Doc. AQ-001 · Rev. 2026.02 · IT asset disposition

Every retired drive
leaves with a signature.

AUTONOMIQ runs the full decommissioning record — discovery, sanitization to NIST SP 800-88 Purge, hash-verified certificates and R2v3 downstream proof — so the answer to "where did that asset go?" is a document, not a guess.

Read the process
1.4M
Assets sanitized
0
Reported data recoveries
11 days
Median close-out time
98.4%
Resale value recovered

60%

of reported breaches involving physical media trace back to assets believed disposed.Blancco / Ontrack, resale-drive study

$4.88M

average total cost of a single data breach across US enterprises last reporting year.IBM Cost of a Data Breach

42%

of second-hand enterprise drives sampled still contained recoverable business data.University of Hertfordshire teardown

I. The exposure

Disposal is the only part of the asset lifecycle nobody instruments.

Procurement is tracked to the invoice. Deployment is tracked to the device. Then the asset reaches end of life and the record turns into an email thread.

01

The paper gap

A hauler receipt proves a pallet moved. It does not prove a drive was sanitized, does not name the method, and will not survive a regulator asking for serial-level evidence.

02

The custody gap

Between the desk, the storeroom shelf and the truck, most fleets have no timestamped custodian. That interval is where assets quietly go missing — and where liability sits.

03

The reconciliation gap

Finance depreciates an asset the ledger still shows as active. IT retires an asset finance never wrote off. Neither system agrees, so the disposal report is assembled by hand each quarter.

II. Chain of custody

Six stages, each one producing a document you can hand to an auditor.

This is the full record AUTONOMIQ maintains per asset. Nothing here is inferred after the fact.

Stage 01

Discovery & reconciliation

Read-only sync with Intune, Jamf, SCCM, Snipe-IT and your CMDB.

AUTONOMIQ ingests serial, model, storage controller type, encryption state, last check-in, warranty and lease terms, then reconciles the result against the finance ledger. Every discrepancy — ghost asset, orphaned serial, double-booked lease — is raised as a line item rather than absorbed silently.

  • Unified asset register
  • Ghost-asset exception list
  • Forecast EOL date per unit

Stage 02

Custody assignment

A named custodian and a timestamp for every physical hop.

Collection is issued as a scannable job. Each transfer — user to depot, depot to sanitization bay, bay to hauler — is signed by an identified custodian with device time, location and photo capture. The custody chain is append-only; a missed scan surfaces as an open interval, never as a silent gap.

  • Signed transfer records
  • Open-interval alerts
  • Photographic condition record

Stage 03

Sanitization

Method selected per media class, not per fleet-wide default.

SATA and SAS magnetic media receive an overwrite Purge; NVMe and SSDs receive vendor sanitize or cryptographic erase with key destruction where the controller supports it; self-encrypting drives are handled by verified key erasure. Media that fails sanitization is routed to physical destruction and shredded to a documented particle size.

  • Method + firmware log
  • Failure-to-destruction routing
  • Operator attribution

Stage 04

Verification

Independent read-back, not a self-reported completion flag.

Post-sanitization, a sampled read-back confirms the media returns no recoverable pattern. The tool records the controller response, the sampled sectors and the SHA-256 hash of the full log. A wipe utility claiming success is treated as an assertion until verification signs it.

  • Read-back sample report
  • SHA-256 log hash
  • Pass / fail disposition

Stage 05

Certification

A serial-level certificate of erasure, issued automatically.

Each asset receives a certificate naming the serial, media type, sanitization method and standard clause applied, operator, verification result and the hash of the underlying log. Certificates are immutable, individually retrievable and exportable as a bundle scoped to any date range an auditor asks for.

  • Per-asset certificate
  • Auditor export bundle
  • Immutable event log

Stage 06

Downstream disposition

Resale, redeployment or R2v3 recycling — settled and written back.

Assets with residual value route to remarketing with a floor price; the rest go to R2v3-certified processors with downstream vendor documentation retained. Settlement value, weight recycled and CO₂e avoided post back to your ERP so the disposal closes in the same ledger it opened in.

  • Settlement statement
  • Downstream vendor record
  • ERP write-back

III. The artifact

What an auditor actually receives.

One certificate per serial. No aggregate summaries, no "batch sanitized" language, no missing method field. Retrieval is by serial, date range, site or disposal event — typically under ten seconds, including for assets retired four years ago.

  • RetentionSeven years, extendable by contract
  • FormatPDF/A-3 with embedded JSON payload
  • IntegritySHA-256 over the sanitization log
  • VerificationPublic hash lookup, no login required

Certificate of Erasure

AUTONOMIQ Decommission

Serial no.

CE-2026-004417

Asset
LT-4471 · MacBook Pro 14,7
Media serial
C02XK1Q2JG5H
Media class
NVMe SSD, self-encrypting
Method
Cryptographic erase + key destruction
Standard
NIST SP 800-88r1, Purge
Verification
Read-back sampled, 512 sectors
Operator
M. Adeyemi · OP-0184
Completed
2026-02-11 09:42 UTC

Log hash (SHA-256)

9f2c41ab7d6e05c8b3f19a4472de8c0157bb93e6a4d21f8c7e5039ab6c14d7e2

Issued under AUTONOMIQ sanitization methodology AQ-SM-04. Disposition status: released for resale.

Verified

IV. Platform

Built for whoever signs the attestation.

