Securely wipe entire HDDs, SSDs, and NVMe drives with industry-leading data sanitization standards. NIST 800-88 and DoD 5220.22-M compliant erasure for enterprise data security and audit-readiness.
Drive Eraser
Comprehensive data destruction capabilities for all types of sensitive information
Regulatory data wiping for Windows, Mac, and Linux computers. Permanent erasure with tamper-proof certificates for audit compliance.
Secure erasure for enterprise servers and RAID configurations. DIY solution that generates certificates meeting global standards like GDPR, HIPAA, and ISO 27001.
Specialized erasure for solid-state storage ensuring complete data destruction. Deploy via bootable USB (Using UNetbootin) or PXE network boot for maximum flexibility.
Permanent erasure for traditional hard drives and USB storage. Software supports remote deployment via MSI and provides audit trail for compliance reporting.
Experience D-Secure Drive Eraser in action — explore the interface and features right here
Interactive product demo — explore Drive Eraser features directly in your browser
Industry-leading data sanitization in 4 simple steps. Deploy via USB, PXE, or MSI.
D-Secure Drive Eraser offers the flexibility to wipe drives and devices in both internet-enabled locations and offline facilities. Deploy via USB drive, PXE boot over network, or MSI package for remote wiping on Windows endpoints.
*Offline variant available for Non-Internet locations
Generates digitally signed reports of erasure to help meet statutory & regulatory compliance. Option to save reports locally or on secure cloud console in PDF format
D-Secure Drive Eraser supports organizational compliance initiatives by aligning with widely accepted data protection principles and secure erasure best practices
EU General Data Protection
Healthcare Information Privacy
Sarbanes-Oxley Act
Payment Card Industry
Native performance across all major CPU architectures and operating systems
Most Common Architecture
Standard 64-bit processors from Intel & AMD used in most desktops, laptops, and servers.
Growing Ecosystem
Modern ARM-based processors for power-efficient computing on mobile, Mac, and servers.
Legacy Support
Legacy 32-bit processors for older systems still in enterprise use requiring secure erasure.
x64, ARM64, x86
x64, ARM64 (Apple Silicon)
x64, ARM64, x86
Technical capabilities that differentiate D-Secure from consumer-grade deletion utilities and basic disk cleanup tools
Centralized management platform for monitoring, reporting, and managing erasure tasks across all locations.
26+ international erasure standards including NIST 800-88, DoD, HMG.
Deploy via USB boot, PXE network boot, or integrate directly with IT asset management systems.
Seamlessly integrate with all enterprise systems via REST APIs.
enables efficient large-scale data destruction, eliminating the need for manual data wiping processes.
Automatically detect hardware specifications, MDM profiles, and activation locks before erasure.
Pay-per-use licensing model with no expiration - use credits whenever you need them.
Trusted by individuals and enterprises worldwide
Securely erase enterprise RAID arrays before disposal, and private data cannot be recovered.
Safely repurpose hardware within organization
Prepare devices for resale programs
Comply with lease return data requirements
Meet GDPR, HIPAA, PCI-DSS requirements
Securely decommission on-premise storage
D-Secure Drive Eraser permanently sanitizes a hard disk drive (HDD) by writing new data patterns across every addressable sector on the disk, overwriting the original content so that it cannot be recovered — even with advanced forensic tools or magnetic analysis techniques. Unlike standard deletion or formatting, which only removes the file system's reference to stored data while leaving the underlying content physically intact, Drive Eraser applies recognised overwriting standards such as NIST SP 800-88 (Clear), DoD 5220.22-M (3-pass and 7-pass), HMG IS5 Baseline and Enhanced, and IEEE 2883-2022, among others. Once the overwrite passes complete, the software performs a verification pass to confirm that all sectors have been correctly processed. The entire operation is documented in a tamper-proof, digitally signed certificate in PDF and XML format, providing an auditable record suitable for GDPR, HIPAA, PCI DSS, and India's DPDP Act 2023 compliance reviews. Drive Eraser supports erasure of up to 32 drives simultaneously on a single machine.
Yes. D-Secure Drive Eraser is designed to securely sanitize solid-state drives (SSDs) as well as traditional hard disk drives. Erasing an SSD is fundamentally different from erasing an HDD, and this distinction matters for compliance. HDDs store data on magnetic platters, where overwriting every sector with new data is straightforward. SSDs use NAND flash memory managed by an internal controller that employs wear-levelling and over-provisioning — techniques that distribute writes across memory cells to extend drive life. As a result, a simple multi-pass overwrite may not reach every physical memory location, meaning data could survive in over-provisioned or remapped areas. NIST SP 800-88 accounts for this by defining a Purge category specifically for SSDs, which uses ATA Secure Erase or NVMe Format commands issued directly to the drive's firmware. D-Secure Drive Eraser supports these Purge-level methods alongside standard Clear-category overwrites, allowing the appropriate technique to be matched to the media type. Each operation generates a digitally signed audit certificate confirming the method applied and the verification result.
