Secure Data Wiping
& Device Sanitization
Safely dispose of old electronics. We perform military-grade, irreversible data erasure on your personal devices before you recycle, donate, or sell them, via certified professionals. For anyone whose data cannot afford to leak: executives, VPs, boards, celebrities, public figures, legal teams, medical practices, financial firms, studios and every business in every industry where confidentiality matters.
For anyone whose data cannot afford to leak
Confidentiality is not just a corporate concern. It matters to a CEO, a film director, a heart surgeon, a defence contractor, a journalist, a musician with unreleased tracks, a lawyer with a client list, a family office, a public figure with a private address. Every branch of work has its own version of "this must never get out". We treat all of them the same way.
Executives & C-Suite
CEOs, CFOs, COOs, managing directors and board members whose devices hold strategy documents, board packs and M&A files.
VPs & Senior Leaders
Vice presidents, directors and department heads with personnel files, forecasts, client contracts and internal investigations.
Celebrities & Public Figures
Actors, musicians, athletes, influencers and public speakers whose private life, personal photos and location data cannot surface.
Legal & Professional Services
Solicitors, barristers, accountants and consultants bound by privilege, with client files that must never be recoverable.
Medical & Healthcare
GPs, surgeons, dentists, therapists and clinics with patient records, imaging and prescription history under strict regulation.
Finance & Banking
Wealth managers, traders, insurance brokers and family offices with portfolios, client identities and transaction histories.
Government & Defence
Contractors, agencies and public sector teams handling classified or sensitive material that must be destroyed to standard.
Media & Production
Film, TV, music and photography studios with unreleased footage, unmixed audio and confidential client material on every drive.
Journalists & Researchers
Reporters, investigators and academics whose sources, drafts and interview recordings must be protected at every stage.
Tech, Startups & Founders
Engineers, founders and investors with source code, private keys, investor decks and pre-launch product information.
Every Business & Trade
Architects, estate agents, HR teams, schools, charities and every organisation with personnel files or client data on retired hardware.
Families & Private Clients
Any household where family photos, financial paperwork, medical records and personal history should never end up in the wrong hands.
Six ways your old hardware can betray you
Every device you have ever owned still contains a version of your life or your work. Most of it will never be looked at. Some of it, in the wrong hands, is a serious problem. Here is what actually sits inside a "wiped" device, whether it held family photos or a board report.
Factory reset is not erasure
A factory reset only deletes the index pointing to your files. The files themselves stay on the drive, recoverable with free tools in under an hour by anyone who knows what they are doing. This is equally true for a home laptop and a corporate one.
Saved passwords in browser storage
Every browser keeps a session cache with passwords, tokens and autofill entries. These survive a standard delete, and can be extracted and used to sign in to your accounts long after the device has changed hands. The risk is much higher for anyone who has ever logged into a company system from that machine.
Client, patient or board documents
Legal, medical, financial and executive devices carry files that were never meant to leave the machine. A donated laptop can leak privileged client files, patient notes or an unreleased board pack without anyone noticing for months.
Photos in recovery caches
Deleted photos from phones and laptops sit in low-level recovery areas that most people never see. The last two years of your camera roll can still be on the device even after you have emptied the trash. For public figures, personal photos are their own category of risk.
Work logins still active
Old laptops signed in to work email, VPN, Slack or Teams keep those sessions cached. A donated laptop can leak into corporate accounts months later, and the trail leads back to you. This is a serious compliance issue for any business of any size.
Smart home and location history
Smart devices log a surprising amount about how you live. Doorbell footage, thermostat schedules, voice assistant snippets and paired phone data are all still inside the device's storage. For high-profile individuals, this is a direct safety concern.
Confidentiality, compliance and chain of custody
For many clients, a wipe is not just about the drive. It is about the paper trail, the regulatory requirements, the non-disclosure agreement and the assurance that no third party ever saw the contents. We build that into every engagement.
NDA-first, chain-of-custody always
Before we touch a single device, we sign a mutual NDA covering everything we may see or handle during the wipe. Both sides commit in writing: you to provide the equipment and the legal authority to dispose of it, and Davidsons IT Agency to guarantee that every piece of information seen or heard during the deletion is never spoken about, never shared, and permanently forgotten once the service has finished. That applies equally to a corporate fleet, an executive's laptop, a celebrity's phone, a lawyer's backup drive or a family NAS. The document is countersigned and returned to you in writing.
