Most of what passes for data destruction inside an organization removes the pointer to the data and leaves the data itself sitting on the platter. The gap between those two things is where breach notifications come from.
A quick format rewrites the file table, not the blocks. Free recovery tools pull the contents back in minutes.
Reliable on a modern encrypted phone, unreliable on everything else. On many devices it clears the profile and nothing underneath it.
Wear levelling means a multi-pass overwrite never reaches the spare blocks. Flash needs a purge command or destruction, not a scrub.
A hole through the casing leaves most of the platter readable, and leaves you with no record that anything happened at all.
The failure mode is rarely the technique. It's the missing paperwork: no serial list, no method on record, no signature. If you can't evidence destruction, you can't evidence it didn't leak.
NIST SP 800-88 Rev. 1 draws the line between Clear, Purge and Destroy. We pick per media type and per your risk appetite, and the method we used goes on the certificate against the serial number.
Every data-bearing device we receive is sanitized in line with NIST SP 800-88 Rev. 1 under our R2v3-certified Appendix B process, and the result is verified before the asset moves on. Every pass is verified by re-read, and a drive that fails verification is never given a second chance — it's rerouted to physical destruction.
On self-encrypting drives and modern encrypted endpoints, destroying the key destroys the data. Fast, verifiable, and the only sound approach on flash that was encrypted from first use.
Media that cannot be verifiably sanitized — failed drives, damaged media, and anything you designate as destroy-only — is physically destroyed by a certified destruction partner inside our audited downstream chain, under documented custody from your dock to the shredder. The shredded material stays in the recycling stream — destroyed, then recovered, never landfilled.
Sanitized or shredded, the output is the same document set: a serialized Certificate of Data Destruction, a chain-of-custody record, and a disposition line you can reconcile against your asset register.
A certificate is only worth the custody record behind it. Here's the record you get.
We agree the media list, the method per class, and the reporting format before anything moves. Mutual NDA signed first if you want one.
Containers and tamper-evident seals arrive ahead of collection. Seal numbers are logged against your job at the point they're closed.
Freight is booked and paid by us, tracked end to end, and released only against a signed manifest. You keep a copy at the dock.
Seals are checked, every asset is scanned into our system by serial, and the received list is reconciled against your manifest. Discrepancies are raised the same day.
Each asset is processed by its agreed method and the result recorded against its serial. Anything that fails sanitization is rerouted to destruction, not retried.
You receive the Certificate of Data Destruction and the disposition report. Anything remarketed is settled at the price we quoted per grade.
Auditors don't accept a logo on a letterhead. Ours is a line-per-asset document you can hand straight to a reviewer.
Delivered as a signed PDF with the underlying data in CSV, so it drops into your asset register without retyping.
Gizmogul is certified to The Sustainable Electronics Reuse & Recycling (R2) Standard v3 by Perry Johnson Registrars, Inc. (PJR) under certificate C2026-04479, covering our Canton, Massachusetts facility.
The part that matters for data destruction is the scope. Ours explicitly covers logical data sanitization and downstream vendor management — meaning both the work we do ourselves and the partners who destroy what we can't sanitize are inside the audit, and get re-audited every year.
Also certified to the Recycling Industry Operating Standard (RIOS), Rev. 2016 (certificate C2026-04480), covering our quality, environmental, and health & safety management systems.
Plenty of vendors shred everything, because shredding is the easy thing to charge for. A shredded drive is a cost line. A sanitized one is a credit.
We'll tell you which side of the line your inventory falls on before you commit, even when the answer costs us the shredding fee. Reuse first, responsible recycling second, landfill never.