NIST 800-88 · DoD 5220.22-M
A certificate for every device, not a certificate for the truck
Sanitization is only worth what you can prove about it afterwards. Every data-bearing asset we handle produces its own verified erasure record — and cannot leave the building without one.
The standard
Verification is the product. Erasure is just the step that earns it.
Any vendor can run wiping software. The question an auditor actually asks is narrower and harder: can you show me what happened to this serial number?
That is why our workflow treats the certificate as the gate rather than the receipt. Validation runs automatically, produces a pass or fail, and the result is enforced in the systems that move assets — not just recorded in a report someone files afterwards. An asset without a passing result is blocked from shipping, from finished goods and from invoicing.
There is no manual override. That constraint occasionally slows a shipment. It is also the reason we can answer the auditor's question.
Methods
Method selected by media and by risk
Software sanitization
Blancco and WipeDrive for compute; ICE, BlackBelt and Phonecheck for mobile. Conformant to NIST 800-88, with DoD 5220.22-M triple-pass available where a client standard requires it.
HDD, SSD and Fusion drives · laptops, desktops, servers, mobile
Physical destruction
For media that cannot or should not be sanitized in place, or where your policy requires destruction regardless of verification result.
Failed media · highest-sensitivity environments
Quarantine on failure
Devices failing validation are routed out automatically with a reason code — WIPE_FAILED, SERIAL_MISMATCH, CERT_INVALID, NO_CUSTODY or QC_PHYSICAL — and cannot rejoin the flow.
Every device, every time
On the certificate
Eight fields, one device
- cert_id
- Certificate identifier
- device_serial
- The asset itself
- wipe_method
- Standard applied
- result_status
- Pass or fail
- operator_id
- Who performed it
- station_id
- Where it happened
- timestamp
- When
- validation_hash
- Tamper evidence
Stored permanently. Exportable as JSON or PDF for ingestion into your own compliance records.
FAQ
What auditors and security teams ask
What standard do you sanitize to?
What is actually on the certificate?
Is a certificate issued per device or per batch?
How is a wipe verified rather than just attempted?
Can we witness destruction?
Do you handle SSDs differently from hard drives?
What about AI servers and accelerated computing hardware?
Does sanitization make us compliant with HIPAA, GLBA or PCI-DSS?
Bring us the drives you cannot account for.
We will inventory them, sanitize them to your standard, and give you a record for every serial number.