top of page

Onsite data destruction for organisations

Destroy the data before it leaves your site.

For projects where storage media must remain under your organisation’s control until the agreed erasure or destruction process is complete—with witnessing and project evidence available.

Planned around your premises, security policy, media and reporting requirement
Project control · Your premises Route active
Client-controlled boundary
01
Current stageScope confirmed

Media, method, access, witnessing and evidence are agreed before attendance.

Current stageOperator onsite

The controlled work area and authorised contacts are confirmed on arrival.

Current stageMedia processed

The selected method is applied to each media group within the agreed boundary.

Current stageOutcome verified

Results and exceptions are recorded to the evidence level agreed for the project.

Current stageRelease approved

Processed residuals or equipment can move to the approved downstream route.

Define
Arrive
Process
Verify
Release
Onsite is usually chosen when
Media cannot leave untreated Witnessing is required Custody must stay visible

Start with the requirement

When processing at your premises makes sense.

Onsite work is a specific project route, not automatically the best or most economical answer for every collection.

01

Policy prevents untreated media leaving

Storage media remains within your controlled premises until the agreed sanitisation or destruction step has been completed.

CONTROLLED RELEASE
02

Authorised staff need to witness the work

Your representatives can observe the agreed process and confirm that the relevant media was presented and treated.

VISIBLE ASSURANCE
03

The project has a strict custody boundary

A planned onsite route reduces movement before processing and can support projects with enhanced handling or access controls.

CHAIN OF CUSTODY
04

You need a defined evidence package

Asset records, method details, exceptions, witnessing information and certification can be matched to the agreed project scope.

PROJECT EVIDENCE

A controlled handover

Your site before. Cleared for release after.

Move the divider to see the operational difference. Processing is completed inside the agreed boundary before residual materials or equipment follow the approved next route.

Before processing

Data-bearing media remains restricted.

Items are held within the agreed work area and reconciled to the project scope before the selected method begins.

After processing

The data risk is addressed before release.

Processed media or residual material can then leave the controlled area for the agreed downstream recycling or equipment route.

VERIFIED Approved next route
01 02 03 04
Untreated · controlled Processed · cleared
Before processing

Data-bearing media remains restricted.

Items are held within the agreed work area and reconciled to the project scope before the selected method begins.

After processing

The data risk is addressed before release.

Processed media or residual material can then leave the controlled area for the agreed downstream recycling or equipment route.

The onsite custody path

One visible route through the project.

The working sequence is agreed in advance and adapted to the site, media, security requirements and evidence requested.

Stage one

Define the controlled work area

Confirm access, authorised contacts, equipment location, handling rules, witnessing and any operational restrictions.

01
Stage two

Reconcile the media

Identify and record the relevant drives or devices to the level agreed for the project.

02
Stage three

Apply the selected method

Complete the appropriate erasure, degaussing or physical-destruction process for the media and requirement.

03
Stage four

Record results and exceptions

Capture agreed evidence, distinguish successful processing from exceptions and confirm any alternative route.

04
Stage five

Release the processed outcome

Only after the agreed data-security step is complete are residual materials or equipment routed onward.

05

Choose by media and requirement

The method follows the technology—not habit.

Different storage technologies require different treatment. Select a method to understand where it can fit.

MEDIA
METHOD 01 · SOFTWARE ERASURE

Preserve useful equipment where policy allows.

Secure software erasure may be suitable for functioning storage and reusable equipment where the project, device, access and verification requirements support it.

Common fitFunctioning SSDs, HDDs and supported devices
Reuse potentialCan preserve the device or media for further use
EvidenceMethod and device-level output where supported and agreed
Key dependencyAccess, device health and supported secure-erasure controls
Where onsite erasure is not technically or operationally suitable, an irreversible destruction route can be agreed instead.
METHOD 02 · DEGAUSSING

Irreversibly sanitise compatible magnetic storage.

Degaussing uses a powerful magnetic field to render data on compatible hard disk and tape media unrecoverable. It does not work on SSD, NVMe or other flash storage.

