Every industry, every device, every file · Enterprise compliance · DOD · GDPR · HIPAA · NDA and chain of custody · Nothing recoverable, verified
Davidsons IT Agency · Data Destruction

Secure Data Wiping
& Device Sanitization

Safely dispose of old electronics. We perform military-grade, irreversible data erasure on your personal devices before you recycle, donate, or sell them, via certified professionals. For anyone whose data cannot afford to leak: executives, VPs, boards, celebrities, public figures, legal teams, medical practices, financial firms, studios and every business in every industry where confidentiality matters.

DOD 5220.22-M standard NDA and chain of custody Every industry, every device Executives · Celebrities · Business Nothing recoverable, verified
Who this is built for

For anyone whose data cannot afford to leak

Confidentiality is not just a corporate concern. It matters to a CEO, a film director, a heart surgeon, a defence contractor, a journalist, a musician with unreleased tracks, a lawyer with a client list, a family office, a public figure with a private address. Every branch of work has its own version of "this must never get out". We treat all of them the same way.

Executives & C-Suite

CEOs, CFOs, COOs, managing directors and board members whose devices hold strategy documents, board packs and M&A files.

VPs & Senior Leaders

Vice presidents, directors and department heads with personnel files, forecasts, client contracts and internal investigations.

Celebrities & Public Figures

Actors, musicians, athletes, influencers and public speakers whose private life, personal photos and location data cannot surface.

Legal & Professional Services

Solicitors, barristers, accountants and consultants bound by privilege, with client files that must never be recoverable.

Medical & Healthcare

GPs, surgeons, dentists, therapists and clinics with patient records, imaging and prescription history under strict regulation.

Finance & Banking

Wealth managers, traders, insurance brokers and family offices with portfolios, client identities and transaction histories.

Government & Defence

Contractors, agencies and public sector teams handling classified or sensitive material that must be destroyed to standard.

Media & Production

Film, TV, music and photography studios with unreleased footage, unmixed audio and confidential client material on every drive.

Journalists & Researchers

Reporters, investigators and academics whose sources, drafts and interview recordings must be protected at every stage.

Tech, Startups & Founders

Engineers, founders and investors with source code, private keys, investor decks and pre-launch product information.

Every Business & Trade

Architects, estate agents, HR teams, schools, charities and every organisation with personnel files or client data on retired hardware.

Families & Private Clients

Any household where family photos, financial paperwork, medical records and personal history should never end up in the wrong hands.

Do you know what is still on that old device?

Six ways your old hardware can betray you

Every device you have ever owned still contains a version of your life or your work. Most of it will never be looked at. Some of it, in the wrong hands, is a serious problem. Here is what actually sits inside a "wiped" device, whether it held family photos or a board report.

Critical

Factory reset is not erasure

A factory reset only deletes the index pointing to your files. The files themselves stay on the drive, recoverable with free tools in under an hour by anyone who knows what they are doing. This is equally true for a home laptop and a corporate one.

Data recovered: 95%
Critical

Saved passwords in browser storage

Every browser keeps a session cache with passwords, tokens and autofill entries. These survive a standard delete, and can be extracted and used to sign in to your accounts long after the device has changed hands. The risk is much higher for anyone who has ever logged into a company system from that machine.

Accounts exposed: 60+
Critical

Client, patient or board documents

Legal, medical, financial and executive devices carry files that were never meant to leave the machine. A donated laptop can leak privileged client files, patient notes or an unreleased board pack without anyone noticing for months.

Files at risk: Thousands
High

Photos in recovery caches

Deleted photos from phones and laptops sit in low-level recovery areas that most people never see. The last two years of your camera roll can still be on the device even after you have emptied the trash. For public figures, personal photos are their own category of risk.

Photos at risk: Thousands
High

Work logins still active

Old laptops signed in to work email, VPN, Slack or Teams keep those sessions cached. A donated laptop can leak into corporate accounts months later, and the trail leads back to you. This is a serious compliance issue for any business of any size.

