Certified Data Sanitization Reports

Applies to: Enterprise and Audit

Purpose

The certified data sanitization report provides an expanded, formal record of a DriveErase operation. It is intended for enterprise asset-disposition, internal assurance, customer evidence, compliance review, and audit workflows.

Report content

Depending on the operation, the report can include:

  • Report date and document type;
  • DriveErase version information;
  • System and operating-environment information;
  • Host hardware identifiers;
  • Job and execution timestamps;
  • Device model, serial, capacity, interface, path, and media classification;
  • Pre-erasure SMART information;
  • Selected sanitization approach and method;
  • Potential and actual compliance statements;
  • Overwrite coverage, pass, flush, failed-range, and verification evidence;
  • Firmware command mode and result;
  • Fallback route, when used;
  • Post-erasure health method, evidence, score, and grade;
  • Final result statement;
  • Date, name, signature, or attestation fields used by the organization.

Compliance statement

The report distinguishes the method that was requested from the result that was actually established. A standards-related statement applies only where the Compliance field records it positively.

A profile name, potential-compliance label, successful job container, or completed fallback is not a substitute for the actual compliance field.

Attestation

Blank or completed attestation fields support the organization’s approval process. A handwritten or electronic operator signature attests to the organization’s statement; it does not alter the technical evidence recorded by DriveErase.

Certified reports generated using the Audit edition are digitally signed by DriveErase.

Review before release

Before attaching the report to an asset disposition:

  1. Confirm every device identity;
  2. Confirm the actual erasure status;
  3. Review verification and failed-range evidence;
  4. Review the actual compliance field;
  5. Review health results separately;
  6. Complete organizational custody and attestation fields;
  7. Retain the report under the approved evidence policy.