when, and what was done to it. Every word in that sentence is load-bearing, and the one that gets skipped is unbroken.
A record with a gap in it is not a chain of custody. It is two records with an unexplained space between them — and in an audit, that space is the only thing anyone will want to discuss.
Which means the interesting question about any provider is not whether they maintain custody. It is where they think custody is most likely to break, and what they do about it there.
Failure modes
Five places custody actually breaks
Note that four of the five happen before equipment reaches a processing facility. The floor is rarely the problem.
- 01
The collection point
Someone puts equipment on a pallet without a manifest, or with a manifest written from memory. Everything downstream inherits that error, and it is invisible until reconciliation.
- 02
The storeroom
Assets sit for months between decommission and collection. Units go missing in ways nobody notices because no record said they were there.
- 03
The handoff between vendors
Procurement, support and disposal sit with different providers. Each holds a partial record; nobody holds a continuous one.
- 04
The subcontractor
The company you contracted with is not the company processing the equipment. Custody transferred to a party you never assessed.
- 05
The batch certificate
A certificate covering a shipment rather than a device. It looks like evidence right up until an auditor asks about one specific serial number.
What an unbroken chain produces
Six artifacts, per asset
Custody is not a promise; it is a set of records. If a provider maintains it, these exist for every individual device — not for the shipment.
- 01 Chain-of-custody receipt — Issued at intake, after the manifest is reconciled against what physically arrived.
- 02 Stage records — One per processing stage, each naming who verified it.
- 03 Sanitization certificate — Per device — serial, method, operator, station, timestamp, result, validation hash.
- 04 Condition and grading record — What state the asset was in, and what that made it worth.
- 05 Disposition authorization — Reuse, resale or certified recycling, recorded per asset.
- 06 Outbound manifest — With carrier confirmation, and downstream manifest where material is recycled.
How we handle it
Gates, not intentions
Our processing workflow is gated and sequential. No device advances to the next stage until the criteria for the current stage are verified and documented, and each gate produces the artifact above. Manual overrides are not permitted.
The gate that matters most is downstream of sanitization. A device without a passing wipe record is blocked in software at label creation and again at fulfilment — so it cannot ship, cannot enter finished goods, and cannot be invoiced. That is a mechanism rather than a policy, which is the distinction worth testing in any provider.
Assets under legal hold are segregated on arrival into restricted-access storage and cannot be wiped or transferred until a written release is received and logged from your authorized representative.
FAQ
Questions auditors and security teams ask
What does chain of custody actually mean in ITAD?
Where does it usually break?
How is it evidenced in an audit?
What happens if an asset goes missing?
When does liability transfer?
How is custody maintained across multiple collection sites?
What is the difference between per-device and per-batch certification?
Test us on this.
Ask us to trace a serial number, or schedule a records review. Compliance officers and third-party auditors can arrange a facility walkthrough on 48 hours' notice.