Session tokens: Still live
Moderate

Smart home and location history

Smart devices log a surprising amount about how you live. Doorbell footage, thermostat schedules, voice assistant snippets and paired phone data are all still inside the device's storage. For high-profile individuals, this is a direct safety concern.

Location data: Present
How we protect you beyond the wipe

Confidentiality, compliance and chain of custody

For many clients, a wipe is not just about the drive. It is about the paper trail, the regulatory requirements, the non-disclosure agreement and the assurance that no third party ever saw the contents. We build that into every engagement.

Trust & confidentiality

NDA-first, chain-of-custody always

Before we touch a single device, we sign a mutual NDA covering everything we may see or handle during the wipe. Both sides commit in writing: you to provide the equipment and the legal authority to dispose of it, and Davidsons IT Agency to guarantee that every piece of information seen or heard during the deletion is never spoken about, never shared, and permanently forgotten once the service has finished. That applies equally to a corporate fleet, an executive's laptop, a celebrity's phone, a lawyer's backup drive or a family NAS. The document is countersigned and returned to you in writing.

Every device is logged on intake with make, model and serial number, photographed, and tracked through every phase. Chain of custody is documented for the entire process. The deletion itself is carried out internally by our certified team, following ISO 27001, GDPR and equivalent data protection regulations. Nothing is left open, nothing is left recoverable, and nothing leaks.

For permanent destruction or other formats of wiping that require a specialist partner, we engage a vetted destruction company, That partner is named and credited on the official certificate for the physical work performed, and is bound by the same privacy guarantees as we are.

If your legal, compliance or security team requires additional paperwork, we can provide a data processing agreement, a written method statement and a signed audit trail before the first device is touched.

Compliance frameworks supported

Standards your auditors recognise

  • DOD 5220.22-M US Department of Defense three-pass overwrite standard.
  • NIST 800-88 Guidelines for media sanitization, US NIST framework.
  • GDPR EU data protection, right to erasure and Article 17.
  • HIPAA US healthcare data and patient record destruction.
  • PCI-DSS Payment card data and financial record destruction.
  • ISO 27001 Information security management alignment.
What actually happens when you "wipe" a drive

Four methods, four very different outcomes

Most people believe that deleting a file or running a factory reset removes the data. It does not. Here is what actually remains on the drive after each method, and what can still be recovered, whether the drive held personal photos or confidential client files.

Delete file Move to trash
98% recoverable
Quick format Standard "wipe"
92% recoverable
Factory reset Consumer default
55% recoverable
Certified DOD 3-pass What we do
0% recoverable
Which standard do you actually need?

Three methods, one clear recommendation

Not every device needs the same treatment. A phone with family photos needs a different standard than a hard drive from an executive laptop that held board minutes. We always explain which is right for your situation, and we always recommend the standard that matches the sensitivity of the data, not the cheapest option.

Basic

Quick format

The default on every device. Fast, and completely insufficient. Suitable only for a drive you are about to physically destroy.

  • Passes1 single pass
  • Recoverable90%+ with free tools
  • TimeMinutes
  • CertificateNone
Suitable forPhysical destruction only
Enterprise

Crypto erase

Enterprise-grade encryption key destruction. Instant, and irrecoverable for even the most determined recovery attempt. Used for SSDs and enterprise kit.

  • MethodKey destruction
  • Recoverable0% mathematically
  • TimeSeconds
  • CertificateFull audit trail
Suitable forSSDs, enterprise, compliance
How we wipe a device

Five phases, one certified erasure

No shortcuts, no "good enough" moments, and no relying on a single tool to do the job. We work through five deliberate phases, each one verified before we move to the next, so the final result is provable to you, your auditor and anyone who ever asks.

01 Phase One

Identity & inventory

Every device logged by make, model, serial number and drive serial. We photograph each item, record the storage medium, and hand you a written inventory before anything is touched. For enterprise clients, this forms the basis of the chain-of-custody document.