Yes. D-Secure Drive Eraser supports NVMe (Non-Volatile Memory Express) drives alongside HDDs and SSDs, covering the full range of storage media found in modern enterprise workstations, laptops, and servers. NVMe drives connect directly to the CPU via the PCIe bus rather than through a SATA controller, delivering significantly faster read and write speeds than SATA SSDs — but this architecture also introduces specific data sanitization considerations. Like SATA-based SSDs, NVMe drives use NAND flash memory with wear-levelling and over-provisioning, making simple sector overwrites insufficient on their own. NIST SP 800-88 Rev. 1 addresses this through the NVMe Format command, which instructs the drive's controller to sanitize all user-addressable storage locations, including over-provisioned areas. D-Secure Drive Eraser supports the relevant NIST 800-88 Purge-category methods for NVMe media. After sanitization, the software generates a tamper-proof, digitally signed certificate in PDF and XML format, recording the standard applied, the drive identifier, and the verification result. For specific firmware version compatibility with your NVMe devices, please contact D-Secure for confirmation.
D-Secure Drive Eraser supports over 26 globally recognised data erasure and sanitization standards, providing the flexibility to meet the compliance requirements of enterprises, government agencies, ITAD operators, and regulated industries across multiple jurisdictions. Supported standards include, but are not limited to: NIST SP 800-88 Rev. 1 (Clear and Purge categories), DoD 5220.22-M (3-pass and 7-pass variants), IEEE 2883-2022, HMG Infosec Standard 5 (Baseline and Enhanced), and others covering international regulatory environments. This multi-standard support means that a single tool can be used across mixed device fleets — applying DoD 5220.22-M where US Department of Defense alignment is required, NIST 800-88 for general enterprise and government use, and HMG IS5 for UK public sector compliance — without needing separate products for each framework. The specific standard applied to each device is recorded in the per-device, digitally signed audit certificate generated at the end of every erasure session. For the complete list of all supported standards, download the product datasheet from the Drive Eraser product page or contact D-Secure directly.
D-Secure Drive Eraser is designed to support compliance with a range of data protection regulations and industry frameworks that mandate secure, documented data destruction as part of proper data lifecycle management. These include: **GDPR Article 17** (Right to Erasure / Right to Be Forgotten), which requires organisations to permanently delete personal data under specific conditions and document that deletion; **HIPAA** (Health Insurance Portability and Accountability Act), which governs the secure disposal of Protected Health Information (PHI) on retired medical and administrative devices; **PCI DSS 4.0**, which requires that cardholder data be rendered unrecoverable on decommissioned systems; **India's Digital Personal Data Protection (DPDP) Act 2023**, which imposes data erasure obligations aligned with those of GDPR; and **SOX** (Sarbanes-Oxley), relevant to financial records disposal. In each case, Drive Eraser's digitally signed, per-device PDF and XML certificates provide the documented audit trail that regulators and internal governance teams expect as evidence of compliant disposal. For a detailed mapping of how the erasure workflow aligns with each framework, visit the D-Secure compliance page.
NIST Special Publication 800-88 Rev. 1 — "Guidelines for Media Sanitization" — is published by the US National Institute of Standards and Technology and defines three sanitization categories based on the sensitivity of the data stored and the type of storage media: **Clear** (overwriting-based methods suitable for lower-sensitivity data and magnetic media), **Purge** (firmware-level commands for flash storage such as SSDs and NVMe drives, providing a higher assurance level), and **Destroy** (physical destruction, outside the scope of software tools). NIST 800-88 is widely referenced by US federal agencies, defence contractors, healthcare organisations, and enterprise IT teams as the authoritative framework for media sanitization decisions. One important clarification: NIST 800-88 is a set of guidelines, not a certification programme — NIST does not formally certify individual products in the way that ISO or SOC 2 auditors do. D-Secure Drive Eraser implements the technical methods prescribed under both the Clear and Purge categories of NIST 800-88 Rev. 1, and applies them appropriately based on the media type being sanitized. Use the free NIST 800-88 Checker tool on the D-Secure website to determine which category applies to your specific media.
