A drive’s data needs to be destroyed after you have finished using it, either to sell it or because it’s reached end-of-life. Once the data is gone from the drive, it’s gone forever. Our team destroys data from hard drives and solid state disks (SSDs) using the same forensic-grade equipment and software that we use to recover data from them. This process involves overwriting each sector on the drive, running a verification check to ensure that no recoverable data remains and issuing a certificate of destruction. After this process is complete, the drive will report as being completely blank and ready for reuse. The data however will never again exist. With our offices based in Bristol we provide data wiping services and hard drive shredding Bristol-wide for businesses. For secure HDD destruction Bristol businesses can rely on, we offer a variety of methods including physical shredding, degaussing and a certificate of destruction for your records.
All drives are written-over prior to running a verify check to confirm there is zero recoverable data prior to providing you with a certificate of destruction.
The type of wipe described above should not be confused with the “quick format” or “dragged-to-bin delete.” These actions do not remove the data stored on the platter where the original files were stored. Instead they merely hide the file locations. Any competent forensics lab (like ours) can easily recover deleted information from these types of wipes. A true wipe uses forensic erasure, which overwrites every addressable sector on the drive, followed by a verification test to confirm that none of the sectors contain any readable data. A true wipe utilises identical equipment and software as used for recovery, but points them in the opposite direction. True wipes follow the most commonly accepted standard of NIST 800-88 for media sanitisation. Once done, the drive reports clean, holds nothing, and cannot be brought back by us or anyone with the same kit.
On a spinning hard drive, a verified overwrite genuinely erases; the magnetic data is replaced and gone. SSDs and flash may appear to be securely erased with a simple overwrite because they scatter data into “spare” cells on the storage media. But this data remains and can still be recovered if the “blocks” are simply remapped by the drive’s controller. This is why secure erase commands at the controller level and cryptographic erase methods are used to clear the mapping information and truly erase data on solid-state drives. The problem lies in knowing whether your device has the capability for a controller level secure erase/cryptographic erase or whether a surface overwrite will suffice. Using the wrong method of erasure is how a user believes they’ve destroyed sensitive data but finds it intact when a resold computer is opened.
These types of projects generally fall within one of several categories: drives/servers/laptops are being retired and need to be cleared in accordance with GDPR; equipment intended for resale, donation or recycling; a business wishing to dispose of project related materials; or a drive was brought to us for recovery purposes and now needs to be made completely unusable. A certificate of erasure is generated for each drive, including serial number, method and date of erasure, for both auditing and record keeping purposes. Verified erasures allow the drive to remain functional thus saving money and reducing environmental impact over physical shredding of the drive, while the data is just as unrecoverable; however, if a client requires physical destruction/shredding of the media we will provide guidance on the appropriate procedure. This process is essentially the inverse of our forensic recovery services, two sides of the same coin.
Yes. For hard disk drives (HDDs), once you perform a verified overwrite, all data is deleted; there is no data left to recover. For SSDs, we utilise the controller’s built-in secure-erase feature instead of performing a surface pass. Regardless of the method utilised, prior to issuing a certificate of erasure, we verify through a read operation that there is zero recoverable data. We do NOT issue certificates for something that we HAVE NOT VERIFIED.
Yes. We document every hard drive that has been removed from service. Each certificate includes information on the hard drive (serial number) and details on how it was erased (method), as well as when it was done (date). This is what an auditor wants to see for evidence that this device has been properly disposed of.
Not always. If the device can be made functional enough to do an erase/overwrite, then we will do it, verify it and issue a certificate accordingly. However, if there is damage to the electronic components, or the mechanical aspect of the hard drive makes it unsafe to perform the erase/write process in situ, then an overwrite is not safe and the media should be physically destroyed; we will let you know which and why, rather than issuing a certification that we would not sign ourselves.