Cogent NetworksCogent Networks Cogent NetworksDriving Innovation, Powering Success. Cogent OS
Service line

Retire IT with evidence
for every serial -
defensibly.

Retired assets in a landfill, donated machines resurfacing for sale, drives you thought were destroyed - that is the risk ITAD exists to remove. We handle every item under documented custody, to recognised standards, with proof at the end.

NIST 800-88ISO 21964 / DIN 66399CHAIN OF CUSTODYCERTIFICATE PER ASSETWEEE
Per asset
Certificate, not per collection
On site
Destruction available at your premises
19
Hubs and entities for collection, to deliver globally
Live
Custody visible in the portal
The proposition

Disposal is the one process whose risk arrives after the work is done

The equipment leaves the building, the project closes, and the exposure sits dormant until a regulator, an insurer or an acquirer asks for evidence that a specific serial number was destroyed on a specific date by a specific method.

Most estates cannot answer that. Assets went to a recycler with a collection note rather than a certificate, the register was never reconciled against what actually left, and drives that were "wiped" have no record of the standard applied. The gap is rarely negligence - it is that disposal was bought as waste removal rather than as a controlled process.

We treat it as a controlled process with three delivery routes, one custody chain and a documentary output per asset. The standard applied is named on the certificate, so the evidence answers the question that will actually be asked.

Three ways we deliver

On site, wiped, or recovered

The right route depends on data sensitivity, residual value and whether anything readable is permitted to leave your building. Most estates use a mix.

On-site destruction

We bring the destruction to you. Nothing readable ever leaves your building.

·Mobile shredding trucks deployed to your site·Bench shredders for lower volumes and sensitive rooms·Secure collection boxes and bins, sealed and padlocked at the point of removal·Witnessed destruction - your team present if you wish·Real-time reporting: every stage visible in the portal as it happens·Serialised manifest signed before anything moves

Certified data wiping

Give hardware a second life. Erasure to a named standard, with a report per drive.

·Certified erasure software to NIST 800-88 Clear and Purge·A detailed report per drive for every operation·Reports reviewed for gaps before any device moves on·Failed or unverifiable drives diverted to physical destruction·Wiped assets flow to redeploy or resale·Activation-lock verification on mobile devices

Collection, recycling & value recovery

Secure transport into our custody, certified recycling, and revenue back where there is any.

·Secure transport from your site into our custody·WEEE-compliant recycling via certified downstream partners·Environmental reporting per project·Buy-back service with grading A to D·Resale channels and an agreed revenue share·Typically over 20% value recovery on Grade A and B
Chain of custody

Eight stages, unbroken

This is the spine of the service. Every stage produces a record, and the records are what make the certificate at the end defensible rather than decorative.

CHAIN OF CUSTODY
UNBROKEN
01
Sealed on site
Secure bins and boxes sealed and padlocked at the point of removal, in front of your team.
Collection manifest
02
Serialised manifest
Every item listed by serial and asset tag, signed by both parties before anything moves.
Tracking record
03
Tracked transport
Our own van or truck, or courier with tracking for transfers. Movement recorded against each serial.
Goods-in reconciliation
04
Receipt & reconciliation
Counted in against the manifest. Any difference opens a discrepancy record with an owner.
Asset register
05
Destruction or wipe
To the method agreed per media type, by our own workers in our own facility or on your site.
Destruction log
06
Evidence capture
Photograph of every destroyed drive with serial and date, before and after photographs, and short video of the destruction exercise.
Photo / video set
07
Certificate per asset
Method, date and operator named per serial - not a single certificate for a pallet.
Certificate per asset
08
Downstream documentation
Certified recycling documentation and environmental reporting for the audit file.
Recycling & WEEE docs
Real-time custody. Every stage, every serial, visible live in the portal as the work happens - with an immutable audit trail in Cogent OS. You do not wait for a report to find out where your assets are or what has been done to them.
Methods by media

What we do to which media, and what it proves

METHODMEDIAON SITEEVIDENCE PRODUCEDREUSABLE AFTER
Certified software erasureHDD, SSDYesPer-drive erasure report naming NIST 800-88 Clear or PurgeYes - redeploy or resale
Cryptographic erasureSelf-encrypting drivesYesKey-destruction record and verification reportYes - redeploy or resale
DegaussingMagnetic media, tapeYesDegauss record per item with field strengthNo
Drill or punchHDDYes - rapidPhotograph per platter housing with serial and dateNo
Crush or bendSSD, flash mediaYesPhotograph per device with serial and dateNo
ShreddingHDD, SSD, tape, opticalYes - mobile truck or benchPhotograph and video of the exercise, particle size to the agreed levelNo
Manufacturer reset and config wipeSwitches, routers, firewallsYes - via consoleConsole log and verification record per deviceYes - redeploy or resale
Mobile-device erasurePhones, tabletsYesErasure report plus activation-lock verificationYes - subject to lock status

The method is agreed per media type before work starts and named on the certificate. Where a drive cannot be verified as erased it is diverted to physical destruction rather than passed on - the second-life path is never assumed.

