Deleting and formatting both leave data recoverable with ordinary tools, which matters the moment hardware leaves your control. The right method depends entirely on the media — and in most cases the certificate listing serial numbers is the actual deliverable.
We read every drive back once it’s been overwritten — confirmation that nothing recoverable survives has to be in hand before any certificate leaves the lab.
If you are disposing of equipment that held personal data, UK GDPR makes you accountable for its destruction — and accountability means being able to demonstrate it, not merely having done it. A skip and good intentions do not constitute a defence.
What you need is a record: serial numbers of each device, the method applied, the date, and who carried it out. That is what a destruction certificate is for, and it is the reason this service exists as something separate from simply throwing hardware away.
We issue a certificate listing every device by serial number with the method used against each. If an auditor, a regulator or a client asks how you disposed of a machine holding their data, that document is the answer.
If the drive is going back into use inside your own organisation on the same network with the same trust boundary, a standard format is usually adequate. Certified destruction is for equipment leaving your control.
If the drive was full-disk encrypted throughout its life and you can demonstrate that, discarding the key is already cryptographic erasure. The data is unreadable and paying to overwrite ciphertext adds a certificate rather than security.
And if you are destroying a handful of old personal drives with nothing sensitive on them, a drill through the platters costs nothing. We would rather tell you that than take a fee for it.
Secure erasure and destruction is quoted per device, with volume rates for estate disposal. The certificate is included rather than charged as an extra, because a destruction service without documentation is not worth buying.
Collection can be arranged across the region for business quantities, with sealed transit and a signed manifest at both ends.
On any modern hard drive, yes. The multi-pass advice descends from 1990s recording densities and has no application to current drives. A single verified overwrite is not recoverable.
Wear levelling. The controller distributes writes across physical blocks and there is no way to address every one of them from outside. Cryptographic erase discards the key instead, which makes all blocks unreadable at once.
If the equipment held personal data and is leaving your control, you need to be able to demonstrate how it was disposed of. The certificate is that demonstration.
Yes, and physical destruction is the correct method for those. A drive that will not respond cannot be erased, so shredding or platter destruction is the only defensible route.
For business quantities across the region, yes, with sealed transit and a signed manifest at collection and delivery.
Witnessed destruction can be arranged by appointment. Some clients require it for their own compliance, and it is a reasonable thing to ask for.