Standards and assurance
What follows is written so a procurement or security team can check it. Where GreyFusion holds a certification it says so; where it follows a standard without being certified against it, it says that instead.
Standards followed
Data sanitisation follows NIST Special Publication 800-88 Rev. 1. End-of-life equipment is handled against the expectations of WEEE (2012/19/EU) and marked per EN 50419, and destruction records name the downstream recycler in line with R2v3’s downstream accountability requirement.
Personal data handling follows the Nigeria Data Protection Act 2023. End-user names and contact details are treated as personal data, access to them is restricted by role and logged, and they do not appear on certificates or in client reports.
What is certified, and what is not
GreyFusion is not, at the time of writing, an R2v3 or e-Stewards certified facility. Those are facility certifications with an audit cycle and a cost, and claiming one without holding it is the sort of thing a buyer checks in four minutes. What GreyFusion does hold is individual professional certification in security management and a system that produces the evidence those standards ask for.
Who supervises the work
Security operations, technical and non-technical, are carried out under the supervision of a certified professional, and that person is named on every report rather than described in the abstract.
How the record resists being rewritten
The chain of custody is append-only. The application’s database role can insert events and read them and has no permission to update or delete one. A correction is a new line with a reason and a name, and the photographs taken at hand-over cannot be deleted by the application at all.
That is a design choice with a cost — it means mistakes are visible rather than tidied away — and it is the reason the record is worth anything to somebody who was not there.
Questions we get asked
- Are you R2v3 or e-Stewards certified?
- No. GreyFusion follows the practices those standards describe and produces the records they ask for, including naming the downstream recycler on destruction certificates, but does not currently hold either facility certification.
- Who signs off the data destruction work?
- Olumide Solanke, Head of Service Delivery — CISM, PMP, AWS Solutions Architect – Associate and CompTIA CySA+ certified. Named on every report.
- How do you handle employee personal data?
- Under the Nigeria Data Protection Act 2023. End-user names and contact details are restricted by role, access to them is logged, and they never appear on a certificate or in a client report.
Read next
A wiped disk and a disk somebody says was wiped are different things. The difference is a verified method, a named o…
IT asset disposition is what happens to a laptop after the person using it stops needing it. Done properly it return…
Tell us which direction you need — devices out to people, or devices back from them — how many, where they are, and …