Signed
02 Phase Two

Sign-out & account release

Every cloud account, work login, VPN session and device pairing is signed out and revoked. Apple ID, Google account, Microsoft account, iCloud, Office 365 and any enterprise directory the device was joined to. Crucial for executives and business users whose sessions are tied to corporate systems.

Accounted
03 Phase Three

Certified wipe & overwrite

Each drive wiped using the standard agreed during the audit: DOD 5220.22-M three-pass overwrite on spinning disks, cryptographic erase on SSDs, and NVRAM wipe on printers, routers and IoT devices. The same process for a family laptop and a corporate fleet.

DOD standard
04 Phase Four

Verification scan

Every wiped drive is scanned end-to-end with recovery-grade tools to confirm nothing is left behind. If a single recoverable sector remains, the drive is wiped again and re-verified before we call it done. This is where our certificates get their weight.

Re-checked
05 Phase Five

Certificate & handover

A signed certificate of destruction is issued for every device, listing the drive serial numbers, the wipe standard used, the date, and a unique reference number. For enterprise clients, the certificate is bundled with the chain-of-custody document and the compliance report your auditor requested.

Certified
Which devices we wipe

Every device, one certified standard

Most people only think about laptops and phones. But almost every electronic device in your home or office holds personal or professional data, and most of them can be recovered by someone who knows how. Here is what we handle for households, executives, studios and businesses.

Laptops & desktops

Windows, macOS and Linux machines with HDD or SSD storage. Full drive wipe and factory reset before handover.

StandardDOD 3-pass
CertificateYes

Phones & tablets

iPhone, iPad and Android devices. Crypto erase combined with factory reset and post-wipe audit.

StandardCrypto erase
CertificateYes

External drives & USB

Portable HDDs, SSDs, USB sticks and SD cards. Wiped cleanly or physically destroyed, your choice.

StandardDOD 3-pass
CertificatePer drive

NAS & home servers

Synology, QNAP and custom builds. Every drive wiped individually, then the chassis reset to factory.

StandardPer drive
CertificatePer drive

Printers & scanners

Home and small-office units that cache recent documents in internal memory. NVRAM wiped before disposal.

StandardNVRAM wipe
CertificateYes

Smart devices & IoT

Smart TVs, speakers, thermostats, doorbells and cameras. Account sign-out and factory reset.

StandardFull reset
CertificateYes

Media & production kit

Cameras, recorders, drones, memory cards and edit drives with raw footage or unreleased material.

StandardRaw media wipe
CertificatePer card

Business & enterprise kit

Servers, workstations, fleet laptops and shared devices. Per-policy erasure with full compliance documentation.

StandardPer policy
CertificateFull chain
Before and after

The same device, two very different handovers

On the surface, both devices look identical. Inside, one still carries your entire digital life, and the other is a clean slate that is safe to give away to anyone. Whether the device held family photos or a corporate board pack, the difference is the same.

Before · factory reset

The device looks wiped. It is not.

  • Browser still holds every saved password
  • Photo recovery caches still contain thousands of images
  • Email and work sessions still signed in
  • Cloud account still linked to the device
  • Drive still holding every file you ever deleted
  • No record of what was done, or what was left
After · certified wipe

Provably empty, ready for anyone.

  • Every account signed out and unlinked
  • Every drive overwritten three times, verified
  • Recovery scan confirms nothing recoverable
  • Printer, router and IoT memories cleaned
  • Signed certificate listing every drive serial
  • Ready for recycling, donation or resale
What for · what you receive

A certificate you can actually show someone

Every device we wipe comes with a signed certificate of destruction. Whether you are donating to a charity, selling to a stranger, handing a machine to a family member or returning a corporate laptop to your IT department, you have a document that proves what was done and when. For executives, celebrities and businesses, that document is often the difference between a clean story and a very bad one.