Every device is logged on intake with make, model and serial number, photographed, and tracked through every phase. Chain of custody is documented for the entire process. The deletion itself is carried out internally by our certified team, following ISO 27001, GDPR and equivalent data protection regulations. Nothing is left open, nothing is left recoverable, and nothing leaks.
For permanent destruction or other formats of wiping that require a specialist partner, we engage a vetted destruction company, That partner is named and credited on the official certificate for the physical work performed, and is bound by the same privacy guarantees as we are.
If your legal, compliance or security team requires additional paperwork, we can provide a data processing agreement, a written method statement and a signed audit trail before the first device is touched.
Standards your auditors recognise
- DOD 5220.22-M US Department of Defense three-pass overwrite standard.
- NIST 800-88 Guidelines for media sanitization, US NIST framework.
- GDPR EU data protection, right to erasure and Article 17.
- HIPAA US healthcare data and patient record destruction.
- PCI-DSS Payment card data and financial record destruction.
- ISO 27001 Information security management alignment.
Four methods, four very different outcomes
Most people believe that deleting a file or running a factory reset removes the data. It does not. Here is what actually remains on the drive after each method, and what can still be recovered, whether the drive held personal photos or confidential client files.
Three methods, one clear recommendation
Not every device needs the same treatment. A phone with family photos needs a different standard than a hard drive from an executive laptop that held board minutes. We always explain which is right for your situation, and we always recommend the standard that matches the sensitivity of the data, not the cheapest option.
Quick format
The default on every device. Fast, and completely insufficient. Suitable only for a drive you are about to physically destroy.
- Passes1 single pass
- Recoverable90%+ with free tools
- TimeMinutes
- CertificateNone
DOD 3-pass
US Department of Defense standard. Every sector overwritten three times with patterns, then verified with a full scan. What we use for most consumer and professional devices.
- Passes3 patterned overwrite
- Recoverable0% verified
- TimeHours, per drive
- CertificateIssued per device
Crypto erase
Enterprise-grade encryption key destruction. Instant, and irrecoverable for even the most determined recovery attempt. Used for SSDs and enterprise kit.
- MethodKey destruction
- Recoverable0% mathematically
- TimeSeconds
- CertificateFull audit trail
Five phases, one certified erasure
No shortcuts, no "good enough" moments, and no relying on a single tool to do the job. We work through five deliberate phases, each one verified before we move to the next, so the final result is provable to you, your auditor and anyone who ever asks.
Identity & inventory
Every device logged by make, model, serial number and drive serial. We photograph each item, record the storage medium, and hand you a written inventory before anything is touched. For enterprise clients, this forms the basis of the chain-of-custody document.
Sign-out & account release
Every cloud account, work login, VPN session and device pairing is signed out and revoked. Apple ID, Google account, Microsoft account, iCloud, Office 365 and any enterprise directory the device was joined to. Crucial for executives and business users whose sessions are tied to corporate systems.
Certified wipe & overwrite
Each drive wiped using the standard agreed during the audit: DOD 5220.22-M three-pass overwrite on spinning disks, cryptographic erase on SSDs, and NVRAM wipe on printers, routers and IoT devices. The same process for a family laptop and a corporate fleet.
Verification scan
Every wiped drive is scanned end-to-end with recovery-grade tools to confirm nothing is left behind. If a single recoverable sector remains, the drive is wiped again and re-verified before we call it done. This is where our certificates get their weight.
Certificate & handover
A signed certificate of destruction is issued for every device, listing the drive serial numbers, the wipe standard used, the date, and a unique reference number. For enterprise clients, the certificate is bundled with the chain-of-custody document and the compliance report your auditor requested.
Every device, one certified standard
Most people only think about laptops and phones. But almost every electronic device in your home or office holds personal or professional data, and most of them can be recovered by someone who knows how. Here is what we handle for households, executives, studios and businesses.
Laptops & desktops
Windows, macOS and Linux machines with HDD or SSD storage. Full drive wipe and factory reset before handover.
Phones & tablets
iPhone, iPad and Android devices. Crypto erase combined with factory reset and post-wipe audit.
External drives & USB
Portable HDDs, SSDs, USB sticks and SD cards. Wiped cleanly or physically destroyed, your choice.
NAS & home servers
Synology, QNAP and custom builds. Every drive wiped individually, then the chassis reset to factory.
Printers & scanners
Home and small-office units that cache recent documents in internal memory. NVRAM wiped before disposal.
