Purpose
Use this page to understand what DriveErase does, how it differs from file deletion or formatting, and where each stage of the operation occurs.
What DriveErase sanitizes
DriveErase operates on complete physical storage devices exposed to Windows as physical disks. A selected job can include one or more eligible devices. Each device receives its own configuration and result record.
The selected operation is not limited to a partition, drive letter, folder, or file system. Overwrite-based methods process the device’s addressable logical range. Firmware-based methods request a supported sanitization operation from the storage device itself.
Formatting a volume, deleting partitions, reinstalling Windows, or removing file-system references is not equivalent to sanitizing the underlying device. Those actions can leave recoverable content in areas that were not overwritten or otherwise processed.
Operating model
A normal DriveErase workflow has two execution contexts:
- Windows application: detects devices, collects operator settings, performs preflight checks, creates the signed job, prepares the privileged environment, and requests the restart.
- Privileged Execution Environment: validates the job, identifies the intended devices, performs the configured pre-erasure check, sanitization method, and post-erasure assessment, and records the results.
This separation enables DriveErase to work without relying on the selected target volumes remaining mounted or available to the full Windows session.
Device-specific configuration
DriveErase classifies each detected device by available media and bus information. The application can recommend a default approach, but the operator remains responsible for confirming that the device identity and method are appropriate.
Typical defaults are:
- HDD and SAS HDD: overwrite-based sanitization;
- Directly attached SATA SSD: firmware-based sanitization with overwrite fallback in Pro or higher;
- Directly attached NVMe SSD: firmware-based sanitization with overwrite fallback in Pro or higher;
- Directly attached SAS SSD: firmware-based sanitization with overwrite fallback in Pro or higher;
- USB and removable flash media: overwrite-based sanitization.
Results and evidence
DriveErase records device identity, selected settings, execution timestamps, erasure status, verification information, and health results. Pro and higher editions can export normal reports. Enterprise and Audit editions can generate certified data sanitization reports. Audit additionally provides digitally signed reports and report validation and management.
Important assurance boundary
A successful result applies to the target and method recorded in the report. It does not automatically cover copies stored in backups, snapshots, replicas, caches, storage arrays, cloud services, or other devices. It also does not prove that hidden or controller-managed areas were processed unless the selected method and recorded evidence establish that scope.
