Applies to: Pro, Enterprise and Audit
Purpose
File identity controls reduce the persistence of the original name and ordinary file timestamps in the live directory entry before deletion. They do not guarantee removal of all historical metadata copies.
Rename before deletion
When enabled, CertErase repeatedly assigns a generated name before processing completes. Configure the rename count according to the approved procedure. The default is three rename cycles, although a sanitization profile can apply a different count.
Repeated renaming can make the original name less visible in ordinary file-system views, but the benefit depends on file-system behavior. Journals, indexes, shadow copies, backups, logs, and forensic remnants can retain older names.
Randomize the extension
When enabled, CertErase assigns a randomized three-character extension during the identity-change stage. This reduces the visibility of the original file type in the active directory entry. It does not alter content already copied elsewhere or guarantee removal of file signatures from overwritten or retained data.
Scrub timestamps and basic metadata
When enabled, CertErase attempts to set creation, last-access, and last-write times to a fixed early timestamp and sets ordinary file attributes to a normal state. The operation is best effort and can be constrained by file-system semantics, permissions, locks, security software, and remote storage behavior.
Configure the controls
- Enable Rename before deleting in the File Identity Metadata area of Settings.
- Set the approved rename count.
- Enable Randomize file extension when required.
- Enable Scrub timestamps and metadata when required.
- Test against representative files and file systems.
- Review logs for item-level failures.
