Destruction standards
| Standard | What it is | How we apply it |
|---|---|---|
| NIST 800-88 Rev. 1 | The US federal guideline for media sanitisation, defining clear, purge and destroy methods. | Software sanitisation is performed to NIST 800-88 with verification reporting per device. |
| DoD 5220.22-M | A multi-pass overwriting specification originating from US Department of Defense industrial security guidance. | Applied where a client’s internal policy specifically requires multi-pass overwriting. |
| Physical destruction | Reduction of media to particles small enough that reconstruction is not feasible. | Used for failed drives, end-of-life media and where policy mandates destruction over sanitisation. |
Regulatory frameworks we support
These obligations rest with your organisation. Our processing and documentation are designed to produce the evidence those obligations require.
HIPAA
Health Insurance Portability and Accountability Act. Certified destruction of equipment that may contain protected health information, with per-asset evidence.
FERPA
Family Educational Rights and Privacy Act. Destruction of student-data-bearing devices before reuse, resale or recycling decisions are executed.
GLBA
Gramm-Leach-Bliley Act. Documented sanitisation and destruction of financial data-bearing storage media.
PCI DSS
Payment card industry requirements around the secure destruction of media holding cardholder data.
State e-waste regulation
Requirements vary by state; our R2v3-governed process is designed to meet the strictest applicable rather than the local minimum.
Federal e-waste and hazardous waste rules
Handling of batteries, mercury-containing devices and CRT material under applicable environmental regulation.
Environmental and recycling standards
R2v3
Governs responsible reuse and recycling, including data security, environmental controls and downstream accountability.
ISO 14001:2015
Certified environmental management system covering pollution prevention and controlled waste handling.
Zero-landfill policy
No processed material is sent to landfill. Streams are separated and moved to vetted downstream processors.
Chain-of-custody requirements we hold ourselves to
- Custody is recorded at every transfer point, not reconstructed afterwards
- Serial-level identification precedes any processing decision
- Data-bearing devices are sanitised or destroyed before reuse assessment is acted on
- Documentation issued references the same serial numbers the client verified
- Downstream processors must meet defined environmental and safety criteria
Working to a standard we have not listed?
Tell us the framework or the clause in your policy. We will confirm whether our process meets it before you commit to anything.
Scoped and quoted in one call
Collection dates confirmed in writing
Certificates issued as standard
Replies within one business day