A certificate that is missing three laptops
A law firm sent you eighty laptops and a dozen hard drives for data destruction. Their IT manager gave you a list of serial numbers. Your team checked them in, wiped the laptops with your wiping software, and shredded the loose drives. Your office then typed a certificate listing the serial numbers destroyed, from the wiping software's reports and a paper sheet from the shredder.
The IT manager compares your certificate with her list. Three laptops are missing. One drive serial number is wrong by a digit. She asks where the three laptops are. Your team searches. Two were wiped but the report was saved under a different job. One is still on a shelf, not wiped at all.
Why certificates do not match
Data destruction involves several steps and several tools, and the certificate is only as good as the weakest link between them.
- Devices are checked in on paper or a spreadsheet, not scanned.
- The wiping software produces its own reports, which must be linked to the customer job.
- Physical destruction, like shredding, is recorded on paper.
- Devices that fail wiping and need destruction instead are tracked informally.
- The certificate is typed by hand from several sources.
What standards your process follows and what the certificate must state are for your business and its customers. We deal with tracking devices and producing the certificate from real records.
What mismatched certificates cost
A certificate that does not match the customer's list damages trust in the thing customers are really paying for: confidence that their data is gone. IT managers and their auditors notice gaps, and a single unexplained gap can lose an account.
Devices that sit unprocessed because they fell through the tracking are the worst case. The time spent searching for them, and explaining to customers, is significant.
How we track devices from arrival to certificate
What we build gives each device a record that follows it through your process.
- Devices are checked in by scanning serial numbers or asset tags against the customer's list. Differences are recorded at once.
- Each device is assigned a process: wipe, or physical destruction. Loose drives and devices that cannot be wiped go straight to destruction.
- Wipe results are pulled from your wiping software's reports or export, matched to devices by serial number, and marked pass or fail.
- Devices that fail wiping are moved to destruction automatically, and physical destruction is recorded by scanning each drive or device before it is shredded.
- A job screen shows every device and its status, so nothing sits unprocessed without being visible.
- When every device on the job has a final status, the certificate is generated from those records, listing serial numbers and methods, with any exceptions shown for a person to resolve before it is issued.
| Device status | Meaning |
|---|---|
| Checked in | Received and matched to the customer's list |
| Wiped, passed | Wipe report linked |
| Wiped, failed | Moved to destruction |
| Destroyed | Scanned before destruction |
| Not received | On the customer's list, not arrived |
The law firm's job with device tracking
The eighty laptops and twelve drives are scanned in against the IT manager's list. Two laptops on the list did not arrive, and she is told the same day. The laptops are wiped; the wiping software's reports are matched automatically. One fails and is moved to shredding. The loose drives are scanned before shredding.
The job screen shows every device complete. The certificate is generated with every serial number and method, and the two missing laptops listed as not received. It matches her list line for line.
Do your certificates match your customers' lists?
- Certificates are typed by hand.
- Wiping software reports are not linked to customer jobs automatically.
- Shredded drives are recorded on paper.
- Customers have found serial numbers missing from certificates.
- Devices have been found unprocessed after the certificate was issued.