Certified data destruction and secure erasure

A wiped disk and a disk somebody says was wiped are different things. The difference is a verified method, a named operator, and a certificate that can be checked without taking anyone’s word for it.

Erasure, to a standard that has a name

GreyFusion sanitises data following NIST Special Publication 800-88 Rev. 1, the guideline most security teams and auditors recognise. It distinguishes Clear from Purge from Destroy, and the right one depends on the media and on what happens to the device next — an NVMe drive going back into service is not handled the same way as a failed disk leaving the building.

The method is recorded per device, not per batch. So is the tool and its version, the drive type, the start and end time, and who ran it.

  • NVMe sanitise and ATA secure erase where the drive supports it
  • Apple Configurator “Erase All Content and Settings” on Apple silicon
  • Overwrite and verification passes where firmware sanitise is unavailable
  • Physical destruction for failed media, with a certificate of destruction

Attestation and verification are separate acts

One person saying a disk was wiped is an attestation. It is useful and it is not proof. A second person confirming the step ran and recording what they saw is verification, and only a verified step can be certified.

The system enforces that separation rather than trusting it: a certificate cannot be issued against an erasure with no verified step, and the attestation and the verification carry different names.

Locks are part of erasure, not an extra

A device still enrolled in a previous owner’s mobile device management, or still carrying an activation lock or a firmware PIN, is not erased in any meaningful sense — it is tied to somebody else’s account. Clearing MDM, Find My and PIN locks is recorded as part of the data destruction step and is not billed separately.

End-of-life equipment

Devices that cannot be reused responsibly are routed for destruction and the downstream recycler is named on the certificate. WEEE (2012/19/EU) and the R2v3 standard both ask for downstream accountability, and an assurance nobody outside the company can check is not an assurance.

Questions we get asked

Is a factory reset the same as secure erasure?
No. A factory reset restores the operating system and, on many devices, leaves recoverable data behind. Secure erasure uses a sanitisation method appropriate to the media — firmware sanitise, cryptographic erase or a verified overwrite — and records which one was used.
What standard do you erase to?
NIST SP 800-88 Rev. 1. The specific method — Clear, Purge or Destroy — is chosen for the media and recorded per device, along with the tool and version used.
Can an auditor check a certificate without contacting you?
Yes. Every certificate carries a verification link that resolves to a page showing the certificate number, the device, the method, the date and the issuing technician. It needs no login. It carries no personal data about the employee who used the device.
Do you destroy drives physically?
Where the media has failed or the owner asks for it, yes — with a certificate of destruction naming the method, the mass and the downstream recycler.

Read next

Certified Data Destruction & Erasure, Abuja | GreyFusion