01

Predictive end-of-life

Warranty expiry, lease return dates, depreciation schedule and battery or SMART health combine into a 90-day retirement forecast, so collection is planned rather than reactive.

02

Media-aware sanitization

Method selection follows the controller, not the fleet default. Magnetic, NVMe, SED, embedded eMMC and RAID-backed arrays each carry their own documented procedure.

03

Immutable event log

Append-only records of every actor, action and timestamp. Prior states remain readable; corrections are recorded as new events rather than edits.

04

ERP and ledger write-back

NetSuite, SAP and Oracle Fusion receive disposal date, settlement value and write-off entries so IT and finance close the same asset on the same day.

05

Site and residency controls

Per-site policy, regional data residency and configurable retention. Certificates for an EU estate never leave EU storage.

06

Vetted downstream network

R2v3 and e-Stewards processors with retained downstream documentation, so your recycling claim survives the second question as well as the first.

V. Field record

A two-year audit finding, closed in a quarter.

Regulated financial services estate, 4,120 assets across three regions, entering an external audit with no serial-level disposal evidence for the prior two years.

4,120
Assets processed in 14 weeks
11 days
Median retirement to certificate
100%
Assets with a signed custodian at every hop
$317k
Resale value returned to the ledger

Week 1–2 · Reconciliation

Read-only sync with Intune and the finance register surfaced 386 ghost assets and 94 serials booked twice against expiring leases.

Week 3–6 · Custody rollout

Depot and bay scanning replaced the shared spreadsheet. Open intervals dropped from a weekly average of 41 to zero by week six.

Week 7–12 · Sanitization at volume

Method selection per controller: crypto erase for SED laptops, NVMe format for servers, destruction for 212 units with unverifiable controllers.

Week 13–14 · Close-out

Certificates, custody chains and downstream manifests exported as a single auditor bundle; write-offs posted back to NetSuite in one batch.

Figures reported by the customer at close-out. Company name withheld under NDA; reference call available at contract stage.

VI. Control mapping

Which clause each artifact answers.

Auditors do not ask for a platform. They ask which control you satisfy and what proves it. This is the short version of that table.

→ Full security posture
NIST SP 800-88r1§4 Sanitization methodsMethod chosen per media controller; verification stored with each job.
ISO/IEC 27001:2022Annex A.8.10 Information deletionDocumented deletion procedure plus per-asset evidence of execution.
ISO/IEC 27001:2022Annex A.5.10 Acceptable use of assetsCustodian assignment and signed transfers for every physical hop.
SOC 2 Type IICC6.5 Disposal of assetsImmutable event log evidencing removal of data before disposition.
GDPRArt. 17 · Art. 32Erasure evidence for personal data held on retired media, retained for audit.
HIPAA§164.310(d)(2)(i)-(ii)Media re-use and disposal record, including destruction where required.
R2v3Core Requirement 7 · Appendix BDownstream vendor documentation retained with each disposition record.

V. In practice

Where the audit stakes are highest.

"We closed a two-year audit finding in six weeks. Every drive that leaves our estate now has a hash-verified certificate attached before it hits the loading dock."
Sarah JenningsCISO, FinSecure Group4,120 assets · 3 regions
"Our team was burning 20 hours a week on disposal spreadsheets. AUTONOMIQ schedules the wipes, pings the hauler and writes back to NetSuite without anyone touching a ticket."
David KwanVP IT Operations, CloudGrid18 hrs/week recovered
ACMEGLOBEXINITECHUMBRELLASOYLENTVEHEMENT

VI. Commercials

Priced per fleet, not per fire drill.

Every tier includes unlimited certificates, custody records and auditor exports. Collection and recycling are billed at cost with the settlement statement attached.

Starter

$1.5kper year

For lean IT teams retiring their first fleet.

Up to 500 assets

  • Intune or Jamf sync
  • NIST 800-88 Clear & Purge
  • Cryptographic erasure certificates
  • Email support
Most selected

Professional

$4.5kper year

For multi-site orgs with audit deadlines.

Up to 2,500 assets

  • Everything in Starter
  • Full REST API + webhooks
  • ERP sync (NetSuite / SAP)
  • Global hauler dispatch
  • Immutable audit log export

Enterprise

$15k+per year

For regulated estates and global fleets.

Unlimited assets

  • Everything in Professional
  • SSO / SCIM + custom RBAC
  • Dedicated compliance engineer
  • Custom retention & residency
  • 99.9% uptime SLA

VII. Questions raised

The objections we hear from security teams.

Answered plainly. If your question is not here, it is usually the one worth asking on a call.

VIII. Reference

Terms, defined precisely.

Most disposal disputes are vocabulary disputes. "Wiped" means four different things depending on who signed the ticket.

Clear
Logical overwrite resisting keyboard-level recovery. Suitable for redeployment inside the same trust boundary.
Purge
Sanitization resisting laboratory recovery — block erase, cryptographic erase or overwrite with verification.
Destroy
Physical shredding or disintegration to a documented particle size. Media is unusable afterwards.
Chain of custody
Unbroken, timestamped record of who held an asset between retirement and final disposition.
R2v3
SERI's Responsible Recycling standard, 2023 revision, governing processors and their downstream vendors.
Downstream vendor
Any party receiving material after your primary processor. Unverified downstream is where most recycling claims fail.

Next step

Close the gap before someone else finds it.

A compliance audit takes forty minutes: we reconcile a sample of your register, show where custody breaks, and hand back the findings whether or not you buy anything.