After every completed erasure session, D-Secure Drive Eraser automatically generates a tamper-proof audit certificate available in both PDF and XML formats. Each certificate is digitally signed using ECDSA P-384 (as described in D-Secure's security documentation), which protects the integrity of the document and allows recipients to verify that it has not been altered after issuance. The certificate records the key details of the erasure event, including the device identifier, storage media type, the erasure standard applied, date and time of operation, number of passes completed, and the verification result confirming that the process was successful. XML output allows the certificate data to be imported directly into asset management systems, ERPs, or ServiceNow workflows for centralised, automated record-keeping at scale. These certificates are designed to serve as the auditable documentation that regulators expect under GDPR Article 17, HIPAA, PCI DSS 4.0, and India's DPDP Act 2023. Whether a certificate constitutes sufficient legal evidence in a specific regulatory proceeding depends on the jurisdiction and the applicable regulatory authority; please consult your legal and compliance team or contact D-Secure for guidance relevant to your situation.
D-Secure Drive Eraser offers three deployment methods to fit different enterprise infrastructure models and operational requirements. **USB Boot:** The software is loaded onto a bootable USB drive. A technician inserts the USB into the target device, boots from it, and runs the erasure session independently of the installed operating system. This is well-suited to one-off device retirement, repair-shop workflows, and situations where network connectivity is unavailable. **PXE Network Boot:** For large-scale, network-based deployments, the software supports Preboot Execution Environment (PXE) booting, enabling IT teams to push erasure sessions to multiple endpoints across a local network simultaneously — without needing to physically access each device or prepare individual USB drives. This is the primary method for high-volume data centre decommissioning and ITAD bulk processing. **MSI Remote Deployment:** For Windows environments, the software can be packaged as an MSI and distributed silently across endpoints using enterprise software distribution tools such as Microsoft SCCM, Intune, or equivalent platforms, with no physical access required. All three methods feed erasure results and certificates into the centralised cloud management console. For deployment architecture guidance specific to your environment, please contact D-Secure.
Offline and air-gapped operation is a critical requirement for many government agencies, defence contractors, classified data environments, and high-security enterprise facilities where no internet connectivity is permitted during sensitive operations. D-Secure Drive Eraser's USB boot deployment method is inherently offline — the software runs from a bootable USB drive and does not require an active internet connection during the erasure session itself. The device being erased does not need to be connected to a network for the operation to complete. This makes it suitable for physically isolated (air-gapped) environments where devices cannot communicate with external systems. The audit certificate generated at the end of the session can be exported locally in PDF or XML format for offline record-keeping. For environments that require centralised certificate management while maintaining air-gap separation for the erasure operation itself, or for specific requirements around licence activation in disconnected environments, please contact D-Secure directly for confirmation on how offline licence validation is handled and what infrastructure dependencies exist for your specific deployment scenario.
Erasure failures and interruptions — caused by power loss, hardware errors, drive firmware issues, or bad sectors — are a real operational concern in high-volume environments, and how a tool handles them is a critical evaluation criterion. D-Secure Drive Eraser flags failed and incomplete erasure events in both the on-device session interface and in the centralised cloud management console, allowing operators to identify which devices require attention without manually reviewing individual logs. Devices where erasure did not complete successfully do not receive a passing audit certificate, ensuring that your compliance documentation only reflects verified, completed operations. For a specific drive that fails erasure — for example, due to bad sectors blocking a complete overwrite — the appropriate remediation is typically physical destruction, which NIST 800-88 classifies under the Destroy category. For precise behaviour in error-handling scenarios, including partial-pass logging, bad-sector reporting, and retry logic, please contact D-Secure for confirmation, as the granular detail of error workflow was not publicly documented at the time of this writing.
D-Secure Drive Eraser supports simultaneous erasure of up to 32 drives per machine in a single session. This capability is particularly valuable in high-throughput environments where processing speed directly affects operational efficiency — including data centre decommissioning projects, ITAD facilities processing returned IT assets, and enterprise IT teams managing large-scale device refresh cycles. When combined with PXE network boot deployment, erasure sessions can be pushed to multiple machines across the network simultaneously, with each machine running up to 32 concurrent drive erasures. RAID arrays are also supported, enabling bulk erasure of storage systems beyond individual device limits. All concurrent sessions report back to the centralised cloud management console, where operators can monitor job status in real time and collect the per-device audit certificates generated upon completion. This architecture is designed to eliminate the bottleneck of sequential, one-at-a-time processing that constrains single-drive erasure workflows. For specific throughput benchmarks applicable to your hardware configuration and network infrastructure, please contact D-Secure for confirmation.