Certificate of Destruction

Device Data Sanitization Record

Reference DDI-2026-0418-7742
Device type
Apple MacBook Pro 14" · Space Grey
Serial number
C02XJ2H7MD6T
Storage medium
Apple NVMe SSD · 512 GB (soldered, crypto erase)
Wipe standard
Cryptographic erase + factory reset (Apple Silicon standard)
Verification
Sector scan · post-wipe audit · no recoverable data
Date of destruction
18 April 2026 · 14:37 GMT
Issued by
Davidsons IT Agency · Certified Data Destruction Technician
Certified
Data Wipe
What happens when you don't

The hidden cost of skipping the wipe

It does not happen overnight. The consequences of an improperly wiped device take years to surface, and by then the device is long gone. Whether the device belonged to a household or a business, the timeline is the same, and the damage gets worse with every year that passes.

Within Days

Quiet resale, quiet risk

The device is sold, donated or dropped at the tip. Nothing appears to happen. The drive still holds everything, but nobody is looking yet. A corporate laptop looks the same as a family one at this stage.

Within Months

First account taken over

An old email address starts receiving password resets. An order appears that nobody placed. A client contract leaks onto a forum. The device is not even a suspect because it was "wiped". For a business, this becomes a compliance incident.

Within Years

Reputation, identity or regulatory fallout

Family photos or ID documents appear on a recovery forum. A business contract, tax return or patient record shows up on a leaked archive. A celebrity's private photos surface. A board pack appears in a competitor's inbox. The trail leads back to a device you handed over years ago.

Measured, not promised

The numbers every wipe is measured against

Every certificate is backed by a verified method, a documented procedure and a written guarantee. These are the numbers we publish on every device we sanitize, whether it comes from a family home or a corporate boardroom.

Wipe standard
DOD 3-pass

US Department of Defense 5220.22-M three-pass overwrite on HDDs, cryptographic erase on SSDs.

Recoverable data
0%

Every drive scanned end-to-end after wipe with recovery-grade tools. Nothing recoverable, or we wipe again.

Compliance frameworks
6supported

DOD 5220.22-M, NIST 800-88, GDPR, HIPAA, PCI-DSS and ISO 27001. The documentation your legal team needs.

Certificates issued
Per device

Every device gets its own signed certificate, listing the drive serial number, the standard used and the date.

How a visit works

From the first inventory to a signed certificate

A short, tidy process. We inventory first, sign everything out, then wipe and verify. You get a signed certificate for every device before we leave the property, whether it is a household, an executive's home office or a corporate site.

01

Inventory & NDA

Mutual NDA signed before we begin. Every device recorded by make, model and serial number, and every account signed out before we touch a single drive.

02

Standard selected

We agree on the wipe standard per device: DOD 3-pass for HDDs, crypto erase for SSDs, NVRAM wipe for printers and routers, aligned to your compliance framework.

03

Wipe & verify

Every drive wiped to the agreed standard, then scanned with recovery-grade tools to confirm nothing is left behind. Chain of custody logged at every phase.

04

Certificate handover

Signed certificate for every device, listing drive serials, wipe standard, date and reference number. Bundled with chain-of-custody and compliance documentation for enterprise clients.

Two common situations

Same mistake, different scale

This is the situation we see most often, in two different worlds. Both made the same assumption: "we reset it, it must be clean". Both found out, years later, that a factory reset is not the same as a certified wipe.

Scenario one · home office · donated laptop

The laptop was donated three years ago. The account takeover happened last week.

A household upgraded their home-office laptop, ran the built-in factory reset, and dropped it at a charity shop the same weekend. Everyone believed the reset had removed their data. Three years later, an old email account was compromised and the trail led back to that laptop.

What the post-mortem revealed
  • The browser cache was never touched. Saved passwords, autofill entries and session tokens were all still in the Chrome profile on the drive.
  • The company VPN profile was still installed. The new owner found a valid VPN client that could still authenticate to a corporate network.
  • Work documents were in the recovery cache. Client contracts from two years earlier were recoverable in minutes with free forensic tools.
  • Family photos had been deleted the day of donation. The recycle bin was emptied, but the underlying files were still on the drive in their original sectors.
  • No certificate existed. Nobody had recorded the drive serial number, and nobody could prove what had actually been done to the machine.
Scenario two · executive departure · returned laptop

A departing VP returned a laptop. Its confidential files resurfaced a year later.

