Physical hard drive destruction with a serial number Certificate of Destruction
Deleting files, reformatting, and degaussing are not data destruction — they’re data concealment. Sensitive data remains recoverable on hard drives and solid-state media until the device is physically destroyed. We provide certified physical destruction of all IT assets, recording the serial number of every drive and including it in a notarized Certificate of Destruction. That document is your audit proof — for HIPAA, DFARS, NIST 800-88, SOX, or any other framework that governs your organization.
Drop-off or on-site pickup · Serving all of New England
- ✓ Physical destruction — HDD, SSD, NVMe, server drives
- ✓ Serial number recorded for every device at intake
- ✓ Notarized Certificate of Destruction with serial numbers
- ✓ Tapes, CDs, DVDs, USB drives, mobile devices
- ✓ On-site pickup or drop-off — locked, chain-of-custody transport
- ✓ HIPAA, DFARS, NIST 800-88, SOX documentation
All ITAD service is custom-quoted · Volume pricing available
Formatting a drive does not destroy the data on it — and your compliance framework knows the difference
A standard drive format overwrites the file system index but leaves underlying data sectors intact. Even “secure erase” and DBAN wipe tools — while more thorough than a format — cannot guarantee complete destruction on solid-state drives, where wear-leveling algorithms can preserve data in sectors the wipe tool never reaches.
NIST 800-88, the federal standard for media sanitization, identifies three categories of disposal: Clear, Purge, and Destroy. Only physical Destroy — shredding or disintegration — provides absolute certainty that no data can be recovered by any forensic method. For healthcare organizations under HIPAA, federal contractors under DFARS, and financial institutions under GLBA, physical destruction with documented chain of custody is the only approach that satisfies auditors without question.
We provide exactly that: physical destruction of every device, serial number documentation at intake, and a notarized Certificate of Destruction that you can file as your compliance record. No software certificates. No self-reported erasure logs. A notarized document from a certified provider with a verifiable 17-year track record and zero data breaches.
The hidden risk of “certified erase” vendors
Many ITAD vendors advertise “NIST-compliant erasure” and issue software-generated certificates. These certificates document what the software reported — not what actually happened at the sector level. On SSDs with wear-leveling, overprovisioning, and bad block remapping, software erasure tools routinely leave accessible data behind. Physical destruction is the only method that eliminates the risk entirely. We do not offer software erasure. We destroy every device physically and document it.
Every type of storage media we destroy
Hard Disk Drives (HDD)
2.5" and 3.5" desktop, laptop, and server HDDs of any capacity or manufacturer
Solid State Drives (SSD)
SATA, NVMe, M.2, and PCIe SSDs — all form factors. Software erasure cannot guarantee SSD sanitization.
Server & RAID Drives
Enterprise drives from SAN, NAS, and server arrays including SAS, SCSI, and all rack-mount form factors
Backup Tapes
LTO (all generations), DAT, DLT, Ultrium, VXA, and all other magnetic backup tape formats
Optical Media
CDs, DVDs, Blu-ray discs — including burned discs containing patient data, financial records, or IP
USB Drives & Flash Media
USB thumb drives, SD cards, CompactFlash, memory sticks — all sizes and form factors
Mobile Devices
Smartphones, tablets, and portable devices containing corporate data — physical destruction on request
Legacy & Specialty Media
Floppy disks, Jaz/Zip cartridges, Bernoulli disks, X-ray film, and any other legacy storage format
A notarized Certificate of Destruction with every device’s serial number — not a software log, a legal document
The difference between a compliant ITAD program and a liability is documentation. A software-generated erasure certificate documents what a program reported. Our notarized Certificate of Destruction documents what physically happened — signed, dated, and notarized by a registered notary public.
For every drive we receive, we record the serial number at intake. That serial number appears on your Certificate of Destruction. An auditor reviewing your HIPAA compliance, your DFARS requirements, or your SOX controls can match every drive on your asset register to its destruction record. There is no ambiguity, no gap in the chain of custody, and no “we believe it was erased” language.
Our Certificate of Destruction is admissible as evidence of compliant disposal under HIPAA, DFARS NIST 800-171, SOX, FACTA, GLBA, MA 201 CMR 17.00, and NH RSA 359-C. It is the document your legal team, compliance officer, and auditor will ask for — and we include it with every job at no additional charge.
