For ITADs and disposal partners
When your client asks what proof you have, you need an answer.
You carry the destruction. Your name is on the certificate, your accreditations are in their supplier file, and if data comes back it is your problem before it is anyone else’s. We licence you the engine that makes the answer provable, per device, and we stand behind it.
The only company we can find anywhere in the world that warrants the outcome and guarantees permanent, irretrievable data destruction.
A new standard nobody has yet been able to match, backed by £10 million of professional indemnity insurance. If you find another vendor whose licence warrants that the data is gone, we would like to see it, and we will say so publicly.
The position you are in
Today you can show that a process ran
When a client asks what evidence you hold that their data is gone, you can hand over an erasure report and your accreditations. Both are real. Neither answers the question, because a completed, verified, certified erasure on a flash drive and a drive still holding recoverable data are not in conflict. They are the expected result of overwriting flash.
We know how that conversation goes, because 684 public bodies were asked the same question and 437 of them could produce nothing beyond a process record and a supplier’s certificates. Their disposal partners had done everything the standard asked.
The exposure sits with you. The certificate has your name on it, and the licence behind the software you used almost certainly disclaims the outcome entirely.
What changes
You licence the engine. It decides, not your operators.
No method to get wrong
The engine reads the device itself, determines the one correct command for that unit and proves the outcome on the medium before anything is certified. Not a setting your technician picks at the start of a shift, and not a default applied across a batch.
Proven, or failed
Where the outcome is proven, a certificate is issued and warranted. Where it cannot be proven the device is failed and quarantined for firmware remediation or physical destruction. No partial pass, and nothing recorded as erased with warnings. Correct selection means fewer devices reach that state, not more.
A warranty you can point at
The outcome warranty runs to you as the licence holder, backed by £10 million of professional indemnity insurance. It is the thing you can put in front of a client that no accreditation gives you.
Throughput
Correct method selection is also the commercial case
This is not only about assurance. We analysed signed disposal reports from an enterprise array. The overwhelming majority of the drives were Instant Secure Erase devices whose correct method is a cryptographic erase taking seconds. Every one of them was overwritten for hours instead, because overwrite was the selected method and it is supported across the widest range of devices.
The array in those reports was not hot swappable, so each batch was gated by its single slowest drive and everything that finished early sat locked in its slot. One drive running for half a day holds every other slot in the shelf hostage.
Far less array and server time for the same volume. Fewer rigs, less floor space, less capital tied up for the same daily output. And because destruction is achieved without physically destroying the media, the asset keeps its resale value.
Does failing closed mean more drives quarantined?
It is the first question every operator asks, and the logs answer it the other way round. The assumption is that a strict engine floods the quarantine bay. What the records show is that the conventional model produces the failures it then records.
Seven of the sixty-three returned the message that the erasure standard offered was not supported, which is the drive declining the standard it was given rather than declining sanitisation. The other fifty-six returned a write error: the configured threshold reached, twenty of twenty sectors failed to overwrite. A refused Purge came back in a median of two seconds. What ran in its place took a median of just under four hours across the host bus, and that is where the write errors came from.
The failures were not in the drives. Take the method choice away from the operator and the hours-long host-side operation that generates them never runs. Failing closed does not create quarantine. It stops a certificate being issued on what the conventional model was already failing, and there is less of it to begin with, because drives that would otherwise be written off complete cleanly and keep their resale value.
What you can say
Four questions your client should be asking every supplier
Including you. These are the questions we publish, and licensing the engine means you can answer all four without checking with us first.
- How does your software select the correct destruction method for each individual drive?The engine interrogates the device and selects automatically. Published patent application GB2638704A.
- Does your certificate warrant that the data on that specific device is irretrievable, or only that a process completed?Warranted, on every certificate issued.
- When the correct method is refused or unsupported, do you fall back to an overwrite and still certify?No. The device fails and no certificate exists.
- If data is later recovered from a device you certified, what do you pay?£10 million of professional indemnity insurance sits behind the warranty.
How it works commercially
What a partnership involves
Verify us first
Before you put your name next to ours
You are about to carry our engine into your own client relationships, so check us the way you would want to be checked. ADISA Product Assurance at Level 5, projects ADPA016 and ADPA039, scope including NVMe, valid to 14 February 2027, listed publicly by ADISA rather than by us. Published patent application GB2638704A. Cyber Essentials. Evidence of indemnity on request.