Whether a drive is heading for resale, being decommissioned, or has already given up everything it stored, what is on it still has to disappear for good — and disappear provably. Using the very forensic-grade equipment we recover data with, turned to the opposite purpose, we wipe hard drives and SSDs: each sector is overwritten, the outcome is verified, and a certificate follows. What returns is a blank, reusable drive; what never returns is the data.
We read every drive back once it’s been overwritten — confirmation that nothing recoverable survives has to be in hand before any certificate leaves the lab.
Reformatting a drive or dragging files to the bin does nothing to the data itself — it stays put on the platters, ready for a lab like ours to lift straight back off. A forensic wipe is a different animal: it overwrites every addressable sector on the drive and then runs a verification pass to prove nothing legible slipped through. Picture the recovery gear and software we use every day, simply turned against the data rather than for it. The work follows NIST 800-88, the accepted yardstick for media sanitisation, which draws a line between Clear — a single overwrite pass, enough to beat any software-level recovery — and Purge, a controller-level erase that stops even a lab. One verified pass settles any drive built this century; the thirty-five-pass routine was a cure for 1990s platter densities and nothing since. When it wraps up, the drive reads clean, holds nothing, and won’t come back — not for us, and not for anyone holding the same equipment.
The two media types part ways right here. Overwrite a spinning hard drive and, once it’s verified, the magnetic data really is replaced and gone. SSDs and flash are where things turn slippery: their controllers scatter data across spare cells and quietly remap blocks out of view, so a blunt surface overwrite can sail straight past whole regions — a drive that looks wiped while it isn’t. That is why solid-state drives take a controller-level secure erase or a cryptographic erase in place of a surface pass, clearing both the mapping table and the cells the drive genuinely uses. A secure erase fires the drive’s own ATA Secure Erase or NVMe Sanitize command and blanks every cell the controller manages, spares included; a cryptographic erase instead destroys the internal media-encryption key, so the ciphertext left behind in the NAND is unreadable in an instant. Choosing the right method for the device in front of you is the whole of the job — get that wrong and ‘destroyed’ data resurfaces on a resold laptop.
The work almost always traces back to one of a handful of situations: hardware being retired — drives, servers or laptops that fall under GDPR and have to be shown as wiped; equipment on its way out for resale, donation or recycling; a business clearing down material at the close of a project; or a drive that arrived for recovery and now has to leave permanently dead. Whichever it is, every drive departs with a certificate of erasure logging its serial, the method and the date — the paperwork your records and your auditors will look for. Where magnetic media can’t take an in-place overwrite, the fallback is degaussing: a field strong enough to saturate the platter and wipe its servo tracks, which clears the drive but also kills it for good. A verified erasure, by contrast, leaves the hardware alive — cheaper and greener than shredding, with the data left every bit as unrecoverable — and where a client truly needs the media physically shredded or destroyed, we’ll steer them to the right route. It is the exact counterpart of our forensic recovery service: the very same bench, worked from the opposite end.
On a hard drive, yes — a verified overwrite writes over the data and nothing remains beneath it to retrieve. For an SSD we run the controller’s own secure-erase in place of a surface pass; either way, the drive is read back and confirmed to hold zero recoverable data before any certificate goes out. We will not certify what we have not verified.
Yes. Each drive comes with a certificate of erasure recording its serial, the method applied and the date — exactly the documentation a data-protection audit looks for once hardware is decommissioned.
Sometimes. Where the drive can be coaxed up far enough to erase, we do it and verify the result. Where the mechanics or electronics are too far gone to wipe safely in place, an overwrite is off the table and the honest option is to destroy the media physically — we will tell you which case applies and why, rather than hand over a certificate we cannot stand behind.