What appears on your Certificate of Destruction
Delivered within 24–48 hours of destruction
Your Certificate of Destruction is emailed as a PDF within 24 to 48 hours of the destruction date. We recommend storing it alongside your IT asset register and ITAD policy documentation. For HIPAA-covered entities, it also satisfies the requirement for a Business Associate Agreement record — which we can provide on request.
Every organization that stores personal, financial, clinical, or classified data on hardware has a legal obligation to destroy that hardware at end of life
IT asset disposal is not a discretionary best practice. It is a documented legal requirement for organizations operating under HIPAA, DFARS, SOX, GLBA, FERPA, and state data security laws including Massachusetts 201 CMR 17.00 and New Hampshire RSA 359-C. The question is not whether to destroy end-of-life hardware — it’s whether the destruction is documented in a way that satisfies your auditors and protects your organization in the event of a breach investigation.
Healthcare — HIPAA Requirement
The HIPAA Security Rule requires covered entities and business associates to implement policies for final disposal of hardware containing ePHI. Physical destruction with notarized documentation is the accepted standard. Applies to hospitals, practices, imaging centers, labs, billing companies, and any BA handling ePHI.
Defense Contractors — DFARS / NIST 800-171
DFARS clause 252.204-7012 requires DoD contractors to protect Controlled Unclassified Information (CUI) and implement NIST SP 800-171 controls, including media protection (Control 3.8). Physical destruction satisfying NIST 800-88’s Destroy standard is required, with documented evidence.
Financial Services — GLBA & SOX
The GLBA Safeguards Rule requires financial institutions to develop, implement, and maintain appropriate disposal procedures for customer information. SOX Section 802 requires retention and secure disposal of financial records. Physical destruction with a notarized CoD satisfies both.
Higher Education — FERPA & Research
Universities disposing of computers, servers, and lab equipment containing student records (FERPA) or research data face documented disposal obligations. IT refreshes and equipment donations require certified destruction of storage media before any hardware leaves campus control.
Corporate IT Departments
Any business disposing of computers, laptops, servers, or storage arrays that contained employee data, customer records, or financial information has obligations under state data security laws (MA 201 CMR 17.00, NH RSA 359-C) and potentially federal statutes. Physical destruction with documentation is the standard approach for enterprise ITAD programs.
Government & Public Sector — GSA
We are a GSA contractor (since 2010), meaning federal and state agencies can procure our ITAD services through the GSA schedule. Government entities disposing of CUI or personally identifiable information on federal systems have documented destruction requirements under NIST and agency-specific policies.
Physical destruction vs. software erasure — a compliance comparison
The method you choose determines what your auditor will accept. Only physical destruction provides absolute certainty and unconditional documentation.
| Criteria | Physical Destruction (Our Service) | Software Erasure | Degaussing |
|---|---|---|---|
| Data recovery possible? | No — device is physically shredded | Possibly — especially on SSDs with wear-leveling | Possibly — ineffective on SSDs entirely |
| Works on SSDs? | Yes — all SSD types and form factors | Unreliable — SSDs may retain data in unmapped sectors | No — degaussing has no effect on solid-state media |
| NIST 800-88 compliant? | Yes — satisfies “Destroy” standard | Partial — satisfies “Clear” or “Purge” only | Partial — satisfies “Purge” for HDDs only |
| Notarized Certificate of Destruction? | Yes — with serial numbers of every device | No — software-generated report only | No — operator-signed log only |
| Auditor acceptance | Unconditional — highest level of evidence | Conditional — depends on auditor and framework | Conditional — not accepted for SSD-containing devices |
| Breach liability eliminated? | Yes — nothing left to breach | Not fully — residual data risk remains | Not fully — SSD residual data risk remains |
From your IT room to your Certificate of Destruction in four steps
Intake & serial number logging
Drop off devices at our Tewksbury facility or schedule a pickup. At intake, every device is logged by serial number. You receive a signed intake receipt before you leave or before our driver departs your site.
Locked transport & custody
For pickups, all devices travel in locked vehicles under documented chain of custody. No device leaves your custody without a signed record. No device arrives at our plant without a matching intake log entry.
Physical destruction at our AAA plant
All devices are physically destroyed at our AAA-certified facility in Tewksbury. Industrial shredding reduces drives to fragments too small to contain any recoverable data. No software. No degaussing. Physical destruction only.
