Publications

Briefings, submissions and the research record.

This is the material we have put in front of regulators, public bodies and partners. It is published here for the same reason the research is: a claim about evidence should come with the evidence attached.

The only company we can find anywhere in the world that warrants the outcome and guarantees permanent, irretrievable data destruction.

A new standard nobody has yet been able to match, backed by £10 million of professional indemnity insurance.

Documents

Published documents


Seven documents. Every one free, ungated, and readable without giving us an email address. Every figure in them comes from erasure logs, published standards, or answers given by public bodies on the record.

Comparison  ·  For ITADs, disposal operators and the buyers who audit them

Everybody asks for a comparison. This is the one that matters.

Same 95 drives. Same rigs. Same firmware. 399 hours as run, against 7 hours 16 minutes with the correct method chosen per device.

  • 88 of those 95 drives could have finished in seconds. Every one was overwritten for hours instead, because the method was chosen before the drive was ever looked at.
  • 331 slot-hours sat locked and idle, because an array cannot release a batch until its single slowest drive is done.
  • Five pages, one idea each. The distinction, the mechanism, the numbers, what the certificate is worth when it is tested, and how to prove or disprove the whole thing on your own kit.
  • September 2026
  • 5 pages
  • PDF, 226 KB
  • Free and ungated

Read the comparison (PDF, 226 KB, opens in a new tab) →

Method paper  ·  For technical reviewers, auditors and disposal operators

61 identical drives. 57 refused the same command.

Same model, same selected method, opposite outcomes. If identical model numbers do not respond the same way, you cannot know in advance what will erase the individual device.

  • The nine steps, in order. Interrogate the device, determine the correct method from it, seed a known marker before erasing, execute only that method, and pass two separate gates before anything is certified.
  • Why a status flag is not proof. A drive reporting that a command finished is a different claim from the data being gone, and only one of them can be warranted.
  • What has to be true before anyone can stand behind the word irretrievable, and why almost nobody in this market does.
  • September 2026
  • 4 pages
  • PDF, 164 KB
  • Free and ungated

Read the method paper (PDF, 164 KB, opens in a new tab) →

Technical briefing  ·  For technical reviewers, ITADs and data controllers

The wipe failed. The certificate says it passed.

The drive refuses the Purge in two seconds. The tool substitutes an overwrite, runs it for hours, and issues a certificate that reads Erased. Nothing on its face says the media-appropriate method never ran.

  • An NVMe drive drawn out, so you can see which part of the medium an overwrite reaches and which part it does not, with the device encryption key still live in the controller.
  • Fails open against fails closed, side by side, and why every current standard now answers that question the same way.
  • Why the exposure is cumulative. One ex-government laptop is a near-worthless target. An estate of them, assembled, is not.
  • September 2026
  • 11 pages
  • PDF, 570 KB
  • Free and ungated

Read the briefing (PDF, 570 KB, opens in a new tab) →

Research study  ·  For data controllers and disposal operators

1,036 requests. 437 bodies with nothing to show.

The Information Commissioner’s Office was asked whether a certificate of destruction demonstrates compliance. The answer set a condition: it may be sufficient “as long as you have ensured that the data has been destroyed effectively”. That question was then put to the UK public sector under the Freedom of Information Act.

  • 365 organisations named the supplier’s certificate as their only basis of assurance. Seven hold a warranty of the outcome.
  • The licence terms behind those certificates, quoted verbatim, with clause references and retrieval dates. Every one of them disclaims the destruction outcome.
  • What 247 peer bodies did about it. 241 moved to physical destruction and absorbed the cost of destroying working equipment. Six required the outcome to be warranted in the contract and kept theirs.
  • Second edition, September 2026
  • 12 pages
  • PDF, 362 KB
  • Free and ungated

Read the study (PDF, 362 KB, opens in a new tab) →

Adoption briefing  ·  For organisations that have already chosen a supplier

You do not have to re-run the tender.

You change the requirement, not the supplier. Mandating what a disposal supplier uses is neither new nor unusual, and what gets mandated today is usually a named product chosen on reputation, or an overwrite standard superseded years ago.

  • The outcome standard in three parts: proven, warranted, insured. Mandate the result rather than the tool, and any supplier who can meet it has met it.
  • Specification wording you can lift straight into a tender, which deliberately does not name us.
  • Four questions to put to any supplier, with an invitation to put the same four to us.
  • September 2026
  • 7 pages
  • PDF, 201 KB
  • Free and ungated

Read the briefing (PDF, 201 KB, opens in a new tab) →

Adoption briefing  ·  For ITADs and disposal operators

Your clients are about to ask you four questions.

And today no erasure licence on the market lets a disposal operator answer all four with the assurance the client is asking for.

  • Why method selection decides everything else, and why an overwrite that passes verification on flash can still leave the data in place.
  • The choice every ITAD is currently forced to make: shred and lose the asset, or erase and carry the risk on a certificate the underlying licence will not stand behind.
  • The commercial case for moving from process provider to evidence provider, and what changes when outcome liability sits with the vendor rather than the operator.
  • September 2026
  • 8 pages
  • PDF, 193 KB
  • Free and ungated

Read the briefing (PDF, 193 KB, opens in a new tab) →

Operator briefing  ·  For ITADs and data services operators

New cyber law. And your certificate is in scope.

The Cyber Security and Resilience Bill is in its final stages. It does not name IT asset disposal as a regulated trade, and this briefing does not pretend otherwise.

  • What it does do: gives regulated organisations stronger duties to manage cyber risk through their supply chains, which is where a disposal provider sits.
  • What that means in practice for the questions a regulated client will start putting to whoever destroys their data.
  • Where the duty already sits today, under obligations that are in force now rather than pending.
  • September 2026
  • PDF, 254 KB
  • Free and ungated

Read the briefing (PDF, 254 KB, opens in a new tab) →

In the meantime

The research is already published in full


The Freedom of Information study, all 1,036 requests and the 684 substantive answers behind it, is published on this site rather than gated. Every response is public and every reference is the authority’s own.

Read The Erasure Gap →    Read the assurance register →