Applies to: Pro, Enterprise and Audit; some profiles can force limited verification
What verification does
Verification reads overwritten data back from the file and compares it with the expected pattern for the relevant pass. It tests whether the application can read back the bytes it requested to be written through the operating system’s logical file interface.
Enable verification
- On the Settings area, enable Verify overwrite after each pass.
- Confirm that the control remains selected and is available under the active edition.
- Run a test and review the per-item verification record.
Verification increases run time because each verified pass requires a read-back operation. The increase depends on file size, pass count, storage performance, and the number of targets.
Failure behavior
A failed pass verification receives one retry. If required verification still fails, CertErase marks the item as failed. Do not represent the item as successfully erased. The file may already be partially or fully overwritten, so a failed result does not mean that the original content remains intact.
Forced final-pass verification
Certain legacy profiles can force verification of the final pass. This is different from verifying every pass. Distinguish between:
- Verification disabled;
- Final pass verified because the profile requires it;
- Every pass verified because the operator selected full verification.
What verification proves
Verification supports the claim that expected data was readable through the same logical storage path immediately after writing. It does not prove that:
- Older physical pages do not remain inside an SSD or flash controller;
- Remapped or failed sectors were sanitized;
- Snapshots, backups, replicas, or caches were removed;
- A storage provider destroyed server-side copies;
- Deleted data is absent from external indexes, logs, or telemetry;
- The correct file was selected and authorized.