Security levels

Destruction to ISO 21964 and DIN 66399

Physical destruction is not one thing. The standards define media classes and P, H and E security levels that set particle size and process rigour, and the correct level depends on how sensitive the data was - not on what the shredder happens to be set to.

We agree the security level per estate before work starts, name it in the scope and name it again on the certificate. That is what lets an auditor confirm the destruction matched the data classification rather than taking the word "shredded" on trust.

Where different parts of an estate carry different classifications - a finance file server against a meeting-room display - we apply different levels rather than levelling everything up to the most expensive option or down to the cheapest.

Media classes

The standards classify media by type - magnetic, solid state, optical, paper and film - because each fails and each is recovered differently.

P, H and E levels

Protection levels set the maximum particle size and process for each class. Higher levels mean smaller particles and tighter verification.

Matched to sensitivity

The level is chosen against your data classification and written into the scope, so cost follows risk rather than habit.

Compliance

Standards we execute to, regulations we support

Erasure standards we execute to

NIST 800-88 Clear and Purge · The primary reference for sanitisation outcomes and the verification each requires.DoD 5220.22-M and ECE · Multi-pass overwrite schemes where a client policy or contract specifies them.HMG Infosec Standard 5 · Higher and lower standard, for UK public-sector and regulated estates.BSI-GS and BSI-GSE · German federal schemes where the estate or the client policy requires them.Cryptographic erasure · Key destruction on self-encrypting drives, with verification.Random-overwrite schemes · Where a specified pattern and pass count is mandated.Firmware-based erasure · Native sanitise commands, verified rather than trusted.

Regulations our process supports

GDPRUK DPA 2018CCPA / CPRAHIPAAGLBASOXPCI DSSPIPEDAPoPIAPDPA (Singapore)ISO 27001 estates

Supporting a regulation means our process produces the record that regulation expects - documented custody, a named method per serial, and a retention position on the evidence itself. It does not mean we certify your compliance; that remains yours, and we give you the artefacts to demonstrate it.

The right standard is chosen per engagement and named on the certificate. If a scope does not say which standard applies, the certificate it produces is worth very little.
Scenarios

When clients call us

Corporate IT refresh

A replaced fleet needs sanitising before it leaves. We collect from sites or receive through our warehouses, wipe what has residual value and destroy what does not.

Data centre decommission

Controlled de-rack with the hall restored to its handover condition - containment cleared, cabling removed, floor and cabinets returned as agreed.

Decommission with ship-back

Assets wiped, certified and returned to a designated site rather than disposed of, where equipment is being consolidated instead of retired.

Office closure

Full wipe and disposal across the whole IT estate, usually against a lease deadline, with the building handed back clear.

Decommission and relocation

Part of the estate moves and part retires. We keep the two streams separate under one custody record so nothing leaves the wrong way.

Ad-hoc and loose media

A cupboard of unaccounted drives and tapes. Secure bins are provided, contents serialised on receipt, and the unknown becomes a documented inventory.

On site

Tooling and a dedicated crew at your premises. Maximum control: nothing readable leaves the building, your team can witness, and the portal shows each stage as it happens. Costs more in travel and mobilisation, and needs a working area and access arrangements.

Off site, or hybrid

Off site waives travel cost and schedules flexibly around our facility capacity. Hybrid is the common answer on sensitive estates: storage media destroyed on site so nothing readable moves, chassis and non-data-bearing hardware processed off site for recycling and value recovery.

How we scope it

What we agree before quoting

A precise scope is what makes the certificate defensible. These are the points we settle in writing first - and the reason our quotes are comparable rather than optimistic.

01
Full device list and specifications
Counts, types, media and known faults
02
Site addresses and working hours
Per location, including access constraints
03
Collection windows
Dates and times, and any lease deadline
04
Disposal method per media type
Wipe, degauss, shred or reset, per class
05
DC restoration requirements
What condition the hall must be left in
06
Certificate requirements
Format, granularity and who receives them
07
Inventory, audit and reporting
What you need, and against which register
08
Site work instructions
Method statements, permits, escorts
09
Worker registration and NDAs
Named workers, access tickets, vetting
10
Packing materials
Bins, boxes, seals, pallets, protective packing
11
Tooling
Bench, shredder, truck, degausser, hand tools
12
Interim warehouse storage
Whether assets are held before processing
13
Project deadline
The date the whole exercise must be complete
14
Value recovery expectations
Grading basis and revenue-share position
Evidence & reporting

What you actually receive

Per asset and per job

Before and after photography of the work area and the assetsA destruction photograph per serial, with the date visibleShort video of the destruction exercise where witnessed destruction appliesAn erasure report per drive, reviewed for gaps before any device moves onA certificate of destruction per asset naming method, date and operatorA consolidated project report reconciled against the manifestRecycling and environmental documentation from the certified downstream chain

Where it lives

Everything is downloadable from the customer portal, live during the job rather than compiled afterwards. You watch the manifest reconcile and the certificates issue as the work proceeds.