A senior executive left a company on good terms, handed back the company laptop, and the IT team ran the standard wipe script and reimaged the machine. A year later, fragments of a board pack appeared in a data leak that was traced back to the returned laptop's retired drive.

What the investigation found
  • The reimage script only reformatted the drive. The previous file system was still on the disk, recoverable with commercial forensic tools.
  • Two cached email accounts were still signed in. One of them belonged to a former client who had since become a competitor's customer.
  • A personal cloud folder synced to the drive. Board packs, internal forecasts and confidential slide decks were mirrored to a personal OneDrive without anyone noticing.
  • No chain-of-custody paperwork existed. When the leak was investigated, the company could not prove which drive had been on which laptop at the time of departure.
  • No NDA covered the return. The executive had signed an employment NDA, but no specific handling document existed for the device handover itself.

Both situations, done properly, would have taken a few hours. Inventory, NDA, sign-out of every account, DOD 3-pass wipe with a verification scan, chain-of-custody documentation and a signed certificate. Same mistake, same fix, completely different outcome in both worlds.

Factory reset is not erasure

A factory reset only deletes the index pointing to your files. The files themselves stay on the drive, recoverable with free tools.

Sign out before you wipe

Every account, session and device pairing must be signed out and revoked. Wiping the drive does not close the sessions.

Verify, do not assume

A wipe that has never been scanned is a hope, not a wipe. Every drive should be checked with recovery-grade tools before handover.

Certificate, NDA and chain of custody

For businesses and executives, the paperwork is as important as the wipe itself. Signed certificate, countersigned NDA, documented chain of custody. That is what makes the erasure defensible.

“

We donated twelve machines to a local school. Every single one came with a certificate listing the drive serial. The school said it was the first time a donor had provided that level of proof.

Small business · 12 laptops donated
“

Our compliance officer needed DOD 5220.22-M, GDPR and a full chain-of-custody document for the auditor. Davidsons delivered all three, on time, for forty retired laptops.

Financial services firm · fleet wipe
“

I am a public figure. My old phone had everything. It went through a signed NDA, a crypto erase, a verification scan and a certificate. It is the first time I have felt genuinely comfortable handing a device over.

Public figure · phone sanitization
Common questions

Before we book the wipe

The things people usually ask us before the first inventory, from households, executives, legal teams, medical practices and businesses.

Is a factory reset not enough on its own?

No, and this is the single most common misconception. A factory reset only deletes the index that points to your files. The files themselves stay on the drive until they are overwritten by new data. With free tools that anyone can download, most of those files can be fully recovered in under an hour. A proper wipe overwrites the drive three times, sector by sector, so there is nothing left to recover. This applies equally to a household laptop and a corporate one.

Do you sign an NDA before you begin?

Yes. Every engagement starts with a mutual non-disclosure agreement that covers everything we may see or handle during the wipe. Both sides commit in writing: you to provide the equipment and the legal authority to dispose of it, and Davidsons IT Agency to guarantee that every piece of information seen or heard during the deletion is never spoken about, never shared, and permanently forgotten once the service has finished. This applies equally to a family laptop, an executive's phone, a celebrity's smart home devices, a law firm's backup drives or a corporate fleet. The NDA is countersigned and returned to you, and it stays in effect after the engagement has finished.

Can you provide chain-of-custody and compliance documentation?

Yes. Every device is logged on intake with make, model and serial number, photographed, and tracked through every phase. Chain of custody is documented for the entire process. The deletion itself is performed internally by our certified team, following ISO 27001, GDPR and equivalent data protection regulations. For clients who need it, we provide a data processing agreement, a written method statement, a full audit trail and certificates aligned to DOD 5220.22-M, NIST 800-88, GDPR, HIPAA, PCI-DSS or ISO 27001, depending on what your auditor requires.

Do you work with external companies for permanent destruction?

