The outcome standard

The only ones who prove the data is gone. And pay if it is not.

Every other vendor certifies that a process ran. We prove that the data on that specific device has been rendered irretrievable, test it at the drive, warrant it in writing, and carry £10 million of professional indemnity insurance behind the warranty. Not a better eraser. A different standard, and so far an unmatched one.

UncappedOur liability for the outcome
£10 millionProfessional indemnity behind it
ADISA Level 5Product assurance · NIST SP 800-88
GB2638704APatent application published

The blind spot

The test passed because the test cannot fail

An overwrite can only reach the addresses the host is able to point at. On flash, the drive’s own controller has already moved the original data out of those addresses and into blocks the host cannot name: remapped, spare, over-provisioned. The overwrite fills the addresses it was given. The verification then reads back those same addresses, finds exactly what it just wrote, and reports success. It is telling the truth about the part of the drive that no longer holds the data.

Nothing failed. No setting was wrong, no operator slipped, no supplier cut a corner. The process ran, the check passed, the certificate was correct. And the data is still there.

This is why a genuine, verified, certified erasure and a drive still holding recoverable data are not a contradiction. With overwrite on flash they are the normal outcome, repeated at scale, every day, inside disposal chains that are fully accredited and doing exactly what the standard asks of them. The certificate is not a lie. It is an answer to a question that was never the right one.

It is why NCSC guidance, NIST SP 800-88 and IEEE 2883 all direct that flash media be sanitised by cryptographic erase or the drive’s own purge command rather than by overwriting. And it is why fully certified disposal chains keep putting devices with intact data onto the second-user market.

So why is anybody still overwriting?

Because that is how the software works. The leading erasure products do not interrogate an individual drive and determine the correct sanitisation method for that device. The method is selected by an operator or configuration in advance. Some platforms subsequently check whether that chosen method is supported; others simply attempt it. Neither determines which sanitisation method is correct for the individual device.

Neither of those is selection.

Overwrite is used as the default because it works across the widest range of devices and gives the operator the highest chance of getting the asset through the process without stopping the production line. It is a throughput decision, not a security decision.

It is also a failure-rate decision. Hours of sustained host-side writes are what produce the write errors and threshold breaches that get a working drive recorded as faulty, and in the erasure logs we have examined those accounted for fifty-six of the sixty-three failed Purge attempts. A device-native command runs on the drive’s own controller and, where the device supports an immediate cryptographic operation, can complete in seconds, so the operation that manufactures those failures never runs at all.

The problem is that a method can be fully supported by a drive and still be the wrong method for destroying the data on it. On flash, overwrite is exactly that. The software sees a supported command, executes it, verifies the addresses it wrote, reports success and issues the certificate. At no point has it determined whether overwrite was the correct sanitisation method for that specific device.

When a device-native method is selected instead and the drive refuses it, or the command does not complete, the same production logic takes over again. The software falls back to overwrite, completes the job, records the erasure as successful and issues the certificate.

So overwrite is not simply one method among many. It is the default path chosen for maximum throughput, and it is the fallback path when the correct method fails.

We remove that decision entirely. The engine interrogates the individual device, determines the correct media-appropriate method itself, applies only that method, and fails closed if it cannot prove the outcome. The operator is given no method to choose and no list to choose from. Where the correct method cannot be executed and proven, the device fails closed and no certificate is issued. Every part of the picture above is taken from the vendors’ own manuals and licences, which is why we have no need to name any of them.

See what 437 public bodies told us →

Why comparisons fail

We are not another erasure product

Comparing us feature by feature against an erasure tool misses what is actually different, because the two things are not answering the same question.

The industry testDid the selected process complete, and did a read-back of the addresses it wrote to confirm the pattern was written? Pass, and a certificate is issued.
Our testIs the data on this specific device now irretrievable, proven at the device and warranted? If that cannot be shown, no certificate exists.

A device can pass the first test and fail the second, and on the face of the certificate the two are indistinguishable. That is the whole problem, and it is why more features, more standards in a dropdown and more accreditations on a supplier list do not solve it.

A standard is something everyone can be measured against, including us. So we publish the test rather than the sales pitch. Ask any supplier, us included, to answer these four in writing.

  1. How does your software select the correct destruction method for each individual drive?
  2. Does your certificate warrant that the data on that specific device is irretrievable, or only that a process completed?
  3. When the correct method is refused or unsupported, do you fall back to an overwrite and still certify it?
  4. What do you pay if data is later recovered from a device you certified?

One comparison you can make without us: every erasure licence we have examined excludes or caps liability for the outcome. Ours does not. Read the two side by side.

