Applies to: All editions
Is CertErase a whole-drive sanitization product?
CertErase is primarily a file-level logical erasure product with optional free-space wiping. It does not replace device firmware sanitize commands, cryptographic erase, or physical destruction where those techniques are required. For whole-drive sanitization, Probativa DriveErase should be used instead.
Does selecting a NIST/IEEE-labelled profile make an operation NIST/IEEE compliant?
No. The profile configures software overwrite recipes aligned with NIST SP 800-88/IEEE 2883-2022. A NIST SP 800-88/IEEE 2883-2022-compliant sanitization program also requires risk-based selection, media suitability, verification, validation, documentation, governance, and an approved disposition decision.
Is one pass enough?
The correct technique depends on media, data sensitivity, threat model, and policy. Additional passes do not solve inaccessible sectors, flash translation, snapshots, backups, or external copies. Use current organizational guidance rather than a universal pass-count rule.
Does CertErase delete a file if overwrite fails?
CertErase requests deletion only after the overwrite stage reports success. A failed item may already have been partially modified and must be handled as unresolved.
What does verification check?
Verification reads logical file data back and compares it with the expected overwrite pattern. It does not inspect inaccessible physical pages or external copies.
Are NTFS alternate data streams included automatically?
They are processed only when the advanced alternate-stream control is enabled and available under the active edition.
Will free-space wiping make the drive look full?
Yes. Temporary data occupies free space during the operation. The application leaves a reserve, then removes its temporary files. A restart can be required before the system drive reports all space as available.
Can I use CertErase in a virtual machine?
Virtual-machine use requires Enterprise or Audit editions. Guest-level overwrite remains subject to snapshots, virtual disks, host storage, and provider controls.
Can I use CertErase on Windows Server?
Windows Server use requires Enterprise or Audit editions. Server deployment requires additional maintenance, replication, backup, and service-locking precautions.
Does the report contain a full SHA-256 hash of every file?
Not necessarily. The Enterprise and Audit report can use a partial SHA-256 fingerprint for large files. Treat it as a correlation fingerprint, not automatically as a complete content hash.
Are the Enterprise edition reports digitally signed?
CertErase Enterprise reports include structured content and sign-off fields but do not add cryptographic digital signatures. Use the Audit edition when issuing cryptographic digitally signed reports is required by your organization.
Are the Audit edition reports digitally signed?
Yes, reports generated using CertErase Audit include cryptographic digital signatures.
Can CertErase remove backups or cloud copies?
No. Those copies must be addressed through the backup, synchronization, storage, or cloud platform that controls them.
What should I retain after an operation?
Retain the authorization, approved target manifest, effective settings, raw output, required exported report, reviewer disposition, unresolved-item record, and evidence-integrity identifier according to organizational policy.
