Most of what passes for data destruction inside an organization removes the pointer to the data and leaves the data itself sitting on the platter. The gap between those two things is where breach notifications come from.
A quick format rewrites the file table, not the blocks. Free recovery tools pull the contents back in minutes.
Reliable on a modern encrypted phone, unreliable on everything else. On many devices it clears the profile and nothing underneath it.
Wear levelling means a multi-pass overwrite never reaches the spare blocks. Flash needs a purge command or destruction, not a scrub.
A hole through the casing leaves most of the platter readable, and leaves you with no record that anything happened at all.
The failure mode is rarely the technique. It's the missing paperwork: no serial list, no method on record, no signature. If you can't evidence destruction, you can't evidence it didn't leak.
NIST SP 800-88 Rev. 1 draws the line between Clear, Purge and Destroy. We pick per media type and per your risk appetite, and the method we used goes on the certificate against the serial number.
Every data-bearing device we receive is sanitized in line with NIST SP 800-88 Rev. 1 under our R2v3-certified Appendix B process, and the result is verified before the asset moves on. Every pass is verified by re-read, and a drive that fails verification is never given a second chance — it's rerouted to physical destruction.
On self-encrypting drives and modern encrypted endpoints, destroying the key destroys the data. Fast, verifiable, and the only sound approach on flash that was encrypted from first use.
Media that cannot be verifiably sanitized — failed drives, damaged media, and anything you designate as destroy-only — is physically destroyed by a certified destruction partner inside our audited downstream chain, under documented custody from your dock to the shredder. The shredded material stays in the recycling stream — destroyed, then recovered, never landfilled.
Sanitized or shredded, the output is the same document set: a serialized Certificate of Data Destruction, a chain-of-custody record, and a disposition line you can reconcile against your asset register.
If it stores a byte, it goes on the inventory. Below is how each class is normally treated — your policy overrides ours on any line.
| Media | Default method | Why |
|---|---|---|
| Hard disk drives (HDD) | Purge, or shred on request | Overwrite reaches every addressable block on magnetic media and the drive keeps its resale value. |
| SSD, NVMe and M.2 | Cryptographic erase or sanitize command | Wear levelling hides spare blocks from an overwrite. Flash needs a firmware-level purge. |
| Phones and tablets | Purge, with lock and activation checks | Encrypted by default, so key destruction plus a verified factory state clears the device. |
| Laptops, desktops and workstations | Purge in place, drive pulled on request | Keeps the machine whole and remarketable, which is where your return comes from. |
| Servers, RAID arrays and SAN | Per-drive purge after array break-down | Controller-level wipes miss drives that dropped out of the array before you retired it. |
| Backup tape (LTO, DLT) | Destroy | Sequential media can't be verified block by block, and tape rarely has residual value. |
| USB sticks, SD and CF cards | Destroy | Low value, high risk, and controller quirks make verification unreliable at volume. |
| Optical discs | Destroy | Write-once media cannot be overwritten at all. |
| Printers, MFPs and network gear | Purge of the internal drive or NVRAM | The forgotten category. Copiers hold years of scanned documents on an internal disk. |
A certificate is only worth the custody record behind it. Here's the record you get.
We agree the media list, the method per class, and the reporting format before anything moves. Mutual NDA signed first if you want one.
Containers and tamper-evident seals arrive ahead of collection. Seal numbers are logged against your job at the point they're closed.
Freight is booked and paid by us, tracked end to end, and released only against a signed manifest. You keep a copy at the dock.
Seals are checked, every asset is scanned into our system by serial, and the received list is reconciled against your manifest. Discrepancies are raised the same day.
Each asset is processed by its agreed method and the result recorded against its serial. Anything that fails sanitization is rerouted to destruction, not retried.
You receive the Certificate of Data Destruction and the disposition report. Anything remarketed is settled at the price we quoted per grade.
Auditors don't accept a logo on a letterhead. Ours is a line-per-asset document you can hand straight to a reviewer.
Delivered as a signed PDF with the underlying data in CSV, so it drops into your asset register without retyping.
Media disposal sits inside almost every framework your organization reports against. We don't make you compliant — your policy does that. We give you the artifacts the policy requires.
Disposal and media re-use safeguards for protected health information, evidenced per device rather than per shipment.
Proper disposal of consumer and financial records, including the disposal rule's demand for a documented, reasonable measure.
Student records on retired one-to-one devices, handled with the same serial-level record as enterprise hardware.
Rendering cardholder data unrecoverable when media is retired, with the destruction method recorded for your QSA.
Erasure and storage-limitation obligations, supported by proof of when personal data stopped existing and how.
Asset disposal that reconciles line for line with the fixed asset register, so the write-off stands up in review.
Underpinning all of it: NIST SP 800-88 Rev. 1, the media sanitization guidance nearly every US framework points back to, applied under our audited R2v3 process.
Gizmogul is certified to The Sustainable Electronics Reuse & Recycling (R2) Standard v3 by Perry Johnson Registrars, Inc. (PJR) under certificate C2026-04479, covering our Canton, Massachusetts facility.
The part that matters for data destruction is the scope. Ours explicitly covers logical data sanitization and downstream vendor management — meaning both the work we do ourselves and the partners who destroy what we can't sanitize are inside the audit, and get re-audited every year.
Also certified to the Recycling Industry Operating Standard (RIOS), Rev. 2016 (certificate C2026-04480), covering our quality, environmental, and health & safety management systems.
Plenty of vendors shred everything, because shredding is the easy thing to charge for. A shredded drive is a cost line. A sanitized one is a credit.
We'll tell you which side of the line your inventory falls on before you commit, even when the answer costs us the shredding fee. Reuse first, responsible recycling second, landfill never.