Sometimes yes, and it is important to be honest about that. For most wipes and sanitizations, the entire process is carried out internally by our certified team under the mutual NDA. For permanent physical destruction or other formats of wiping that require a specialist partner, we engage a vetted destruction company, also under the same NDA. That partner is named and credited on the official certificate for the physical work they perform, and is bound by the same privacy guarantees as we are. The certificate you receive is signed by every party involved, so the full chain is documented and auditable.

Do you actually destroy the device, or just wipe it?

Both are available. If you want the device gone for good, we coordinate physical destruction of the drive, either in-house or through our vetted destruction partner, and issue a destruction certificate. If you want it donated, sold or handed down, we wipe it to DOD 5220.22-M standard, verify the wipe, and issue a sanitization certificate. You choose which route makes sense for each device. For enterprise fleets, we can mix both approaches in a single visit and document them accordingly.

What about SSDs and Apple Silicon Macs? Can they be wiped?

Yes, and they use a different method called cryptographic erase. Instead of overwriting the drive repeatedly, the encryption key that protects the data is destroyed, which makes everything on the drive mathematically unrecoverable in one step. This is actually the strongest form of wipe available today, and it is what we use on every modern SSD and Apple Silicon device. It is also what makes a certified wipe of an executive's MacBook possible without ever needing to open the case.

What happens to the certificate if I sell or donate the device?

The certificate is yours, and it can be transferred with the device. If you sell or donate, we can print a second copy addressed to the new owner, listing the drive serial and the wipe standard. That way the new owner has proof the device is clean, and you have proof that you did the right thing. This is especially important for anything donated to a charity, school or second-hand shop, and it is standard practice for businesses disposing of fleet hardware.

Do you remove the drives from the device?

Sometimes yes, sometimes no. For laptops, phones and tablets, the drives are usually soldered or integrated, so the wipe happens in place. For desktop towers and NAS boxes, we can pull the drives, wipe them individually, and either return them to you or coordinate physical destruction, depending on what you want. Every drive gets its own line on the certificate, so there is no ambiguity about what was wiped.

Will my old work accounts still be signed in?

Not once we finish. Every email, VPN, chat, file-sharing and single-sign-on session is explicitly signed out and revoked before the wipe. This includes anything cached in the browser, any autofill credentials, any saved tokens, and any device pairings. Your IT or security team will get a written record of the sign-outs on request, so they can close out the device on their side as well. This is critical for departing executives and any business that must prove what happened to a device after a staff change.

Can you handle executive departures and corporate fleet wipes?

Yes. Executive departures, board member device returns, corporate fleet retirements, office moves and M&A hardware disposals are all part of what we do. We handle the NDA, the sign-outs, the wipe, the verification, the compliance documentation and the certificate. For a fleet, we work through the devices in batches and issue a single consolidated report alongside the per-device certificates. Everything is auditable, and everything is documented.

How do you handle media and creative industry devices?

Cameras, audio recorders, drone storage and memory cards are treated exactly like computer drives: DOD 3-pass overwrite or cryptographic erase, depending on the medium, followed by a verification scan. We understand that raw media often contains unreleased footage, private client material, unedited interviews and draft cuts that must never surface. The certificate lists the card or drive serial, the standard used and the date, so the studio has a defensible record of every piece of media that was destroyed.

How long does a typical wipe take?

A phone or tablet is usually under an hour, including verification. A laptop with an SSD takes about the same. A mechanical HDD in a desktop or NAS takes several hours per drive because of the three-pass overwrite, so multiple drives are usually done over a day or two. For an enterprise fleet, we agree a schedule that fits around your operations and provide daily progress reports. We always give you a written time estimate before we start, and we never leave a device half-wiped.

Ready to hand over a device, not your data?

From the first inventory to the signed certificate, Davidsons IT Agency wipes, verifies and certifies every device before it leaves your hands. Military-grade erasure, NDA on request, chain of custody, written proof. For households, executives, celebrities, legal teams, medical practices, financial firms, studios and every business in every industry where confidentiality matters.

Book a Secure Data Wipe
DOD 5220.22-M certified erasure NDA · chain of custody · compliance report Signed certificate for every device