For end users

You are the controller. The obligation does not transfer with the box.

You can outsource the disposal. You cannot outsource being the one who has to demonstrate the data is gone. We give you device-level evidence that survives an audit, whether the disposal partner you already use runs it, your own team does, or ours comes to you.

The only company we can find anywhere in the world that warrants the outcome and guarantees permanent, irretrievable data destruction.

A new standard nobody has yet been able to match, backed by £10 million of professional indemnity insurance. If you find another vendor whose licence warrants that the data is gone, we would like to see it, and we will say so publicly.

Where you actually stand

What you are holding today probably will not answer the question

Most organisations dispose through an accredited partner, receive a certificate of destruction, and file it. That is what policy asks for and it is what almost everybody does. It is also, on its own, evidence that a process was executed rather than evidence that your data is gone.

We know because 1,036 UK public bodies were asked under the Freedom of Information Act. There were 684 substantive answers, and 437 of them held no outcome warranty and no device-specific evidence. Nearly every one had followed policy and used a certified supplier. The gap is in what the records are capable of showing, not in whether anyone did their job.

“These records confirm that an erasure process has been completed successfully in accordance with the tool’s validation method, but they do not constitute a guarantee of irrecoverability for each specific device.” An NHS foundation trust, on the assurance it relies upon

Read the research →

Why it matters to you specifically

Accountability is a duty to demonstrate, not to assert

Article 5(1)(e)Personal data kept in identifiable form no longer than necessary. Data still recoverable on a disposed device has not stopped being kept.
Article 5(2) and 24You are responsible for, and must be able to demonstrate, compliance. A record that a process ran demonstrates the process.
Article 32(1)(d)A process for regularly testing and evaluating the effectiveness of your technical measures. Effectiveness is measured at the outcome.

Your disposal partner’s accreditations are their assurance, not yours. If a device surfaces with recoverable data on it, the questions come to you first, and a certificate describing a completed process is not an answer to them.

Before you change anything

Keep your supplier. Change the requirement.

You do not need to replace your ITAD, MSP or disposal partner to use the Smart Wipe Engine. Your existing supplier can licence the engine from us and use it when processing your assets, inside the disposal service and chain of custody you already have.

For many organisations the change is not who disposes of the equipment. It is what you require them to prove before a device is allowed to leave the process. Our own DPIA framework puts it the same way: where the existing supplier base can support it, the mitigation is achievable through specification update rather than supplier change.

Data destruction on our assets is carried out using the DSS Smart Wipe Engine, and a warranted, device-specific certificate is produced for every successful destruction event. For an existing supplier relationship, where you are instructing a partner you already hold a contract with

Whether that needs a contract variation or a procurement step is a question about your contract, not about the engine. What it does not need is a new supplier relationship.

If you are a public body, specify the outcome instead

A competitive procurement should describe what has to be achieved rather than name a product, and where a trade name has to be referenced an equivalent has to be allowed to compete. So do not ask for us. Ask for the standard, and let anyone who can meet it come forward.

The supplier shall, for each storage device processed, determine the sanitisation method automatically from that individual device rather than from an operator selection or a pre-configured policy; shall provide no facility for an operator to select or override the method; shall verify the resulting data state on the device itself rather than relying on a process completion status; shall fail closed and issue no certificate where the outcome cannot be verified; shall issue a device-specific certificate recording the device identifiers, the method applied and the verified outcome; and shall warrant in the contract that the data on each certified device is irrecoverable, with that liability not excluded or capped and supported by professional indemnity insurance. An outcome specification, naming no supplier

Every clause there describes a result, not a brand, so it is open to anybody who can meet it. If it turns out that nobody else can, that is a finding about the market rather than a restriction you wrote. Ask us for it as a document →

Your supplier’s side of it

Why it should be an easy yes for your supplier

This does not arrive at your disposal partner as a criticism of their process. It arrives as a customer asking for a higher assurance standard, and an engine that lets them deliver it inside the service they already run. They keep the relationship and they keep the work.

FasterA device-native command runs inside the drive rather than across the bus, so it can complete in seconds or minutes where an overwrite pass takes hours.
More through the same operationLess time tied up per asset means more assets through the same bench and the same people.
Lower cost per deviceLess labour time, less rack time and less operational overhead for each asset processed.
Nothing to pay for a failureWhere destruction cannot be proven, no certificate is issued and no destruction charge is payable. That is clauses 9.4 and 9.5 of the licence, not a goodwill gesture.
No method selection at the benchThe engine determines the correct method for the individual device. The operator does not choose it, so there is less to train and less skilled judgement to rely on.
Asset value preservedProving the outcome at the drive does not require destroying the drive, so equipment can keep its resale, reuse or donation value.
A stronger service to youThey move from handing you a certificate that a process ran to handing you a warranted, device-specific outcome with Data Safe Solutions behind it. Their existing erasure software cannot give them that.

Speed, throughput, cost and resale depend on the assets, their condition and how the operation is run, so we state them as what the method makes possible rather than as figures we guarantee. The warranted outcome is the part we do guarantee, and it is in the licence.

What your supplier gets from us →    Ask us to talk to them →

If you would rather run it yourself

Your team, or ours

In house

Licence the engine

Your own staff run it on your own site as part of normal refresh and end of life. We train them, and there is very little to teach, because there is no method to select. Media never leaves your control and you are not dependent on anyone’s collection schedule.

Attended

On site destruction

Our engineer attends and clears the work alongside your team. Useful for a backlog, a large refresh, or where you would rather not carry the process internally at all.

All three routes produce the same evidence, because the engine behaves identically whoever operates it, and that includes your existing supplier running it. The operator cannot change the outcome.

On site destruction →

What you are left holding

Evidence per device, and someone standing behind it

Proven

A certificate that records the correct method was applied to that specific device and the outcome was tested at the drive. Warranted, with £10 million of professional indemnity insurance behind it.

Not proven

The device is failed and quarantined for firmware remediation or physical destruction. No certificate is issued, so nothing enters your records claiming a destruction that did not happen.

Every asset is logged and tagged with a QR code linking to its own record, exportable into your asset management system. When an auditor asks about one machine, you can answer about that machine.

See the assurance register →

Before you buy anything

Four questions to put to every supplier, including us

01How does your software select the correct destruction method for each individual drive?
02Does your certificate warrant that the data on that specific device is irretrievable, or only that a process completed?
03When the correct method is refused or unsupported, do you fall back to an overwrite and still certify it?
04What do you pay if data is later recovered from a device you certified?

We answer all four in writing and we would ask that whoever else you are considering is required to do the same.