Smart devices & IoT
Smart TVs, speakers, thermostats, doorbells and cameras. Account sign-out and factory reset.
Media & production kit
Cameras, recorders, drones, memory cards and edit drives with raw footage or unreleased material.
Business & enterprise kit
Servers, workstations, fleet laptops and shared devices. Per-policy erasure with full compliance documentation.
The same device, two very different handovers
On the surface, both devices look identical. Inside, one still carries your entire digital life, and the other is a clean slate that is safe to give away to anyone. Whether the device held family photos or a corporate board pack, the difference is the same.
The device looks wiped. It is not.
- Browser still holds every saved password
- Photo recovery caches still contain thousands of images
- Email and work sessions still signed in
- Cloud account still linked to the device
- Drive still holding every file you ever deleted
- No record of what was done, or what was left
Provably empty, ready for anyone.
- Every account signed out and unlinked
- Every drive overwritten three times, verified
- Recovery scan confirms nothing recoverable
- Printer, router and IoT memories cleaned
- Signed certificate listing every drive serial
- Ready for recycling, donation or resale
A certificate you can actually show someone
Every device we wipe comes with a signed certificate of destruction. Whether you are donating to a charity, selling to a stranger, handing a machine to a family member or returning a corporate laptop to your IT department, you have a document that proves what was done and when. For executives, celebrities and businesses, that document is often the difference between a clean story and a very bad one.
Device Data Sanitization Record
- Device type
- Apple MacBook Pro 14" · Space Grey
- Serial number
- C02XJ2H7MD6T
- Storage medium
- Apple NVMe SSD · 512 GB (soldered, crypto erase)
- Wipe standard
- Cryptographic erase + factory reset (Apple Silicon standard)
- Verification
- Sector scan · post-wipe audit · no recoverable data
- Date of destruction
- 18 April 2026 · 14:37 GMT
- Issued by
- Davidsons IT Agency · Certified Data Destruction Technician
Data Wipe
The hidden cost of skipping the wipe
It does not happen overnight. The consequences of an improperly wiped device take years to surface, and by then the device is long gone. Whether the device belonged to a household or a business, the timeline is the same, and the damage gets worse with every year that passes.
Quiet resale, quiet risk
The device is sold, donated or dropped at the tip. Nothing appears to happen. The drive still holds everything, but nobody is looking yet. A corporate laptop looks the same as a family one at this stage.
First account taken over
An old email address starts receiving password resets. An order appears that nobody placed. A client contract leaks onto a forum. The device is not even a suspect because it was "wiped". For a business, this becomes a compliance incident.
Reputation, identity or regulatory fallout
Family photos or ID documents appear on a recovery forum. A business contract, tax return or patient record shows up on a leaked archive. A celebrity's private photos surface. A board pack appears in a competitor's inbox. The trail leads back to a device you handed over years ago.
The numbers every wipe is measured against
Every certificate is backed by a verified method, a documented procedure and a written guarantee. These are the numbers we publish on every device we sanitize, whether it comes from a family home or a corporate boardroom.
US Department of Defense 5220.22-M three-pass overwrite on HDDs, cryptographic erase on SSDs.
Every drive scanned end-to-end after wipe with recovery-grade tools. Nothing recoverable, or we wipe again.
DOD 5220.22-M, NIST 800-88, GDPR, HIPAA, PCI-DSS and ISO 27001. The documentation your legal team needs.
Every device gets its own signed certificate, listing the drive serial number, the standard used and the date.
From the first inventory to a signed certificate
A short, tidy process. We inventory first, sign everything out, then wipe and verify. You get a signed certificate for every device before we leave the property, whether it is a household, an executive's home office or a corporate site.
Inventory & NDA
Mutual NDA signed before we begin. Every device recorded by make, model and serial number, and every account signed out before we touch a single drive.
Standard selected
We agree on the wipe standard per device: DOD 3-pass for HDDs, crypto erase for SSDs, NVRAM wipe for printers and routers, aligned to your compliance framework.
Wipe & verify
Every drive wiped to the agreed standard, then scanned with recovery-grade tools to confirm nothing is left behind. Chain of custody logged at every phase.
Certificate handover
Signed certificate for every device, listing drive serials, wipe standard, date and reference number. Bundled with chain-of-custody and compliance documentation for enterprise clients.
