Add CertErase to Windows Explorer

Applies to: All editions; saving current settings as defaults requires Pro, Enterprise or Audit

Purpose

Windows Explorer integration adds an Erase with CertErase command for file-system objects. It is designed for operator convenience, not unattended policy enforcement.

Install the integration

  1. Open CertErase under the Windows user who will use the context-menu command.
  2. Open the Integration tab.
  3. Select Add to install or enable Explorer integration.
  4. Confirm the result message.
  5. In Windows Explorer, right-click a disposable test file and confirm that Erase with CertErase appears.

CertErase registers the Windows Explorer command for the current Windows user. Other users on the same machine must enable the integration separately.

Use the Explorer command

  1. Select one or more approved files or folders in Windows Explorer.
  2. Right-click the selection.
  3. Select Erase with CertErase.
  4. Confirm that CertErase receives the intended targets.
  5. Review the effective default settings and operation output.

Windows Explorer selections are queued into a single running CertErase instance, and multiple selected items are supported. Explorer integration can use saved defaults and may not show the same preparation sequence as a manually assembled session. Review the active defaults before starting the erasure.

Default settings

Explorer-launched operations use the application’s saved default configuration. Pro, Enterprise and Audit can save the current settings as defaults. Before enabling Explorer integration in production:

  • Establish an approved default profile;
  • Decide whether verification is required;
  • Decide whether alternate data streams and metadata controls are required;
  • Confirm that free-space wiping is not unintentionally enabled for routine context-menu operations;
  • Test the warning and confirmation behavior;

Remove the integration

Use the Integration tab’s Remove command. Confirm that the context-menu entry disappears for the current user. In managed environments, administrators should also verify the relevant per-user registration state.

Security considerations

Explorer integration lowers the number of steps between selection and destruction. Restrict it to trained users, avoid ambiguous default settings, and do not deploy it as a substitute for authorization or review.