The record is held in the immutable audit trail in Cogent OS, so an audit question years later is answered from the system with the evidence attached rather than from a folder someone hopes still exists.

Retention on the evidence itself is agreed per contract, because holding destruction records forever is its own data-protection question.

Sustainability

Disposal as a compliance and an environmental outcome

The same process that produces your audit evidence also determines whether the material is reused, recycled properly or quietly landfilled. Those are not separate questions, and a supplier who cannot document one usually cannot document the other.

Our chain is certified end to end: WEEE-registered disposal routes, responsible downstream partners audited for their own certifications, and material tracked to its destination rather than handed on. Reuse comes first where a device has life left, because reuse beats recycling on every environmental measure.

Environmental reporting is issued per project - what was reused, what was recycled by material stream, and what was diverted from landfill - so the disposal exercise contributes to your reporting instead of being an unexplained line in it.

Reuse first

Wiped and graded for redeploy or resale where value and condition allow.

Certified recycling

Material streams separated and processed through certified partners.

WEEE registered

Compliant routes with the documentation an audit expects.

Reported per project

Reuse, recycling and diversion figures issued with the project report.

The numbers

Recovery, turnaround and diversion

VALUE RECOVERY BY GRADE
Grade A>20%
Grade B>20%
Grade CPartial
Grade DRecycle only
CERTIFICATES ISSUED WITHIN SLA
98%
Per asset, against the agreed turnaround
DISPOSAL OUTCOME BY ASSET
2,160TOTAL
Wiped and remarketed 1,240Shredded - data bearing 480Recycled - no value 260Returned to stock 180
On site

How the work looks

Mobile shredding truck at a client site
Sealed and padlocked secure collection bins
Certified wiping bench with drive bays
Proof

A delivered engagement

CASE STUDY · GLOBAL SOCIAL-MEDIA COMPANY · WITNESSED ON-SITE HDD DESTRUCTION
100%
On-site destruction
Per hand-over
Custody documented and signed
Per serial
Certificate issued

A global social-media company needed hard drives destroyed under an unbroken, witnessed chain of custody - with the condition that no drive would ever leave the facility intact.

Our field workers arrived on site with a shredding truck. Drives were released only by the site custodian, handed to Cogent in sealed boxes with custody documentation presented and signed at the point of transfer. The drives were moved only within the facility - to the on-site staging area - and shredded there, in front of the custodian.

Every drive's serial number was captured before destruction, and a destruction receipt was issued against each individual HDD - serial by serial, not a single certificate for a pallet. The client's audit file holds a record for every drive: who released it, who received it, when it was destroyed, and the evidence behind it.

Anonymised by agreement. Client names available under NDA.

FAQ

Questions buyers ask

Who holds liability once the assets leave our building?

Custody transfers at a documented point, not at a vague one. The serialised manifest is signed by both parties before anything moves, and from that signature the assets are in our custody with our insurance position applying. Until the manifest is signed they are yours. That boundary is written into the engagement rather than assumed, which matters because an undocumented handover leaves the liability with you by default.

Can we witness the destruction?

Yes, and for on-site work it is common. Your team can be present at sealing, at the shredder and at the reconciliation. Where you cannot attend, the portal shows each stage as it happens with the destruction photographs and video appearing against each serial, so witnessing is possible remotely rather than only in person.

We have a cupboard of loose drives and tapes with no records. Can you handle that?

Yes - it is one of the most common first engagements. We provide secure bins, and the contents are serialised on receipt so the unknown becomes a documented inventory before anything is destroyed. The reconciliation report will show items you did not know you had, which is usually the most valuable part of the exercise.

Is there a minimum volume?

No. A single decommissioned server or a handful of drives is a legitimate job, priced accordingly, and we would rather do it properly than have it sit in a cupboard for two years. Large programmes are priced per asset with the method and grading basis agreed up front.

Can you handle estates across several countries?

Yes, through our nineteen country entities and their owned warehouses. Collection and processing happen in-country wherever possible, which avoids moving data-bearing media across borders unnecessarily. Where movement is required, the in-country entity handles it as importer or exporter of record with the customs documentation held against the custody record.

Related

Other service lines in this practice

IT ProcurementWarehouse + 3PL (WaaS)Practice overview

Got an estate to retire?

Send us the device list, the sites and the deadline. We will come back with the method per media type, the evidence you will receive and the value recovery you can expect.

Get a Quote Talk to an expert
+44 20 3936 1085 · INFO@COGENTNETWORKS.COM