Same mistake, different scale
This is the situation we see most often, in two different worlds. Both made the same assumption: "we reset it, it must be clean". Both found out, years later, that a factory reset is not the same as a certified wipe.
The laptop was donated three years ago. The account takeover happened last week.
A household upgraded their home-office laptop, ran the built-in factory reset, and dropped it at a charity shop the same weekend. Everyone believed the reset had removed their data. Three years later, an old email account was compromised and the trail led back to that laptop.
- The browser cache was never touched. Saved passwords, autofill entries and session tokens were all still in the Chrome profile on the drive.
- The company VPN profile was still installed. The new owner found a valid VPN client that could still authenticate to a corporate network.
- Work documents were in the recovery cache. Client contracts from two years earlier were recoverable in minutes with free forensic tools.
- Family photos had been deleted the day of donation. The recycle bin was emptied, but the underlying files were still on the drive in their original sectors.
- No certificate existed. Nobody had recorded the drive serial number, and nobody could prove what had actually been done to the machine.
A departing VP returned a laptop. Its confidential files resurfaced a year later.
A senior executive left a company on good terms, handed back the company laptop, and the IT team ran the standard wipe script and reimaged the machine. A year later, fragments of a board pack appeared in a data leak that was traced back to the returned laptop's retired drive.
- The reimage script only reformatted the drive. The previous file system was still on the disk, recoverable with commercial forensic tools.
- Two cached email accounts were still signed in. One of them belonged to a former client who had since become a competitor's customer.
- A personal cloud folder synced to the drive. Board packs, internal forecasts and confidential slide decks were mirrored to a personal OneDrive without anyone noticing.
- No chain-of-custody paperwork existed. When the leak was investigated, the company could not prove which drive had been on which laptop at the time of departure.
- No NDA covered the return. The executive had signed an employment NDA, but no specific handling document existed for the device handover itself.
Both situations, done properly, would have taken a few hours. Inventory, NDA, sign-out of every account, DOD 3-pass wipe with a verification scan, chain-of-custody documentation and a signed certificate. Same mistake, same fix, completely different outcome in both worlds.
Factory reset is not erasure
A factory reset only deletes the index pointing to your files. The files themselves stay on the drive, recoverable with free tools.
Sign out before you wipe
Every account, session and device pairing must be signed out and revoked. Wiping the drive does not close the sessions.
Verify, do not assume
A wipe that has never been scanned is a hope, not a wipe. Every drive should be checked with recovery-grade tools before handover.
Certificate, NDA and chain of custody
For businesses and executives, the paperwork is as important as the wipe itself. Signed certificate, countersigned NDA, documented chain of custody. That is what makes the erasure defensible.
We donated twelve machines to a local school. Every single one came with a certificate listing the drive serial. The school said it was the first time a donor had provided that level of proof.
Small business · 12 laptops donatedOur compliance officer needed DOD 5220.22-M, GDPR and a full chain-of-custody document for the auditor. Davidsons delivered all three, on time, for forty retired laptops.
Financial services firm · fleet wipeI am a public figure. My old phone had everything. It went through a signed NDA, a crypto erase, a verification scan and a certificate. It is the first time I have felt genuinely comfortable handing a device over.
Public figure · phone sanitizationBefore we book the wipe
The things people usually ask us before the first inventory, from households, executives, legal teams, medical practices and businesses.
Is a factory reset not enough on its own?
No, and this is the single most common misconception. A factory reset only deletes the index that points to your files. The files themselves stay on the drive until they are overwritten by new data. With free tools that anyone can download, most of those files can be fully recovered in under an hour. A proper wipe overwrites the drive three times, sector by sector, so there is nothing left to recover. This applies equally to a household laptop and a corporate one.
Do you sign an NDA before you begin?
Yes. Every engagement starts with a mutual non-disclosure agreement that covers everything we may see or handle during the wipe. Both sides commit in writing: you to provide the equipment and the legal authority to dispose of it, and Davidsons IT Agency to guarantee that every piece of information seen or heard during the deletion is never spoken about, never shared, and permanently forgotten once the service has finished. This applies equally to a family laptop, an executive's phone, a celebrity's smart home devices, a law firm's backup drives or a corporate fleet. The NDA is countersigned and returned to you, and it stays in effect after the engagement has finished.
Can you provide chain-of-custody and compliance documentation?
