Home / Security

Security built into every erasure

The proof of erasure is only as trustworthy as the system that produces it. Here is how VaultRazer protects your records, and how to report a security issue to us.

Last updated 8 October 2026
Product security

Controls you can show your auditors

Tamper-evident certificates

Every certificate is digitally signed and carries a SHA-256 hash. Any change to the record breaks the signature, so auditors can trust what they read.

Verified, not assumed

Full or sampled read-back confirms each erasure. A drive that fails erasure or verification never receives a successful certificate and is flagged for destruction.

Access control

Role-based permissions, SAML 2.0 single sign-on and multi-factor authentication control who can run erasures, change policies and read records.

Full activity log

The Console keeps a full activity log, so you can trace who did what and when. Send events to your SIEM through webhooks or the REST API.

Your choice of hosting

Run the Console in the VaultRazer cloud, on your own servers, or in a fully air-gapped environment where no record leaves your network.

Trusted boot

Drive Eraser boots from USB, ISO or PXE on UEFI systems with Secure Boot enabled, as well as legacy BIOS, without relying on the installed operating system.