For Chief Risk Officers

You have been told data disposal is covered. Here is what that assurance actually rests on.

Your CIO and your CISO are not wrong to report it as controlled. They followed policy and used a certified supplier. The gap is in what the paperwork is capable of proving, and nobody in the chain is asked to prove more than that.

Every supplier certificate we have examined records that a process ran. Not one warrants that the data is gone.

Every erasure licence we have examined, other than our own, disclaims or caps liability for the outcome. The certificate in your file is evidence of activity, not of destruction.

The risk on your register

What you are told, and what the certificate actually says

What you are told

Disposal is handled by an accredited supplier. Every device comes back with a certificate. The risk is controlled.

What the certificate shows

The method that ran. Not whether it was the right method for that device, and not whether the data is gone. The licence behind it disclaims the outcome the certificate implies.

Those are not the same statement, and the difference is the whole of your exposure. What follows is why a correct, certified, fully accredited process can leave recoverable data on a device, and why no one downstream of you has accepted responsibility for it.

Why it fails

The verification checks the part of the drive that no longer holds the data

This is not negligence and it is not a bad supplier. It is how overwriting works on modern storage.

01

An overwrite can only reach the addresses the drive reports to the computer it is plugged into. That is the limit of what any erasure software can touch from outside the drive.

02

On flash storage the drive’s own controller has already moved copies of the data into remapped, spare and overprovisioned blocks. The host cannot address those blocks and cannot see them.

03

The overwrite fills the addresses it was given. The verification then reads those same addresses back, finds exactly what was just written, and reports success.

04

The report is accurate. It is accurate about the part of the drive that no longer holds the data. The copies the controller moved are untouched, and the device leaves with a certificate.

Nothing failed. No setting was wrong, no operator made a mistake and no supplier cut a corner. The process ran, the verification passed and the certificate is correct. The data is still there.

This is why NIST SP 800-88 Revision 2 directs that overwrite not be relied on for current flash media, and sends the choice of method to IEEE 2883, the standard written for the media itself.

The second failure

When the correct method is refused, the software falls back and certifies anyway

Even where the right device native command is selected, it is not always accepted. The drive can refuse it, or the command can fail to complete.

At that point production logic takes over. The software falls back to an overwrite, finishes the job, records the erasure as successful and issues the certificate. Nothing on the certificate distinguishes that device from one where the correct method ran and worked.

What the record shows

Erasure completed. Method recorded. Certificate issued. The device moves on and the asset register is closed.

What actually happened

The correct method was refused, an overwrite ran in its place, and no one was told. The evidence you hold cannot tell the two apart.

Who is carrying it

The assurance runs in a circle and stops with you

The certificateRecords that a process was executed to a stated method. It does not warrant that the data on that device is irrecoverable.
The supplierOperates the software as instructed and passes on what the software reports. The accreditations are the supplier’s assurance, not yours.
The software licenceSupplied as is. No warranty that data will be rendered irretrievable. Liability for data loss excluded or capped.
The controllerYou. Article 5(2) UK GDPR requires you to demonstrate the outcome, not the activity. That duty has not moved anywhere.

Nobody in that chain has accepted responsibility for whether the data is gone. The only party carrying a legal duty is the one at the start of it.

Asked for the text of the guarantee it had said it held, one central government department answered: “There is no such warranty or guarantee.” Department for Work and Pensions, FOI2026/25131

How common is this

1,036 requests to UK public bodies, and what came back

Between January and September 2026 the question was put to the UK public sector under the Freedom of Information Act, by a private individual rather than by a company. What evidence do you hold that the data on your end of life storage media was actually rendered irretrievable?

1,036requests issued to UK public bodies
685responses classified against the organisations’ own recorded positions
437with no outcome warranty and no device specific evidence, relying on a certificate issued under terms that disclaim the outcome
248have already moved to an assurance model that does not rest on unwarranted process certification

Those 248 are more than a third of the organisations that answered. Same regulator, same supplier market, same question put to them. So the question is no longer whether a certificate without a warranty can be defended in principle. It is why an organisation would keep relying on one when a third of its peers already do not.