Common fitMagnetic HDDs and compatible tape media
Reuse potentialThe processed storage media cannot remain a functioning drive
EvidenceMethod, asset and degausser records where agreed
Key dependencyMedia type must be confirmed as magnetically compatible
Mixed projects commonly need more than one method because modern equipment may contain HDD, SSD, NVMe and embedded storage.
METHOD 03 · PHYSICAL DESTRUCTION

Render storage media permanently unusable.

Physical destruction is available where policy, contract, device condition or failed erasure requires media to be mechanically destroyed before leaving the premises.

Common fitHDDs, SSDs and other agreed storage media
Reuse potentialThe destroyed media cannot be reused
EvidenceAsset, witnessing or destruction-point records by scope
Key dependencyParticle size and treatment must match the requirement
Destroying storage media does not always mean the complete laptop, server or device must also be destroyed.

Evidence matched to scope

See what the project can record.

Not every organisation needs the deepest possible audit. We agree the evidence package before attendance so the operational work and final reporting match.

Onsite project evidence
PROJECT ROUTE Witnessed onsite processing
RECORDING
Authorised site and project contacts Confirmed
Asset or serial-number records By scope
Processing method and outcome Recorded
Witnessing or destruction-point details Available
Exceptions and alternative treatment Tracked
Certificate and completion report Issued
PROJECT PROGRESS
01 / 06 VERIFIED

Before the appointment

Prepare the site, not just the media.

Good preparation reduces delays, protects the working area and helps the evidence match the assets presented.

01

Define the scope

Provide media types, approximate quantities, equipment configuration and the required method or security outcome.

Required
02

Confirm access

Identify loading, parking, security, induction, working-space, power and authorised-contact arrangements.

Required
03

Prepare equipment

Make devices or drives accessible and identify anything encrypted, locked, damaged, soldered or unusually configured.

Recommended
04

Agree the evidence

Confirm asset-list reconciliation, serial records, witnessing details, certificates and reporting format in advance.

By scope

Practical answers

Before choosing onsite processing.

The right route depends on the media, site, volume, required outcome and evidence.

Does data-bearing media leave our premises before processing? +

No, where the agreed onsite route requires media to remain under your control. The relevant media is processed within the agreed area before processed residuals or equipment follow the approved next route.

Can our staff witness the process? +

Yes. Authorised representatives can witness the agreed process where this is part of the project plan and site arrangements allow it.

Can HDDs and SSDs be treated in the same way? +

Not always. Degaussing is appropriate for compatible magnetic media, but not SSD or NVMe flash storage. Physical destruction and supported erasure methods must also be selected according to the storage technology and required outcome.

Do you destroy entire laptops and servers onsite? +

The normal requirement is to address the data-bearing storage rather than unnecessarily destroy a complete device. Whole-device destruction can be discussed where policy, design or the project requirement makes it necessary.

What reporting is available? +

Depending on the agreed scope, this can include asset and serial-number records, processing methods, outcomes, exception reporting, witnessing details, certificates and a tailored completion report.

Is onsite destruction suitable for a small number of drives? +

It can be, but onsite attendance has project and travel costs. For smaller or lower-risk requirements, secure offsite processing or another controlled route may be more proportionate. We will explain the practical options before quoting.

Tell us what must be processed before it leaves.

Send the media types, approximate quantity, site location, required method, witnessing needs and reporting requirement. We will confirm whether an onsite route is appropriate.

Recognised guidance, with the process visible at your premises.

Where storage media must be processed before leaving site, the agreed method, witnessing requirement and evidence package are defined in advance.

  • ISO 9001 certified quality management — Current
  • Information Commissioner's Office registration — Registered until 16 April 2027
  • NIST SP 800-88 Rev. 2 — Guidelines for Media Sanitization — Guidance referenced — not a Bioteknik certification.
  • NCSC — Secure Sanitisation and Disposal of Storage Media — Guidance referenced — not a Bioteknik certification.
  • UK GDPR / ICO secure disposal expectations — Regulatory guidance referenced — not a Bioteknik certification.

Public NCSC sanitisation guidance is proportionate to OFFICIAL information; separate guidance applies where media has handled SECRET or above.

Licences, credentials and standards

bottom of page