The U.S. baseline for media sanitization — Clear, Purge, and Destroy. Apex executes purge-level sanitization and verifies the result on our record-generating stations; on the drive and endpoint carts your licensed wipe suite performs the purge to the same standard.
The responsible-recycling standard's data-security requirements. R2v3 certification belongs to your facility, not to equipment — Apex supplies the platform and, on our record-generating stations, the per-asset records your certifying body asks for.
Strict data-destruction and chain-of-custody expectations. Per-device records are built to feed the documentation e-Stewards facilities keep. The certification is held by the facility, not the machine.
The media-specific sanitization techniques Rev. 2 now points to in place of its own device tables. Our compliance strips cite it alongside NIST so the method is traceable to the medium.
The asset-disposal security certification recognized across the UK and EU. Apex's verification model is designed to align with ADISA's risk-based expectations.
Still offered where a contract or customer policy calls for it. Worth knowing: Rev. 2 declares multi-pass overwrite unnecessary — a single pass suffices — so we don't market extra passes as extra assurance.
The UK government's current guidance on secure media sanitization, published by the National Cyber Security Centre and supported by the wiping suites our drive and endpoint carts boot.
The obligation is the operator’s, the record is what evidences it. Where retired media holds regulated personal or health data — HIPAA, GDPR and their equivalents — every asset is documented so you can show what was done to it.
On the eleven machines where Apex software generates the record, this is what it holds and what it is built to satisfy. A fifth control is in engineering, and it is named below rather than implied.
Every asset is identified at intake by its serial or per-device identifier — serial, IMEI or MAC — and recorded through to a documented disposition. Custody opens at intake and closes as released, quarantined or routed to destruction. It is never left open.
Each record carries the method used, the tool and its version, the operator who performed the action, the result, and a timestamp. A result is PASS, FAIL or QUARANTINED; a record with no result is an open custody event.
Records are written to your own NAS in a structured, exportable format — a per-asset PDF and a CSV or JSON lot file carrying the full field set. Nothing depends on Apex hosting anything, and nothing has to leave your facility.
The record set is built to satisfy the documentation expectations of NIST SP 800-88 Rev. 2, aligned to IEEE 2883-2022 — the fields an auditor asks for during your certification, in the form they ask for them.
Linked record hashes, per-machine signing with a published public key, and append-only enforcement at the database layer are specified and in development. They are not in the shipping software today, and we will not describe them as though they are. We would rather tell you what the record does now and announce the rest when it ships.
The fleet splits in two. On eleven machines Apex software produces the record; on eight the certificate comes from your own licensed wipe suite. We never present someone else's certificate as ours.
Apex software produces the per-device certificate and a custody log: every asset uniquely identified from the device itself, every state change carrying an accountable operator and a synchronized timestamp, and every record written to your own NAS in a structured, exportable format.
Your PXE wipe suite — WipeOS or any licensed third party — performs the sanitization and issues the certificate. Apex supplies the platform, the physical custody controls (lockable quarantine bin, locks, seals) and the operating environment. We will never represent those certificates as our own.
NIST SP 800-88 Rev. 2 separates them, and so do the records. Verification confirms that this specific action succeeded on this specific device. Validation is the program-level determination, made in advance and backed by documented evidence, that a method is effective for an entire class of devices. Both appear on every Apex-generated record.
Five custody events, from intake to documented disposition. Step through them and watch the record fill — these are the fields the chain-of-custody specification requires on every machine that generates its own record.
Field names and custody events above are taken from the chain-of-custody specification. Values are masked sample data for illustration, not a real certificate. This applies to machines where Apex generates the record — on the wipe carts your own licensed suite issues the certificate instead.