Guide
What a certificate of data destruction should show
If you dispose of drives for a business, sooner or later someone asks for proof. A client, an auditor, a buyer, or your own records. The document that answers them is a certificate of data destruction. The trouble is that “certificate” can mean anything from a real, verifiable record to a Word template someone typed a serial number into. Here is what a certificate actually needs to show to be worth anything, and how to tell a strong one from a weak one.
Why the certificate matters
Wiping a drive and being able to prove you wiped it are two different things. The wipe protects the data. The certificate protects you. When a client asks how their information was disposed of, or an auditor wants to see your process, or a buyer wants assurance the machine is clean, “we wiped it” is not an answer. A certificate is. It is the record that turns a private action into something you can stand behind in front of someone else.
What a good certificate includes
A certificate is only as good as the specific, checkable facts on it. At a minimum it should show:
The exact drive. The make, model, and above all the serial number of the drive that was wiped. A certificate that does not name the specific drive proves nothing about the drive in question. The serial number is what ties the record to the physical hardware.
The method used. Which sanitization method was applied, and to what standard. “NIST 800-88 Purge” or “NIST 800-88 Clear” tells a reader exactly what was done and lets them judge whether it suits the drive. “Wiped” on its own does not.
The verification result. Whether the wipe was checked afterward by reading the drive back, and whether it passed. A method without verification is a claim. A verified result is evidence the data is actually gone, not just that an erase was attempted.
The date and time. When the sanitization happened, so the record sits in a timeline you can defend.
A tamper-evident fingerprint. Some way to confirm the certificate has not been altered since it was created. Without this, any certificate is just editable text, and a serial number or a date could be changed after the fact with no trace.
The difference between a real certificate and a template
Plenty of “certificates of destruction” are just a form. Someone runs a wipe, opens a template, and types in the details by hand. Nothing stops those details being wrong, whether by mistake or on purpose, and nothing lets a reader confirm them. It looks official and proves nothing.
A real certificate is generated by the tool that did the wipe, from the actual result of that wipe, and it is verifiable. That means the drive details, method, and result are recorded by the software as they happened, not typed in afterward, and there is a way for anyone holding the certificate to check it is genuine and unaltered. The fingerprint is what makes that possible. If the certificate and its underlying log are cryptographically tied together, changing either one breaks the match, and the check fails. That is the line between a document you hope is trusted and one that can be independently confirmed.
What ProofWipe produces
ProofWipe generates a certificate for every drive it sanitizes, straight from the result of the wipe. Each one lists the drive and its serial number, the NIST 800-88 method used, the read-back verification result, and the date and time. It carries a tamper-evident fingerprint, a SHA-256 hash tying the certificate to the wipe's log, so any later change to either would be caught.
Anyone can verify a certificate at proofwipe.com/verify. It recomputes the fingerprint in the browser and confirms it matches, with nothing uploaded. So the buyer or auditor you hand it to does not have to take your word or ours. They can check it themselves.
If you are disposing of drives and need to prove it, that is the standard to hold any certificate to: specific, verified, and tamper-evident, not just a printed claim. Get ProofWipe at proofwipe.com, and see how the wipe and verification work in our guide to how ProofWipe wipes a drive and proves it.