Notarized CoD within 24–48 hrs
Your notarized Certificate of Destruction — listing every serial number, the destruction date, the method, and the quantity — is emailed as a PDF within 24 to 48 hours. File it with your ITAD policy and IT asset register.
17+ years. Zero data breaches. The Certificate of Destruction that auditors accept without question.
National ITAD chains offer convenience but limited accountability. When your devices leave on a truck and the driver isn’t your employee, your Certificate of Destruction is only as reliable as the vendor’s internal controls — which you cannot audit. We are a locally owned and operated business with a 17-year track record of zero breaches, BBB A+ rating, AAA-certified plant, GSA contractor status, and a notarized Certificate of Destruction that includes the serial number of every device we received.
If an auditor calls your CoD into question, you want to be able to call the owner of the company who signed it.
I took matters into my own hands and did research from Shred-it, Cintas to Staples. I preferred to do business with Neighborhood Parcel because they were local and I was dealing with the owner — not some random call center. The service was on time, professional, and the invoice was exactly what they quoted. The certificate arrived the next morning. A+ all the way around.
Frequently asked questions about ITAD and hard drive destruction
For HDDs, software erasure that meets NIST 800-88 Clear or Purge standards can satisfy HIPAA’s requirement that ePHI be rendered “unreadable, indecipherable, and unable to be reconstructed” — but only if the erasure is verified and properly documented. For SSDs, software erasure is inherently unreliable due to wear-leveling and overprovisioning, meaning data may remain in unmapped sectors. Physical destruction satisfying NIST 800-88’s Destroy standard is the only method that eliminates residual data risk entirely on SSDs, and produces a Certificate of Destruction that HIPAA auditors accept unconditionally. We strongly recommend physical destruction for any device containing ePHI.
For smaller quantities — under 20 drives — walk-in drop-off is generally available Monday through Friday from 10AM to 5PM at our Tewksbury MA facility at 1215 Main St, Unit 115. We prefer a quick phone call at (978) 636-0301 before you arrive so we can ensure we have the right staff and equipment available, especially if you’re bringing a mix of drive types. For larger IT decommissioning projects — 20+ drives, server arrays, or rack equipment — please call to schedule so we can allocate the correct resources and prepare your intake documentation in advance.
All ITAD service is custom-quoted based on quantity, device types, and whether pickup or drop-off is required. We do not publish per-drive rates because pricing varies significantly by volume — a 5-drive retirement has different economics than a 500-drive data center decommission. We are competitive with national ITAD vendors on volume projects and often significantly less expensive for small- to mid-size jobs because we don’t have national overhead. Call (978) 636-0301 or submit a request online with your approximate quantity and device types and we will provide a flat-rate quote in writing.
Yes. We provide on-site pickup for IT decommissioning projects of any scale — from a single server retirement to a full data center decommission. Our CORI-checked drivers transport all devices in locked vehicles under documented chain of custody from your facility to our AAA-certified plant. For large projects, we bring boxes or crates for secure packing on-site and provide a signed intake receipt before departing. We serve all of Greater Boston, Middlesex County, Essex County, Worcester County, and southern New Hampshire. Call (978) 636-0301 at least 48 hours in advance for large-volume pickups.
Yes. Our physical destruction process satisfies NIST SP 800-88’s Destroy standard, which is the method required under NIST 800-171 Control 3.8.3 for media containing Controlled Unclassified Information (CUI) that is to be disposed of. Our notarized Certificate of Destruction — with serial numbers for every device — provides the documented evidence of compliant media sanitization that DFARS 252.204-7012 audits require. We are a GSA contractor and have provided ITAD services to federal and state government entities since 2010. Call (978) 636-0301 to discuss your specific DFARS or government contract requirements.
Yes. For clients who require visual confirmation of destruction — defense contractors, legal firms, executive leadership disposing of personal devices, or organizations with internal audit requirements — we offer witnessed ITAD sessions at our Tewksbury facility by appointment. You observe physical destruction of each device. A witnessed destruction session is subject to our standard witnessed shredding minimum rate. Contact us at (978) 636-0301 to discuss scheduling and requirements.
Every serial number documented. Every device physically destroyed. Every Certificate notarized.
Drop-off or pickup. Small IT retirements to full data center decommissions. One flat-rate quote, confirmed in writing before we touch a single device.