How we handle your media, the standards we follow, what our certificates prove, and the documents your procurement team needs. Send this page to whoever has to sign off.
NIST SP 800-88, Guidelines for Media Sanitization, is the federal reference for getting data off storage media. It defines three levels, and we use all three.
For working hard drives. Every user-addressable sector is overwritten, then read back to verify. This is the default for HDDs and what makes drives reusable.
For SSDs and flash. Overwriting can miss flash cells, so we use the drive's built-in sanitize, secure-erase, or cryptographic-erase commands, then verify.
For failed drives, anything that can't be verified, and media your policy says must be destroyed. Documented with the same per-drive certificate.
Need DoD 5220.22-M multi-pass because a contract or policy names it? We'll run it, and your certificate will say so. Read our plain-English guide to NIST 800-88 →
The short version: from the moment we take custody until your certificate is issued, your media never leaves our control. Here's what that means in practice.
Every drive is logged by model and serial number the moment we take custody — at your site for pickups, or on arrival for mail-in. That intake list is what your final report reconciles against.
Business pickups are inventoried at your site and transported sealed, with a signed handoff. Your team is welcome to witness intake and sealing.
Media that holds your data never leaves EndByte's control until it has been sanitized or destroyed. There are no subcontracted wipes and no unlogged hand-offs in between.
Hard drives are overwritten; SSDs are sanitized with the drive's own firmware commands where supported. DoD 5220.22-M multi-pass is available when your policy requires it, and the certificate records whichever method was used.
A wipe isn't trusted until it's verified. Every sanitized drive gets a full read-back before it can earn a certificate.
Any drive that fails verification — or can't be verified — is physically destroyed and documented the same way. It is never returned or resold as “probably fine.”
Each certificate records the device model, serial, method, verification result, date, and operator. Batch jobs also get a report reconciling every serial received to its final disposition.
Verified working drives may be resold (that's what funds the free program). Destroyed material and anything that can't be reused goes to e-waste recycling — nothing is landfilled.
Most data-protection rules require you to dispose of media securely — and to be able to prove it. Our certificates are built to be that proof.
| Framework | What it expects at disposal | Learn more |
|---|---|---|
| HIPAA Security Rule45 CFR 164.310(d)(2) | Policies for the final disposal of ePHI and the hardware it lives on, and removal of ePHI before media is re-used. | Industry guide → |
| GLBA Safeguards Rule16 CFR 314.4(c)(6) | Secure disposal of customer information once it's no longer needed. | Industry guide → |
| FACTA Disposal Rule16 CFR Part 682 | Reasonable measures when disposing of consumer report information, including destroying or erasing electronic media. | Industry guide → |
| California customer records lawCal. Civ. Code § 1798.81 | Businesses must destroy customer records containing personal information — including by erasing — so they're unreadable. | Per-drive certificate + batch report |
| SOC 2Trust Services Criteria CC6.5 | Protections over physical assets are discontinued only after data on them can no longer be read or recovered. | Industry guide → |
| ISO/IEC 27001:2022Annex A 7.14 | Secure disposal or re-use of equipment: storage media is verified to be sanitized before disposal. | Industry guide → |
General information, not legal advice. Using EndByte doesn't by itself make an organization compliant with any framework — but it gives you the disposal records those frameworks ask for.
Onboarding us as a vendor? Here's what procurement usually asks for.
Exactly what you'll receive for every drive.
Download → ON REQUESTFor your accounts-payable setup.
Request by email → ON REQUESTIssued to your organization on request.
Request by email → ON REQUESTSend us your vendor questionnaire and we'll complete it.
Send it over →Anyone holding an EndByte certificate — you, your auditor, or the buyer of your old hardware — can confirm it's genuine by entering its number on our verification page.
Send them our way. Straight answers, usually the same day.