“These records confirm that an erasure process has been completed successfully in accordance with the tool’s validation method, but they do not constitute a guarantee of irrecoverability for each specific device.” An NHS foundation trust, describing the assurance it relies on
“Your request has highlighted a gap in our Data Protection Accountability obligations for this processing.” Scottish Environment Protection Agency, FOISA response F0201023, which committed to drafting a DPIA in the answer itself

See the research →    Read the full argument →

Before you take anyone’s word, including ours

Four questions to put to your own people

Put these to your CIO, your CISO and your disposal supplier, in writing. The answers tell you where you stand without involving us at all.

01How does the erasure software select the destruction method for each individual drive, and who or what makes that choice?
02Does the certificate we hold warrant that the data on that specific device is irretrievable, or only that a process completed?
03When the correct method is refused or unsupported, does the software fall back to an overwrite and still certify the device?
04What does the supplier pay if data is later recovered from a device they certified, and what does their software licence say about that?

We answer all four in writing about our own engine, and we would expect you to require the same of anyone else you are considering, including your current supplier.

See how we answer the four →    Read our licence terms →

What it takes from you

Your supplier changes the tool. You do not change the supplier.

One instruction, and nothing else changes. You are not appointing us, moving a contract or running a competition, because you are not the one licensing anything. Your existing disposal supplier changes the erasure software it runs on your assets, and you get evidence that answers the question above.

Cost to youNothing. The supplier carries the licence, and it costs them less than the one they use now.
TenderNone. You are not buying anything or appointing anyone.
SupplierThe one you already have. Same relationship, same collections, same chain of custody.
Your processUnchanged. Devices leave the way they leave today.
Your IT teamNo new system to run, no budget line, no project.
What you getA certificate per device recording the method applied and the verified outcome, a warranty that the data is irrecoverable, and an insurer standing behind it.

The instruction

With effect from [date], data destruction on our assets is to be carried out using the DSS Smart Wipe Engine. DSS will ensure every successful destruction produces a device specific certificate, warranted as irrecoverable and backed by £10 million of professional indemnity insurance. Sent to your existing disposal supplier. That is the whole of it.

If your contract needs a variation to carry it, it is one paragraph, and we will give you the wording. Ask for it →

The supplier’s side

Why your supplier will be glad you asked

This does not land on your supplier as a complaint. It lands as a cheaper, faster tool and a stronger service to sell, with the contract kept.

CheaperWe price below what they are paying their current software vendor.
Nothing up frontBilled per successful wipe, monthly in arrears. No annual block of licences bought in advance.
No charge for a failureWhere destruction cannot be proved, no certificate is issued and nothing is charged. That is in the licence.
FasterOn a self encrypting drive the correct method is a cryptographic erase that completes in seconds. An overwrite on the same drive runs for hours, and on some drive types most of a working day.
Fewer failed attemptsThe engine reads each drive and selects the right method first time. No trial and error, no fallback, no second licence burned on a retry.
Trained in minutesDownloadable software. There is no method for the operator to choose, so there is very little to teach.

What your supplier gets from us →    Ask us to speak to them →

Who stands behind it

Engine, warranty, liability, insurance

The engineInterrogates each device, determines the one correct method for it, applies only that method, and fails rather than certify what it cannot prove. Engineered to NIST SP 800-88 and IEEE 2883, independently assured at ADISA Product Assurance Level 5.
The warrantyClause 5.1 of the licence warrants that the data on each certified device is irrecoverable.
The liabilityClause 6.1 makes us liable where the platform records a successful destruction and that outcome was not achieved. Clause 17.1 leaves that liability uncapped. The exclusions are set out at 6.2 and published with the rest of the licence, so you can read them before you rely on it.
The insuranceBacked by £10 million technology professional indemnity, each and every claim, and £10 million public and products liability with the inefficacy exclusion deleted. Underwritten by Hiscox. The schedule is published, not described.

Read the licence →    See the insurance schedule →

Do not take our word for it

Test it on your own devices

Have your supplier run 100 devices through its current tooling and keep the results. Then have them run the same 100 through ours, free of charge. Same drives, same bench, same operator. You compare the evidence side by side and keep both sets either way.

Arrange the test →    Ask for the contract wording →