Retain and Protect Sanitization Evidence

Applies to: All editions; available report formats vary by edition

Preserve originals

Retain original exported and signed files in a controlled repository. Store transformed CSV data, screenshots, printed copies, summaries, and ticket excerpts as derivatives rather than replacements.

For Audit reports, preserve the original signed file byte-for-byte. Validate it at intake and again when evidence is presented for an audit or dispute.

Personal and sensitive information

Reports can contain serial numbers, host identifiers, user or operator information, timestamps, and infrastructure details. Classify and share them according to organizational security and privacy policy.

Retention period

The correct retention period depends on contractual, regulatory, audit, asset, warranty, and legal requirements. Define it in policy rather than deleting reports when the associated device leaves service.

Exception evidence

Retain failed and incomplete reports. They establish why a device was quarantined, reprocessed, or destroyed and prevent an unsuccessful attempt from being mistaken for a completed sanitization.