Use CertErase Sanitization Profiles

Applies to: Pro, Enterprise and Audit

Purpose

Sanitization profiles apply predefined combinations of an overwrite method and supporting controls. They provide repeatable configuration, but they do not replace media assessment, authorization, or validation.

Available sanitization profiles

Level 1 — Moderate

  • NIST-labelled single-pass overwrite
  • Advanced controls disabled

Use only where the organization accepts basic logical overwrite without read-back verification or metadata controls.

Level 2 — Elevated

  • NIST-labelled single-pass overwrite
  • Verify after each pass
  • Process alternate data streams
  • Rename before deletion three times
  • Randomize the extension
  • Scrub timestamps and basic metadata
  • No file-system metadata churn
  • No automatic free-space wipe

This profile adds verification and common NTFS residual-data controls while limiting volume-wide impact.

Level 3 — Severe

  • Level 2 controls
  • Rename before deletion five times
  • Enable best-effort file-system metadata churn

Use only after testing the time, temporary-file, and endpoint-security impact of metadata churn.

Level 4 — Extreme

  • Level 3 controls
  • Rename before deletion ten times
  • Wipe free space after deletion

This profile can consume substantial time and temporary disk capacity. It affects the entire selected volume’s addressable free space, not only the original file’s allocation.

Level 5 — Paranoid

  • NIST-labelled three-pass overwrite
  • Verify after each pass
  • Process alternate data streams
  • Enable best-effort file-system metadata churn
  • Rename before deletion fifty times
  • Randomize the extension
  • Scrub timestamps and basic metadata
  • Wipe free space after deletion

This profile is operationally intensive and should not be interpreted as universally superior. It increases writes and run time while remaining subject to the same storage-controller, snapshot, backup, and remote-copy limitations as other logical methods.

Apply a profile

  1. Add only disposable test targets during initial validation.
  2. Select the approved profile.
  3. Review every control that the profile changes.
  4. Confirm the target volume, available free space, and expected duration.
  5. Run a controlled test.
  6. Record the final effective settings in the procedure.

Do not rely on profile names alone

Reports should record the exact method, pass count, and enabled controls. A profile label can change between releases; evidential interpretation should be based on the recorded settings and product version.