Standards-based erasure your auditors will recognize
VaultRazer follows NIST SP 800-88 Rev. 2 and IEEE 2883-2022, supports more than 25 national and industry erasure standards, and produces evidence that maps to the regulations you report against.
Which technique for which media
NIST's media sanitization guidelines set different requirements by media type. VaultRazer detects the media and applies the matching technique automatically.
| Media | Clear | Purge | VaultRazer default |
|---|---|---|---|
| ATA / SATA hard drive | Overwrite all user-addressable locations | ATA Sanitize (overwrite) or Secure Erase | Overwrite + verify |
| SAS / SCSI hard drive | Overwrite all user-addressable locations | SCSI Sanitize (overwrite) | Overwrite + verify |
| SATA SSD | Overwrite all user-addressable locations | ATA Sanitize block erase or crypto erase | Sanitize + verify |
| NVMe SSD | Overwrite all user-addressable locations | NVMe Sanitize (block erase or crypto erase), Format with secure erase | Sanitize + verify |
| Self-encrypting drive (TCG Opal) | Overwrite | Cryptographic erase of the media encryption key | Crypto erase + verify |
| Mobile device (iOS / Android) | Factory reset | Cryptographic erase via device's secure reset | Crypto reset + checks |
| USB flash / memory card | Overwrite all user-addressable locations | Generally not supported by the media; destroy if Purge is required | Overwrite, flag for Purge |
25+ standards from 8 jurisdictions
Choose a standard per policy, site or customer. The standard used is recorded on every certificate.
| Standard | Issuer | Method | Verification |
|---|---|---|---|
| NIST SP 800-88 Rev. 2 Clear | US · NIST | 1 overwrite pass | Full read-back |
| NIST SP 800-88 Rev. 2 Purge | US · NIST | Firmware sanitize or crypto erase | Full read-back |
| IEEE 2883-2022 Clear | IEEE | Logical overwrite | Full read-back |
| IEEE 2883-2022 Purge | IEEE | Sanitize command or crypto erase | Full read-back |
| DoD 5220.22-M | US · DoD | 3 passes | Final pass |
| DoD 5220.22-M ECE | US · DoD | 7 passes | Final pass |
| NSA 130-1 | US · NSA | 3 passes | Final pass |
| NCSC-TG-025 | US · NCSC | 3 passes | Final pass |
| US Air Force AFSSI-5020 | US · USAF | 3 passes | Final pass |
| US Army AR 380-19 | US · Army | 3 passes | Final pass |
| US Navy NAVSO P-5239-26 | US · Navy | 3 passes | Final pass |
| OPNAVINST 5239.1A | US · Navy | 3 passes | Final pass |
| HMG Infosec Standard 5, Baseline | UK · NCSC | 1 pass | Final pass |
| HMG Infosec Standard 5, Enhanced | UK · NCSC | 3 passes | Final pass |
| BSI-GS | DE · BSI | Firmware erase + overwrite | Full read-back |
| BSI-GSE | DE · BSI | Extended firmware erase + overwrite | Full read-back |
| BSI-2011-VS | DE · BSI | Overwrite for classified data | Full read-back |
| ANSSI guidance | FR · ANSSI | Overwrite or firmware erase | Full read-back |
| Australian ISM | AU · ASD | 1 pass, media-dependent | Final pass |
| NZISM | NZ · GCSB | 1 pass, media-dependent | Final pass |
| RCMP TSSIT OPS-II | CA · RCMP | 7 passes | Final pass |
| TCG cryptographic erase | TCG | Destroy media encryption key | Read-back sample |
| Firmware-based erasure | ATA / NVMe | Drive sanitize command | Full read-back |
| Bruce Schneier's algorithm | Industry | 7 passes | Final pass |
| Peter Gutmann's algorithm | Industry | 35 passes | Final pass |
| Random overwrite (custom) | Configurable | 1 to 99 passes | Configurable |
What the law asks for, and how VaultRazer answers
| Regulation | Requirement | VaultRazer evidence |
|---|---|---|
| GDPR EU · Art. 5, 17, 32 | Keep personal data only as long as needed; erase on request; secure processing, including disposal. | Per-asset certificate with method and timestamp; File Eraser for targeted erasure requests. |
| DPDP Act 2023 India · Sec. 8(7) | Data fiduciaries must erase personal data once the purpose is served or consent is withdrawn. | Scheduled File Eraser jobs and device certificates to show erasure took place. |
| HIPAA US · 164.310(d)(2) | Policies for final disposal of ePHI and its removal before media re-use. | Signed certificate per device, plus an activity log of who erased what. |
| PCI DSS v4.0 Req. 9.4.7 | Electronic media with cardholder data is destroyed when no longer needed, so data cannot be reconstructed. | NIST Purge erasure with verification and a certificate for each POS, server or drive. |
| GLBA Safeguards Rule US · 314.4(c)(6) | Securely dispose of customer information no later than two years after last use. | Retention-based erasure schedules and searchable certificates. |
| ISO/IEC 27001:2022 A.7.14 · A.8.10 | Verify storage media is erased before disposal or re-use; delete information when no longer required. | Certificates and audit packs ready for certification and surveillance audits. |
| CCPA / CPRA California · 1798.81, 1798.105 | Destroy customer records so they are unreadable; honor deletion requests. | Device and file erasure certificates tied to requests and assets. |
Six things every certificate proves
Identity
A unique certificate ID, linked to the asset tag and the drive's serial number.
Hardware
Make, model and capacity of each drive, captured directly from the device.
Method and standard
The technique used and the standard it satisfies, including the NIST level achieved.
Time and place
Start and end timestamps in UTC, the site and the operator who ran the job.
Verification
The verification method and its result. A failed verification never receives a certificate.
Integrity
A digital signature and hash. Any change to the record invalidates it.
Certificate of Data Erasure
VR-CERT-2026-0042871- Drive
- Samsung PM9B1 512 GB NVMe
- Drive serial
- S6VWNX0W305711
- Method
- NVMe Sanitize, crypto erase
- Standard
- NIST SP 800-88 Rev. 2, Purge
- Completed
- 2026-10-06 14:03:48 UTC
- Operator
- j.mehta · BLR-IT-02
- Verification
- Full read-back, 0 errors
- Result
- Successful
Signed by VaultRazer Signing CA · SHA-256 9f2c41e8a7b05d3c6e1f84a2d97b0c35e6a18f4d2b7c903e15a6f80d4c2b7e91