The equipment leaves the building, the project closes, and the exposure sits dormant until a regulator, an insurer or an acquirer asks for evidence that a specific serial number was destroyed on a specific date by a specific method.
Most estates cannot answer that. Assets went to a recycler with a collection note rather than a certificate, the register was never reconciled against what actually left, and drives that were "wiped" have no record of the standard applied. The gap is rarely negligence - it is that disposal was bought as waste removal rather than as a controlled process.
We treat it as a controlled process with three delivery routes, one custody chain and a documentary output per asset. The standard applied is named on the certificate, so the evidence answers the question that will actually be asked.
The right route depends on data sensitivity, residual value and whether anything readable is permitted to leave your building. Most estates use a mix.
We bring the destruction to you. Nothing readable ever leaves your building.
Give hardware a second life. Erasure to a named standard, with a report per drive.
Secure transport into our custody, certified recycling, and revenue back where there is any.
This is the spine of the service. Every stage produces a record, and the records are what make the certificate at the end defensible rather than decorative.
| METHOD | MEDIA | ON SITE | EVIDENCE PRODUCED | REUSABLE AFTER |
|---|---|---|---|---|
| Certified software erasure | HDD, SSD | Yes | Per-drive erasure report naming NIST 800-88 Clear or Purge | Yes - redeploy or resale |
| Cryptographic erasure | Self-encrypting drives | Yes | Key-destruction record and verification report | Yes - redeploy or resale |
| Degaussing | Magnetic media, tape | Yes | Degauss record per item with field strength | No |
| Drill or punch | HDD | Yes - rapid | Photograph per platter housing with serial and date | No |
| Crush or bend | SSD, flash media | Yes | Photograph per device with serial and date | No |
| Shredding | HDD, SSD, tape, optical | Yes - mobile truck or bench | Photograph and video of the exercise, particle size to the agreed level | No |
| Manufacturer reset and config wipe | Switches, routers, firewalls | Yes - via console | Console log and verification record per device | Yes - redeploy or resale |
| Mobile-device erasure | Phones, tablets | Yes | Erasure report plus activation-lock verification | Yes - subject to lock status |
The method is agreed per media type before work starts and named on the certificate. Where a drive cannot be verified as erased it is diverted to physical destruction rather than passed on - the second-life path is never assumed.
Physical destruction is not one thing. The standards define media classes and P, H and E security levels that set particle size and process rigour, and the correct level depends on how sensitive the data was - not on what the shredder happens to be set to.
We agree the security level per estate before work starts, name it in the scope and name it again on the certificate. That is what lets an auditor confirm the destruction matched the data classification rather than taking the word "shredded" on trust.
Where different parts of an estate carry different classifications - a finance file server against a meeting-room display - we apply different levels rather than levelling everything up to the most expensive option or down to the cheapest.
The standards classify media by type - magnetic, solid state, optical, paper and film - because each fails and each is recovered differently.
Protection levels set the maximum particle size and process for each class. Higher levels mean smaller particles and tighter verification.
The level is chosen against your data classification and written into the scope, so cost follows risk rather than habit.
Supporting a regulation means our process produces the record that regulation expects - documented custody, a named method per serial, and a retention position on the evidence itself. It does not mean we certify your compliance; that remains yours, and we give you the artefacts to demonstrate it.
A replaced fleet needs sanitising before it leaves. We collect from sites or receive through our warehouses, wipe what has residual value and destroy what does not.
Controlled de-rack with the hall restored to its handover condition - containment cleared, cabling removed, floor and cabinets returned as agreed.
Assets wiped, certified and returned to a designated site rather than disposed of, where equipment is being consolidated instead of retired.
Full wipe and disposal across the whole IT estate, usually against a lease deadline, with the building handed back clear.
Part of the estate moves and part retires. We keep the two streams separate under one custody record so nothing leaves the wrong way.
A cupboard of unaccounted drives and tapes. Secure bins are provided, contents serialised on receipt, and the unknown becomes a documented inventory.
Tooling and a dedicated crew at your premises. Maximum control: nothing readable leaves the building, your team can witness, and the portal shows each stage as it happens. Costs more in travel and mobilisation, and needs a working area and access arrangements.
