Digitally Signed Reports in DriveErase Audit

Applies to: Audit

Purpose

DriveErase Audit digitally signs sanitization reports so that authorized recipients can validate their integrity and origin. The signature is applied to the report generated by the Audit workflow.

What the signature establishes

Successful validation can establish that:

  • The report was signed by the DriveErase Audit reporting process represented by the signing identity;
  • The signed content has not been modified after signing;
  • The file can be associated with its validation status and signing information.

What the signature does not establish

A valid signature does not, by itself, prove that:

  • The operator selected the correct physical asset;
  • The organization followed its custody procedure;
  • Every external copy of the data was removed;
  • A positive compliance result exists when the report states otherwise;
  • The device remained unchanged after the operation;
  • The organization satisfies every legal or regulatory obligation.

The signature protects the evidence document. The technical and procedural claims remain those recorded in the report.

Preserve the signed file

Do not edit, resave, print-to-PDF, merge, optimize, annotate, or otherwise transform the original signed report. Any content change can invalidate the signature.

Where notes or approval material must accompany the report, store them as separate linked records or use the approved SaaS management workflow without altering the original signed file.

Validation

The report can be validated using the supported DriveErase Audit validation workflow.

    Invalid signatures

    Quarantine an invalid or altered report. Obtain the original signed file from the authoritative repository and repeat validation. Do not repair or recreate the file and describe it as the original signed report.