In an enterprise IT environment, data erasure is not a standalone task — it is a critical step in the full IT asset lifecycle, connecting device procurement, active use, redeployment, resale, and end-of-life retirement. D-Secure Drive Eraser is built to integrate into this broader lifecycle rather than operate as an isolated utility. Its REST API allows enterprise asset management systems and custom applications to programmatically trigger erasure operations, retrieve certificate data, and manage job queues at scale. Native ServiceNow integration enables ITSM teams to initiate and track erasure directly within their existing ticketing and asset tracking workflows — linking erasure events to the asset's service record without requiring a separate tool or manual data entry. ERP integration allows certificate and device data to flow into enterprise resource planning systems for consolidated reporting. The cloud management console provides centralised oversight of all concurrent and historical erasure jobs, supporting audit readiness across the full device fleet. For enterprise procurement, volume licensing tiers are available for 10, 50, 100, 500, and 1,000+ licences, with custom MSP and OEM pricing available on request.
D-Secure Drive Eraser operates on a **pay-per-use licence model**, where each licence corresponds to one complete erasure operation on one device. A key feature of this model, as stated by D-Secure, is that **licences do not expire** — purchased licences remain valid for future use and are not subject to annual renewal or subscription deadlines. This is particularly well-suited to organisations whose erasure volumes fluctuate across quarters or project cycles, such as ITAD facilities that handle variable inflows of returned assets, or enterprise IT teams that manage periodic device refresh programmes rather than continuous daily processing. Licences are available in volume tiers: 1, 10, 50, 100, 500, and 1,000+ licences, with pricing starting at **$25.00 per licence** for the Standard Erasure variant and **$30.00 per licence** for the Drive Eraser + Diagnostics variant. Custom pricing is available for MSPs, OEM partners, and high-volume enterprise accounts. It is important to note that D-Secure File Eraser — the separate file-level product — uses a different pricing model (annual subscription starting at $40.00/year). For volume quotes, MSP pricing, or multi-year arrangements, contact the D-Secure sales team.
IT Asset Disposition (ITAD) operators have distinct requirements that differ from standard enterprise IT: high throughput, multi-client audit trails, resale-readiness documentation, regulatory compliance across multiple client frameworks simultaneously, and the ability to process devices efficiently without a consistent network infrastructure on the floor. D-Secure Drive Eraser addresses these needs through several capabilities. **Bulk processing:** Simultaneous erasure of up to 32 drives per machine, combined with PXE network boot for multi-machine parallel sessions, supports high-volume daily throughput. **Per-device certificates:** Each device receives its own tamper-proof PDF and XML audit certificate, digitally signed and recording the standard applied, the device identifier, and the verified outcome — giving the ITAD operator documentation to pass to clients as proof of compliant data destruction. **Multi-standard support:** With 26+ erasure standards, a single platform handles client requirements ranging from NIST 800-88 to DoD 5220.22-M to HMG IS5. **Partner programme:** D-Secure's ITAD Partner programme (see the Partners page) offers additional commercial terms including volume pricing and dedicated support. For white-label or branded certificate requirements, the OEM partner programme may be relevant; please contact D-Secure for details.
Yes. D-Secure Drive Eraser is designed to handle server-class hardware and RAID arrays in addition to individual PCs, laptops, and Macs. This is an important distinction for enterprise and ITAD buyers, since decommissioning server infrastructure involves different hardware configurations — multiple drives in RAID enclosures, hot-swap bays, and server chassis that may not support standard desktop boot media in the same way as workstations. Drive Eraser supports simultaneous erasure of up to 32 drives per machine, which is directly applicable to multi-drive server configurations. PXE network boot deployment enables server erasure to be initiated remotely over a network, without requiring a technician to manually attach a USB boot drive to each server in a rack — a significant operational efficiency in data centre decommissioning projects. RAID array erasure is supported, allowing the storage system to be sanitized as a unit where the configuration permits. For specific RAID controller compatibility, server chassis boot configuration requirements, and support for specific server hardware manufacturers or hyperconverged infrastructure, please contact D-Secure for confirmation, as this level of hardware-specific detail was not publicly documented at the time of this writing.
Use our free compliance tools to determine the right sanitization method, estimate costs, and check regulatory requirements.
Find out if your media needs Clear, Purge, or Destroy per federal NIST guidelines.
Try Free ToolEstimate your financial exposure from improper disposal by industry and record count.
Try Free ToolCalculate exact overwrite passes and erasure time under NIST 800-88 and DoD standards.
Try Free ToolAudit your Article 17 'Right to Erasure' readiness with our interactive compliance checklist.
Try Free ToolExpert insights on data security, erasure standards, and best practices
Common misconceptions about data erasure and the truth behind them.
Get personalized guidance on deployment, licensing, and audit-ready data erasure strategies tailored to your organization's needs.