FAQ
Data sanitization: frequently asked questions
Straight answers about methods, standards and evidence — including the questions where the honest answer is “that is the wrong question”.
Are you NIST certified? Are you IEEE certified?
No — and neither is anyone else, because NIST and IEEE do not certify products. We implement NIST SP 800-88r2 and IEEE 2883-2022. Bodies that do certify, such as ADISA, are a separate question, and we only claim certifications we actually hold.
How many overwrite passes do you do?
That is the wrong question, and the reason is short: passes only touch addressable space. NIST SP 800-88r2 explicitly says multi-pass overwrite is not needed, and notes that DoD dropped its overwrite specification in 2006. For a real Purge we issue the drive’s own sanitize command, which reaches areas no number of passes can.
Do you support DoD 5220.22-M?
Yes, because customers still ask for it by name. We label it as legacy and certify the outcome as a Clear, because that is what it is. NIST SP 800-88r2 specifically counters the DoD multi-pass language.
What is the difference between Clear and Purge?
Clear protects against someone reading the drive through its normal interface. Purge protects against a laboratory opening the drive up, and covers areas Clear cannot reach — retired sectors, over-provisioning and caches.
Which one should we use?
Purge, wherever the drive supports it. Both NIST SP 800-88r2 §3.1.2 and IEEE 2883 §5.5 recommend Purge over Destroy for sustainability reasons, because the drive stays resellable. Purge also satisfies any requirement written for Clear — IEEE 2883 §5.3 says a stronger method always conforms.
Can you sanitize an SSD properly?
Yes, via the drive’s native sanitize or cryptographic-erase command. What we will not do is overwrite an SSD and call it a Purge. Over-provisioned cells are unreachable from the host interface, and NIST SP 800-88r2 says overwriting flash achieves very little confidentiality protection.
What if a drive is locked or encrypted?
We detect SED / TCG Opal, BitLocker and LUKS, and provide legitimate unlock paths — recovery key, passphrase, PSID revert. Where a TCG Locking SP is owned we automatically use the cryptographic-erase path, as the standard requires.
What if the wipe fails?
It is reported as failed. We do not downgrade to a weaker method to make it pass. If no purge technique works, the certificate states that the destroy method is required.
Can an auditor verify your certificate without trusting you?
Yes. Each certificate is signed on the device with an Ed25519 key whose private half never leaves the machine, over canonical JSON of the exact facts. The public key and signature go to the portal, and there is a public verification page. Changing one character invalidates the signature.
Do you work offline or air-gapped?
Yes. Sanitization, verification, signing and PDF generation all run locally. The cloud portal is an asynchronous replica, not a dependency.
What standards does the certificate cite?
The method achieved (Clear or Purge), the specific technique that ran, the verification performed and its basis, and the validation decision — worded as “NIST SP 800-88r2 Purge · IEEE 2883-2022 Purge”.
Which media types are supported?
ATA, SCSI/SAS and NVMe. eMMC and UFS are not supported today: those devices have no native purge path in our software, so only a host overwrite is possible, which is a Clear.