Skip to content
The lit glass frontage of the WesternTechSystems facility at night

NIST 800-88 · DoD 5220.22-M

A certificate for every device, not a certificate for the truck

Sanitization is only worth what you can prove about it afterwards. Every data-bearing asset we handle produces its own verified erasure record — and cannot leave the building without one.

The standard

Verification is the product. Erasure is just the step that earns it.

Any vendor can run wiping software. The question an auditor actually asks is narrower and harder: can you show me what happened to this serial number?

That is why our workflow treats the certificate as the gate rather than the receipt. Validation runs automatically, produces a pass or fail, and the result is enforced in the systems that move assets — not just recorded in a report someone files afterwards. An asset without a passing result is blocked from shipping, from finished goods and from invoicing.

There is no manual override. That constraint occasionally slows a shipment. It is also the reason we can answer the auditor's question.

Methods

Method selected by media and by risk

Software sanitization

Blancco and WipeDrive for compute; ICE, BlackBelt and Phonecheck for mobile. Conformant to NIST 800-88, with DoD 5220.22-M triple-pass available where a client standard requires it.

HDD, SSD and Fusion drives · laptops, desktops, servers, mobile

Physical destruction

For media that cannot or should not be sanitized in place, or where your policy requires destruction regardless of verification result.

Failed media · highest-sensitivity environments

Quarantine on failure

Devices failing validation are routed out automatically with a reason code — WIPE_FAILED, SERIAL_MISMATCH, CERT_INVALID, NO_CUSTODY or QC_PHYSICAL — and cannot rejoin the flow.

Every device, every time

Test and verification workstations on the WesternTechSystems processing floor

On the certificate

Eight fields, one device

cert_id
Certificate identifier
device_serial
The asset itself
wipe_method
Standard applied
result_status
Pass or fail
operator_id
Who performed it
station_id
Where it happened
timestamp
When
validation_hash
Tamper evidence

Stored permanently. Exportable as JSON or PDF for ingestion into your own compliance records.

FAQ

What auditors and security teams ask

What standard do you sanitize to?
NIST Special Publication 800-88 is our baseline. Where a client policy or contract specifies it, we also run DoD 5220.22-M triple-pass. Method selection is risk-based and recorded per device, so the certificate shows which standard was applied to that specific asset.
What is actually on the certificate?
Certificate ID, device serial, sanitization method, result status, operator ID, station ID, timestamp and a validation hash. Certificates are stored permanently and export as JSON or PDF. Because they are issued per device, an auditor asking about one machine gets an answer about that machine.
Is a certificate issued per device or per batch?
Per device. Batch-only certification is a well-known weakness in this industry — it looks like evidence until someone asks a specific question. Every data-bearing asset we process carries its own record.
How is a wipe verified rather than just attempted?
Validation is automated and produces a pass or fail. A pass writes the certificate; a fail quarantines the device with a reason code. Critically, the result is enforced downstream: an asset without a passing wipe is blocked at label creation and again in fulfilment, so it cannot ship, cannot enter finished goods and cannot be invoiced.
Can we witness destruction?
Client compliance officers and designated third-party auditors can schedule facility walkthroughs and records reviews on 48 hours' notice. Tell us what you need to observe and we will scope it into the engagement.
Do you handle SSDs differently from hard drives?
Yes. Flash media does not respond to overwrite-based methods the way magnetic media does, which is why NIST 800-88 distinguishes Clear, Purge and Destroy rather than prescribing a single technique. Method selection accounts for media type, and the certificate records which method was applied.
What about AI servers and accelerated computing hardware?
The storage media in those systems is sanitized and certified exactly as any other drive is — and there is a great deal of it, since a dense accelerated rack can carry ninety or more devices across its trays. What we will not tell you is that we sanitize the accelerator itself, because no published standard defines a procedure for it and no manufacturer supplies one. We set out where the guidance stops in our analysis of accelerator sanitization, and how it works as a service in GPU and AI infrastructure lifecycle management.
Does sanitization make us compliant with HIPAA, GLBA or PCI-DSS?
No — and be cautious of any vendor who says it does. Those obligations sit with your organization, not with a service provider. What we produce is the serialized, auditable evidence your compliance team and your examiners ask for when demonstrating that media was disposed of properly. We do not certify your compliance. We document ours, so you can evidence yours.

Bring us the drives you cannot account for.

We will inventory them, sanitize them to your standard, and give you a record for every serial number.