Hardware Services · ITAD
How we deliver certified data erasure
This page exists because security-review teams keep asking the same eight questions before approving a disposal project — so here are the answers, in writing, before you have to ask.
The short version
- Software erasure runs on Blancco Drive Eraser, with a digitally signed, tamper-proof report per drive.
- Standards set to match your policy — NIST 800-88 Clear/Purge, DoD 5220.22-M, HMG Infosec Standard 5, 25+ supported; the one executed is recorded on each drive's report.
- Erasure happens on your site or at our facility — your choice, fixed in the SOW, chain of custody either way.
- A drive that fails erasure is physically destroyed and certified as such. It never re-enters recycling.
Security review
The eight questions, answered
Written to be forwarded to your security or compliance team as-is. Every claim below is verifiable on the per-device report or in the SOW.
01
At what stage is the data erased — on site, or after transport?
Both models are available, and you choose during scoping — the choice is written into the SOW before any device is moved.
Off-site (standard managed flow)
Drives are inventoried, tagged and sealed into locked security bins on your premises, transported with chain-of-custody documentation, then erased at our processing facility. No device is unaccounted for at any point — this is the published 10-step ITAD process.
On-site, before collection
When your policy requires that readable data never leaves the premises, we erase — or physically destroy (HDD punch/drill) — storage media on site, with per-device photo evidence, before anything is packed for transport.
02
Which data erasure standard do you use?
Software erasure runs on Blancco Drive Eraser. The standard is set per engagement to match your policy: NIST 800-88 (Clear, or Purge where the drive's firmware supports it), DoD 5220.22-M / ECE, HMG Infosec Standard 5, and 25+ other published standards including IEEE 2883-2022 — the full list is on our ITAD page.
The standard actually executed is recorded per device on the erasure report — your auditors see which method ran against which serial number, not a blanket claim. The masked sample report further down this page shows the exact field. Blancco's NIST 800-88 implementation is Compliance Verified by ADISA for both HDDs and SSDs.
03
How do you erase SSDs and NVMe drives?
Flash media can't be treated like spinning disk, so SSDs and NVMe drives are processed with Blancco's patented SSD erasure method (US Patent 9,286,231), which combines exactly the mechanisms security reviews ask about:
Firmware-level sanitisation
Device Sanitize commands and cryptographic erase are issued where the drive's firmware supports them — reaching NIST 800-88 Purge level on drives that support Sanitize.
Overwriting
Multiple random overwrites across the drive's full logical capacity, with freeze-lock removal so locked drives can't silently skip the pass.
Full verification
Every erasure is verified before the report is issued; the mechanism that actually ran on each drive is recorded on that drive's report.
A drive whose firmware cannot complete a verified erasure is not given the benefit of the doubt — it is physically destroyed instead (see the failed-drive question below).
04
Which Blancco product and version do you use?
Blancco Drive Eraser, licensed per project — we procure current-release licences when a project is scoped rather than holding old licence stock. Recent engagements have run current 7.x releases; the masked sample report below was produced by Drive Eraser 7.13.0 on a June 2025 run.
The exact software version used is stamped on every per-device erasure report, and we state it in your SOW on request — version information reaches you as verifiable evidence on the report, not as a claim in an email.
05
If physical destruction is used, what is the final shred particle size?
Four physical destruction methods are available, chosen per media type and policy: on-site HDD punch/drill, certified degaussing, SSD/HDD bending, and industrial shredding through a certified destruction partner.
We won't quote a particle size in millimetres on a marketing page: shredding runs on the certified partner's equipment, so the final particle size depends on the machine assigned to your batch. It is specified in the SOW up front and stated on the destruction certificate. If your policy mandates a maximum particle size, name it during scoping — we either meet it, or tell you before work starts.
06
What happens to a drive that fails the erasure process?
It never re-enters the recycling or resale stream. Every batch passes a report-QA step in which the Blancco results are reviewed for missing or failed devices. Any drive that fails erasure — or whose verification cannot complete — is routed to physical destruction (punch/drill, bend or shred, as agreed in the SOW).
The destroyed drive appears on the final Certificate of Disposal with its serial number and destruction method, backed by the same photo/video evidence taken for all physically destroyed media.
07
What certificates will we receive — and can we see samples?
Four documents, depending on what your project includes:
Per-device Blancco erasure report
Digitally signed and tamper-proof: serial number, erasure standard and mechanism, verification result, timestamp and software version.
Per-device Destruction Certificate
For physically destroyed media: serial number, asset tag, device type, method, date and certificate reference.
Certificate of Disposal + comprehensive report
The batch-level summary listing every asset and its outcome — written to stand up in ISO 27001 audits and regulatory reviews.
Recycling certificate
Issued through the certified e-waste partner where the project includes recycling — zero landfill.
Sample documents (Data Destruction Certificate, Recycling Certificate) are available on request — and a masked report from a real erasure run is shown just below, so you can see the format before you ask.
08
How is the service priced?
ITAD is quoted per project against a signed SOW — there is no honest per-drive list price, because the cost drivers are logistical. What moves the quote:
Devices
Quantity, dimensions and weight — they set the vehicle, labour hours and packing materials.
Sites
Location(s), site access requirements, and whether DC conditions must be restored.
Methods & tools
Which erasure and destruction methods your policy requires — Blancco licences, degauss equipment, bending, certified shredding.
Evidence depth
Inventory and audit requirements, certificate formats, photo/video evidence.
Schedule
Business hours vs. overtime / non-business-hours work, and the project deadline.
Evidence
What the erasure report actually looks like
A real Blancco report from one of our erasure runs — serial numbers, identifiers and the signature are masked, nothing else is changed. Every drive we process produces one of these.
Blancco Drive Eraser 7.13.0
Sample — serials, identifiers and signature masked
2025-06-16 03:53:05 (+0000) · HP ELITEBOOK 840 G6 · S/N 5CG0••••••
Data Erasure Report
Erasure Results
Disk: 1 · SK hynix PC601 512GB
Serial: AS01N6••••••••••
Bus: NVMe · Sectors: 1,000,215,216
Health: Good
Start/End: 03:40:54 → 03:52:21
Duration: 00:11:27
Method: HMG Infosec Standard 5, Lower Standard · Rounds: 1 (1 overwrite)
Status: ✓ Erased
Hardware Details (excerpt)
Intel Core i7-8665U · 16GB DDR4 · BIOS R70 01.08.01 · TPM 2.0 (Infineon) · Asset tag ••••••
Report Details
Report UUID: 0126abbe-••••-••••-••••-••••••••••••
Software Version: Blancco Drive Eraser 7.13.0
Digital Signature: HdLRMdpgT68lxO7pw•••••••••••••••••••••••••
Data Erasure Operator
Supervisor
Reports can be issued in English or Chinese.
Digital signature
Tamper-evident — the report can be verified, not just filed
Report UUID
Every report individually referenced
Method & rounds, per drive
The standard that actually ran, not a blanket claim
NVMe flagged
Flash media identified and handled per device
Full hardware inventory
Reconciles against your asset register — down to BIOS, TPM and asset tag
Dual sign-off
Operator and supervisor both sign the run
For magnetic disks and servers, the report also records HPA/DCO hidden-area checks and remapped-sector counts before and after erasure — a multi-disk machine is covered in a single report.
Ready for your security team's checklist?
Send us your device list and your policy requirements — you'll get a fixed quote and sample certificates, not a discovery call.