Data Sanitization
Every drive that passes through Tomlin Systems is sanitized before it is reused or resold. Sanitization here follows the methods defined in NIST SP 800-88 Rev. 1, Guidelines for Media Sanitization, published by the National Institute of Standards and Technology.
Why NIST SP 800-88 Rev. 1
SP 800-88 Rev. 1 is the reference standard most commonly cited by U.S. federal agencies and private-sector data handling policies for deciding how storage media should be sanitized before reuse, resale, or disposal. It doesn't prescribe one procedure for every device — instead it defines a small set of sanitization categories and gives guidance on which category is appropriate for a given type of media, based on where that media is going next and how sensitive the data on it was. Using it as the reference point means the method applied to a given drive is documented and repeatable, not ad hoc.
The three categories
SP 800-88 defines three sanitization categories. Tomlin Systems uses all three, depending on the drive:
| Category | What it means |
|---|---|
| Clear | Applies logical techniques to overwrite data on all user-addressable storage locations, protecting against simple, non-invasive data recovery techniques. |
| Purge | Applies physical or logical techniques that render data recovery infeasible using state-of-the-art laboratory techniques — for example, a drive's built-in cryptographic erase or ATA/NVMe secure erase command set, where supported and verified. |
| Destroy | Physically destroys the media so that it cannot be reused as a storage device and data recovery is infeasible. |
Matching the method to the media
Which category applies to a given drive depends on the media type and its condition, not a single blanket procedure:
- Hard disk drives (HDD) are generally sanitized using an overwrite or Purge-level process appropriate to the drive.
- Solid-state drives (SSD) are handled differently from HDDs, since overwrite techniques designed for spinning media don't reliably reach every physical storage location on flash-based media. Where supported, SSDs are sanitized using their built-in secure erase or cryptographic erase commands.
- Self-encrypting drives (SEDs) can, where supported and verified, be sanitized by cryptographic erase — destroying the encryption key so the previously encrypted data is no longer recoverable.
- Media that cannot be reliably verified — because the sanitization method can't be confirmed to have worked, or the drive doesn't support a dependable method — is not resold. See below.
Verification
Sanitization is confirmed before a drive is reused or offered for resale. A drive that cannot be verified as sanitized is not put back into circulation.
Drives that can't be sanitized
Drives that cannot be reliably sanitized — whether because of a hardware fault, an unsupported or unverifiable method, or any other reason the process can't be confirmed — are physically destroyed rather than resold.
Certificate of Sanitization
A Certificate of Sanitization is available for sanitized drives, documenting the drive, the method applied, and the date. A sample certificate can be requested by emailing patrick@tomlinsystems.com.