Assurance, and what each certificate actually certifies
This page exists so that anyone assessing us can verify what we claim without asking us first. Every reference below is checkable against an independent source, and we have said plainly where a standard does not apply to us and why.
The only company we can find anywhere in the world that warrants the outcome and guarantees permanent, irretrievable data destruction.
A new standard nobody has yet been able to match, backed by £10 million of professional indemnity insurance. Every reference on this page can be checked against an independent source, and that claim can be tested by reading any competitor’s licence.
We are not a competing erasure product, so assessing us against the checklist written for one produces the wrong answer. The industry’s test is whether a selected process completed. Ours is whether the data on the device is gone, proven at the device and warranted. What follows is how we answer our own test, and what each certification does and does not tell you about either.
01 / Basis of assurance
The only question is whether the engine succeeded on the device
Assurance here is binary, and it is per device. Either the engine proved the data on that unit is gone, or it did not. There is no third state, and no certificate exists for one.
Certificate issued and warranted
The correct media-appropriate command for that specific unit completed. A known pattern written to the drive before the erase is confirmed gone after it, and every readable region, including remapped sectors, is reported clear. The certificate records a successful destruction, and the indemnity stands behind it.
Device failed, no certificate
The device is failed closed and quarantined for firmware remediation or physical destruction. Nothing is passed on a substitute method, and no certificate of destruction is issued. There is no partial pass, and no result recorded as erased with warnings.
A certificate is not a receipt that a job ran. It records the device, the method the engine selected for it, the result proven at the medium and the time the erase took. See a specimen certificate and read what it actually says before comparing it with one you already hold.
Who operated it does not change the answer
The engine is automated. It reads each device, determines the single correct command for that unit, and proves the result on the medium rather than reading a status flag. The operator does not choose the method, cannot substitute a weaker one when the correct one is refused, and has no setting that alters the outcome. Nothing is certified that was not proven at the device. That automated per-device selection is the subject of our published UK patent application GB2638704A, filed 28 February 2024 and published 3 September 2025.
That is why the usual organisational controls answer a question this product does not raise. Where an operator selects the erasure method, their training, screening and process discipline decide whether your data survives, and certifying the organisation is a fair proxy for that risk. Where the operator cannot affect the outcome, it is not a proxy for anything.
The engine is licensed to direct clients, ITADs, platform partners and resellers, and it behaves identically in every one of them. The warranty attaches to the licence holder. Our own people attend a customer site in one context only, the attended DSS Mobile service. Every engineer who attends holds an Enhanced DBS check before they attend, and that control is engaged there and nowhere else.
02 / Register
What you can verify independently
| Claim | Reference | Where to verify |
|---|---|---|
| ADISA Product Assurance, Level 5 | ADPA016 ADPA039 Scope includes NVMe. Valid to 14 February 2027. |
adisacertification.com, listed publicly by ADISA, not by us. View ADPA016 certificate · View ADPA039 certificate |
| Automated per-device method selection, UK | GB2638704A Published application. Filed 28 February 2024, published 3 September 2025. |
UK Intellectual Property Office, applicant Data Safe Solutions Ltd |
| Automated per-device method selection, US | 19/064,309 Published application, under examination. |
USPTO Patent Center, applicant Data Safe Solutions Ltd |
| Standards the engine is tested against | NIST SP 800-88 IEEE 2883 | Tested by ADISA under the Product Assurance scheme above |
| Cyber Essentials | Certified | IASME certificate search. View our certificate |
| Insurance behind the warranty | £10,000,000 £10,000,000 Technology professional indemnity, each and every claim, and public and products liability with the inefficacy exclusion deleted. Hiscox. |
Schedule published. Page three: the standard inefficacy exclusion is deleted by endorsement under public and products liability. Read the schedule |
03 / Warranty
The control that no certificate provides
Across this industry a certificate of data destruction records that a process was executed. It does not warrant that the data is irretrievable. Competing erasure licences disclaim the outcome and exclude or cap liability for the result. The Smart Wipe Engine licence does not.