Read our licence terms →    See how we answer all four →

The determination

The engine decides, not the operator

In the conventional model the erasure method is chosen before the individual drive is processed, by an operator or by a configuration. Some platforms then check whether that chosen method is supported; others simply attempt it. Neither determines which method is correct for that specific device. A support check can only reject a method the drive cannot run, never one it can run but which is wrong for it, and plain overwrite is supported on effectively every drive in service, even though on a modern drive it leaves large parts of the media untouched.

01

Interrogate

The engine reads the device’s own characterisation parameters directly from the drive. Not the model number on the label, and not a lookup list.

02

Select

It determines and issues the one correct command for that unit. The erase runs inside the drive rather than across the bus, so it completes under load. No operator choice, no method list, and nothing certified that was not proven.

03

Prove

Known data is written before the erase and read back after it. The result is tested at the device rather than taken from a status flag.

Proven

The correct command completed, the known pattern is unrecoverable, and every readable region including remapped sectors reports clear. A certificate is issued and warranted.

Not proven

The device is failed and quarantined for firmware remediation or physical destruction. No certificate is issued. There is no partial pass and nothing recorded as erased with warnings.

Delivery

One engine. However you need it run.

The engine behaves identically whoever operates it, because the operator cannot alter the outcome. What changes is who runs it and where your media sits while they do.

In-house licenceYour own staff run it on your own site, trained by us. Media never leaves your control.
DSS MobileOur engineer attends your site. Destruction completes before any device moves. Each asset is tagged and logged for audit.
Through an ITADYour disposal partner licenses the engine and runs it under their own chain of custody.
Embedded in a platformThe engine integrated into a partner’s own service or product.

The evidence

The largest study of its kind was done by one private citizen

The largest empirical study of data destruction across the UK public sector was carried out at the start of 2026 by a private individual. No company, no research team, no budget and no privileged access. One question, put to UK public bodies under the Freedom of Information Act. Anyone can ask the same question and compare the answers.

The question: what recorded evidence do you hold that the data on your disposed storage devices was actually rendered irretrievable?

1,036requests issued
684substantive responses
437held no outcome warranty and no device-specific evidence
“Your request has highlighted a gap in our Data Protection Accountability obligations for this processing.” Scottish Environment Protection Agency, F0201023. The regulator went on to confirm it would now draft a Data Protection Impact Assessment to meet Article 32 of the UK GDPR.
“The methods used are designed to only signal completion when that data has been removed successfully. Therefore, if the process indicates completion, that means the data has been erased.” Department for Work and Pensions, FOI2026/25131. Asked in the same letter for the wording of that guarantee: “There is no such warranty or guarantee.”

That is the assumption the entire model rests on. Completion is treated as proof of the outcome, because the software was built to report completion only when the outcome was achieved. Nothing is tested at the device.

The Ministry of Defence answered “Yes” to holding an outcome warranty, applied the cost limit when asked for its wording, then amended the answer to confirm that Defence Digital holds no such warranty at all. Read the named responses →

Three problems we solve

Where we work

01 / Data destruction

Verified erasure, warranted

The Smart Wipe Engine, delivered as a licence, an attended service or through your disposal partner. Proof at the device, a certificate only where destruction is proven, and professional indemnity insurance behind it.

How it works →
02 / AI integration

NHS and enterprise data, connected

We deliver Bardioc, Almato’s semantic data platform, which consolidates data across siloed systems without disrupting existing workflows, on open-box AI that can be inspected rather than trusted. Separately, we work with the University of Liverpool on NHS data.

How it works →
03 / Cybersecurity · in development

Enforcement before the operating system

A compromised operating system cannot be the final authority on whether it is trustworthy. We are building an endpoint system on the principle the erasure engine already works to: enforce first, then prove it. In development, not yet available.

What we are building →
NHSDefenceLocal government Financial servicesEnterpriseITAD partners

Working with

Assurance

Everything we claim, and where to check it

We publish our certifications, what each one actually certifies, and the standards that do not apply to us and why. Every reference is verifiable against the issuing body rather than against us. We would rather you checked.

Read the assurance register →

Test it

Do not take our word for it. Take your own drives.

Run 100 drives through your current system. Then run the same 100 through ours. The same devices, on the same rigs, with the same firmware, so it is a true device by device match rather than two separate samples.

Compare them on purge match rate, verified outcomes, drives recovered rather than condemned, and throughput. You keep the results whichever way they fall. There is no upfront commitment and nothing to unpick if you walk away.

Book the comparison test →