Applies to: All editions; report fields vary by edition
Separate four evidence questions
Defensible evidence should answer four different questions:
- Scope: Which files, folders, streams, and volumes were included?
- Configuration: Which method and supporting controls were active?
- Execution: Which stages completed or failed for each item?
- Assurance boundary: What locations and storage layers were outside CertErase’s control?
File fingerprints
The Certified Report will record SHA-256-based fingerprints for each item. For a large file, this value can be a partial fingerprint derived from sampled regions, including the beginning and end of the file, rather than a hash of every byte.
Verification fields
Interpret verification fields with the configured profile:
- Per-pass verification enabled: all configured passes are intended to receive logical read-back comparison.
- Profile-forced final verification: only the final pass may have been verified.
- Verification disabled: successful writing and deletion were reported without logical read-back comparison.
Timestamps
Use UTC timestamps for cross-system correlation. Confirm that the workstation clock was synchronized. Application timestamps document software-observed events; they do not independently prove who was physically present or who authorized the operation.
Device and environment information
Machine and operating-system details help establish context.