Every erasure licence we have examined excludes or caps liability for the outcome. Ours does not. That is a comparison anyone can make for themselves by reading the two licences side by side, and we would encourage it.
Where a Data Safe Solutions Certificate of Data Destruction records successful completion, we warrant that the data on the identified device has been rendered irretrievable in accordance with NIST SP 800-88. Where destruction is not successful, no Certificate of Data Destruction is issued and no outcome warranty applies. The failed attempt remains recorded for audit.
The distinction that matters commercially is not the insurance. It is the liability. We warrant the outcome and we accept uncapped liability for it under our standard licence. What stands behind that liability is a technology professional indemnity section whose insuring clause names our activity directly, covering any act, error or omission in the processing, storage, destruction or erasure of personal data, and covering breach of any contract between us and a client, which is what clause 5.1 is. Alongside it sits public and products liability on which the standard inefficacy exclusion has been deleted by endorsement rather than left in. Both limits are £10,000,000, the professional indemnity each and every claim. No underwriter writes data erasure into the clause at that limit without first examining how the erasure is done. The schedule is published rather than described, and you can read what it says here.
We can warrant the outcome because the engine is built to achieve the outcome rather than to produce a certificate. It reads each device, determines the one correct command for that unit, writes a known pattern before the erase and reads it back afterwards. Where it cannot verify a proper result the device is failed and quarantined. There is no method for the operator to select and no setting to get wrong. We can go without a fallback because the method underneath it completes.
04 / Applicability
Standards we are commonly asked about
| Standard | Status | Position |
|---|---|---|
| ADISA Product Assurance | Held, Level 5 | Tests the erasure product itself against NIST SP 800-88 Rev 1. This is the certification that speaks to the outcome on the device. |
| Cyber Essentials | Held | Covers our own IT estate. Relevant to us as a supplier, silent on what happens to your drive. |
| Enhanced DBS check | Held | Every engineer who attends a customer site holds an Enhanced DBS check, issued by the Disclosure and Barring Service and verifiable on request. Directly relevant to Model B, where an engineer attends your site. Not engaged by Model A, where we have no access to your assets or premises. |
| ISO/IEC 27001 | Not held | We would rather say so than imply otherwise. ISO 27001 scope is defined by the organisation seeking it, so it can be certified over a tightly bounded management system and still establish nothing about the erasure itself. |
| BS EN 15713:2023 | Not applicable | Governs organisations that collect, transport, store and physically destroy confidential material. We do none of those. Holding it would certify a service we do not provide. |
05 / Evidence
Why organisational certification is the wrong test
That view did not come from theory. At the start of 2026 a private individual put a single question to UK public bodies under the Freedom of Information Act: what recorded evidence do you hold that the data on your disposed storage devices was actually rendered irretrievable?
The suppliers named in those responses hold ISO 27001, ISO 9001, ISO 14001, ADISA asset-recovery certification and Cyber Essentials Plus. The certificates are offered as the assurance, because no evidence of the outcome exists. Asked directly whether its destruction certificates warranted the result, one regulator answered:
“I can confirm that the destruction certificates do not constitute an explicit outcome-based warranty or guarantee that the personal data on each storage device has been rendered irrecoverable as a final state.” Office for Nuclear Regulation, response to FOI202603081
A management system certificate certifies the organisation. It has never certified the drive. That distinction is the whole of our business.
06 / Test us
Four questions to put to any erasure supplier
Including us. We will answer all four in writing, and we would ask that whoever we are being compared against is required to do the same.
- How does your software select the correct destruction method for each individual drive?
- Does your certificate warrant that the data on that specific device is irretrievable, or only that a process completed?
- When the correct method for a device is refused or unsupported, do you fall back to an overwrite and still certify it?
- What do you pay if data is later recovered from a device you certified?