Yes. Every device is logged on intake with make, model and serial number, photographed, and tracked through every phase. Chain of custody is documented for the entire process. The deletion itself is performed internally by our certified team, following ISO 27001, GDPR and equivalent data protection regulations. For clients who need it, we provide a data processing agreement, a written method statement, a full audit trail and certificates aligned to DOD 5220.22-M, NIST 800-88, GDPR, HIPAA, PCI-DSS or ISO 27001, depending on what your auditor requires.
Do you work with external companies for permanent destruction?
Sometimes yes, and it is important to be honest about that. For most wipes and sanitizations, the entire process is carried out internally by our certified team under the mutual NDA. For permanent physical destruction or other formats of wiping that require a specialist partner, we engage a vetted destruction company, also under the same NDA. That partner is named and credited on the official certificate for the physical work they perform, and is bound by the same privacy guarantees as we are. The certificate you receive is signed by every party involved, so the full chain is documented and auditable.
Do you actually destroy the device, or just wipe it?
Both are available. If you want the device gone for good, we coordinate physical destruction of the drive, either in-house or through our vetted destruction partner, and issue a destruction certificate. If you want it donated, sold or handed down, we wipe it to DOD 5220.22-M standard, verify the wipe, and issue a sanitization certificate. You choose which route makes sense for each device. For enterprise fleets, we can mix both approaches in a single visit and document them accordingly.
What about SSDs and Apple Silicon Macs? Can they be wiped?
Yes, and they use a different method called cryptographic erase. Instead of overwriting the drive repeatedly, the encryption key that protects the data is destroyed, which makes everything on the drive mathematically unrecoverable in one step. This is actually the strongest form of wipe available today, and it is what we use on every modern SSD and Apple Silicon device. It is also what makes a certified wipe of an executive's MacBook possible without ever needing to open the case.
What happens to the certificate if I sell or donate the device?
The certificate is yours, and it can be transferred with the device. If you sell or donate, we can print a second copy addressed to the new owner, listing the drive serial and the wipe standard. That way the new owner has proof the device is clean, and you have proof that you did the right thing. This is especially important for anything donated to a charity, school or second-hand shop, and it is standard practice for businesses disposing of fleet hardware.
Do you remove the drives from the device?
Sometimes yes, sometimes no. For laptops, phones and tablets, the drives are usually soldered or integrated, so the wipe happens in place. For desktop towers and NAS boxes, we can pull the drives, wipe them individually, and either return them to you or coordinate physical destruction, depending on what you want. Every drive gets its own line on the certificate, so there is no ambiguity about what was wiped.
Will my old work accounts still be signed in?
Not once we finish. Every email, VPN, chat, file-sharing and single-sign-on session is explicitly signed out and revoked before the wipe. This includes anything cached in the browser, any autofill credentials, any saved tokens, and any device pairings. Your IT or security team will get a written record of the sign-outs on request, so they can close out the device on their side as well. This is critical for departing executives and any business that must prove what happened to a device after a staff change.
Can you handle executive departures and corporate fleet wipes?
Yes. Executive departures, board member device returns, corporate fleet retirements, office moves and M&A hardware disposals are all part of what we do. We handle the NDA, the sign-outs, the wipe, the verification, the compliance documentation and the certificate. For a fleet, we work through the devices in batches and issue a single consolidated report alongside the per-device certificates. Everything is auditable, and everything is documented.
How do you handle media and creative industry devices?
Cameras, audio recorders, drone storage and memory cards are treated exactly like computer drives: DOD 3-pass overwrite or cryptographic erase, depending on the medium, followed by a verification scan. We understand that raw media often contains unreleased footage, private client material, unedited interviews and draft cuts that must never surface. The certificate lists the card or drive serial, the standard used and the date, so the studio has a defensible record of every piece of media that was destroyed.
How long does a typical wipe take?
A phone or tablet is usually under an hour, including verification. A laptop with an SSD takes about the same. A mechanical HDD in a desktop or NAS takes several hours per drive because of the three-pass overwrite, so multiple drives are usually done over a day or two. For an enterprise fleet, we agree a schedule that fits around your operations and provide daily progress reports. We always give you a written time estimate before we start, and we never leave a device half-wiped.
Ready to hand over a device, not your data?
From the first inventory to the signed certificate, Davidsons IT Agency wipes, verifies and certifies every device before it leaves your hands. Military-grade erasure, NDA on request, chain of custody, written proof. For households, executives, celebrities, legal teams, medical practices, financial firms, studios and every business in every industry where confidentiality matters.
Book a Secure Data Wipe

