Deleting a file and formatting a drive both leave the data sitting there. When hardware leaves your control the obligation follows it, so what matters is a method appropriate to the media — overwriting for hard drives, cryptographic erase for SSDs — and documentation you can hand to whoever asks.
We read every drive back once it’s been overwritten — confirmation that nothing recoverable survives has to be in hand before any certificate leaves the lab.
A deleted file stays on the disk until overwritten, and a quick format only rewrites the index. If a drive is leaving your control — sold, returned on lease, sent for disposal — neither is sufficient, and both leave data that ordinary recovery software will find.
Two legitimate methods, and which applies depends entirely on the media.
This is where a good deal of well-meant advice is out of date.
On a hard drive, every sector the controller exposes can be addressed and overwritten, so a verified overwrite genuinely removes the data. The old advice about seven or thirty-five passes derives from concerns about older, far lower recording densities and is no longer necessary — a single verified pass on modern media is accepted practice.
On an SSD, overwriting is unreliable for a different reason: wear levelling means the controller decides where writes physically land, and there are reserved and over-provisioned blocks the operating system cannot address at all. Data can survive in those. The correct method is the drive’s own cryptographic erase, which discards the key and makes the entire flash unreadable in seconds — faster, more complete, and less wearing on the drive.
Wiping is easy. Being able to prove it is the service.
Sold, donated, recycled or returned at the end of a lease — the point at which data protection obligations follow the hardware out of the door.
Personal data must not be kept longer than necessary, and secure disposal is part of demonstrating that you comply.
The awkward case — a drive that cannot be wiped because it no longer responds. Physical destruction with documentation is the answer here.
Many contracts require certified destruction with serial numbers recorded. A certificate is the deliverable, not the wipe itself.
Quoted before anything is destroyed, because it cannot be undone.
Secure destruction is priced per device and quoted on request — it depends on quantity, method and whether certification is required. We will confirm exactly what is being destroyed, by serial number, before starting.
One thing we will always ask: are you certain the data is not needed? Destruction is irreversible, and it is worth ten seconds of doubt now rather than a recovery enquiry afterwards. If there is any question, we will recover first and destroy second.
No. Deleting removes the index entry and a quick format rewrites it — in both cases the data stays on the disk and ordinary recovery software will find it. Secure destruction means overwriting every addressable sector, or crypto-erasing an SSD.
One verified pass is sufficient on modern hard drives. The seven and thirty-five pass patterns people cite come from concerns about far lower recording densities decades ago and serve no practical purpose today.
Not reliably. Wear levelling means the controller decides where writes land, and reserved and over-provisioned blocks cannot be addressed at all. The correct method is the drive’s own cryptographic erase, which discards the key and makes the flash unreadable instantly.
It cannot be wiped, because nothing can address it. Physical destruction with documented serial numbers is the appropriate route, and it is exactly the case where a certificate matters most.
Yes — recording serial numbers, method and date. That document is usually the actual deliverable, since it is what an auditor, insurer or client asks to see.
Priced per device and quoted on request, depending on quantity, method and certification. We confirm exactly what is being destroyed by serial number first, because it cannot be undone.