Off site waives travel cost and schedules flexibly around our facility capacity. Hybrid is the common answer on sensitive estates: storage media destroyed on site so nothing readable moves, chassis and non-data-bearing hardware processed off site for recycling and value recovery.
A precise scope is what makes the certificate defensible. These are the points we settle in writing first - and the reason our quotes are comparable rather than optimistic.
Everything is downloadable from the customer portal, live during the job rather than compiled afterwards. You watch the manifest reconcile and the certificates issue as the work proceeds.
The record is held in the immutable audit trail in Cogent OS, so an audit question years later is answered from the system with the evidence attached rather than from a folder someone hopes still exists.
Retention on the evidence itself is agreed per contract, because holding destruction records forever is its own data-protection question.
The same process that produces your audit evidence also determines whether the material is reused, recycled properly or quietly landfilled. Those are not separate questions, and a supplier who cannot document one usually cannot document the other.
Our chain is certified end to end: WEEE-registered disposal routes, responsible downstream partners audited for their own certifications, and material tracked to its destination rather than handed on. Reuse comes first where a device has life left, because reuse beats recycling on every environmental measure.
Environmental reporting is issued per project - what was reused, what was recycled by material stream, and what was diverted from landfill - so the disposal exercise contributes to your reporting instead of being an unexplained line in it.
Wiped and graded for redeploy or resale where value and condition allow.
Material streams separated and processed through certified partners.
Compliant routes with the documentation an audit expects.
Reuse, recycling and diversion figures issued with the project report.
Devices reach us from three directions, and the value recovered feeds back into the next refresh rather than disappearing.
Every faulty unit replaced on site travels back through the warehouse and into either RMA or certified disposal, so nothing accumulates in a cupboard.
Open the service page →End-of-life stock and unreturned leaver devices are segregated in the facility and routed into the disposal line under the same custody model.
Open the service page →Displaced fleets collected as the new devices deploy, wiped and graded, with recovered value reported against the programme.
Open the service page →


A global social-media company needed hard drives destroyed under an unbroken, witnessed chain of custody - with the condition that no drive would ever leave the facility intact.
Our field workers arrived on site with a shredding truck. Drives were released only by the site custodian, handed to Cogent in sealed boxes with custody documentation presented and signed at the point of transfer. The drives were moved only within the facility - to the on-site staging area - and shredded there, in front of the custodian.
Every drive's serial number was captured before destruction, and a destruction receipt was issued against each individual HDD - serial by serial, not a single certificate for a pallet. The client's audit file holds a record for every drive: who released it, who received it, when it was destroyed, and the evidence behind it.
Anonymised by agreement. Client names available under NDA.
Custody transfers at a documented point, not at a vague one. The serialised manifest is signed by both parties before anything moves, and from that signature the assets are in our custody with our insurance position applying. Until the manifest is signed they are yours. That boundary is written into the engagement rather than assumed, which matters because an undocumented handover leaves the liability with you by default.
Yes, and for on-site work it is common. Your team can be present at sealing, at the shredder and at the reconciliation. Where you cannot attend, the portal shows each stage as it happens with the destruction photographs and video appearing against each serial, so witnessing is possible remotely rather than only in person.
Yes - it is one of the most common first engagements. We provide secure bins, and the contents are serialised on receipt so the unknown becomes a documented inventory before anything is destroyed. The reconciliation report will show items you did not know you had, which is usually the most valuable part of the exercise.
No. A single decommissioned server or a handful of drives is a legitimate job, priced accordingly, and we would rather do it properly than have it sit in a cupboard for two years. Large programmes are priced per asset with the method and grading basis agreed up front.
Yes, through our nineteen country entities and their owned warehouses. Collection and processing happen in-country wherever possible, which avoids moving data-bearing media across borders unnecessarily. Where movement is required, the in-country entity handles it as importer or exporter of record with the customs documentation held against the custody record.
Send us the device list, the sites and the deadline. We will come back with the method per media type, the evidence you will receive and the value recovery you can expect.