Interpret CertErase Evidence, Fingerprints, and Verification

Applies to: All editions; report fields vary by edition

Separate four evidence questions

Defensible evidence should answer four different questions:

  1. Scope: Which files, folders, streams, and volumes were included?
  2. Configuration: Which method and supporting controls were active?
  3. Execution: Which stages completed or failed for each item?
  4. Assurance boundary: What locations and storage layers were outside CertErase’s control?

File fingerprints

The Certified Report will record SHA-256-based fingerprints for each item. For a large file, this value can be a partial fingerprint derived from sampled regions, including the beginning and end of the file, rather than a hash of every byte.

Verification fields

Interpret verification fields with the configured profile:

  • Per-pass verification enabled: all configured passes are intended to receive logical read-back comparison.
  • Profile-forced final verification: only the final pass may have been verified.
  • Verification disabled: successful writing and deletion were reported without logical read-back comparison.

Timestamps

Use UTC timestamps for cross-system correlation. Confirm that the workstation clock was synchronized. Application timestamps document software-observed events; they do not independently prove who was physically present or who authorized the operation.

Device and environment information

Machine and operating-system details help establish context.