Compliance

Records Destruction Certificate Generator

Generate a certificate of destruction that records what was destroyed, when, by which method, under whose authority and against which retention rule, with checks for the fields auditors ask about.

Last reviewed by the Radiatus Cloud team

The certificate appears here.

Going for ISO 27001, SOC 2, HIPAA or GDPR?

Radiatus runs end-to-end compliance & GRC programs.

Get a free readiness review

Deletion you cannot evidence is deletion you did not do

An organisation that deletes data correctly but keeps no record of it is in the same position, when asked, as one that never deleted anything. The certificate is the evidence, and it is what turns a routine disposal into something defensible: a document naming what was destroyed, when, by what method, under whose authority and against which retention rule. Producing it after the fact from memory is not the same exercise, because the details that matter are exactly the ones nobody remembers.

The method determines whether destruction actually occurred

Deleting a file marks its blocks as reusable; it does not remove the data. On modern solid-state storage, overwriting a specific file is not reliably possible at all because the controller writes elsewhere, which is why cryptographic erasure, destroying the key rather than the data, has become the recommended method for encrypted media. NIST SP 800-88 distinguishes clear, purge and destroy, and a certificate that says "deleted" without saying which of those happened records an intention rather than an outcome.

Backups and copies are where destruction fails

The most common defect in a destruction record is that it covers the primary system and nothing else. Data that has been removed from a database but persists in nightly backups, in an analytics warehouse, in a support ticket and in a departed employee's export has not been destroyed. A certificate that does not name the copies considered is silent on the question an auditor will ask first.

Related tools

Frequently Asked Questions

Why does the destruction method matter?

Because deleting a file marks its blocks reusable rather than removing the data. NIST SP 800-88 distinguishes clear, purge and destroy, and a record saying only "deleted" states an intention rather than an outcome.

What is cryptographic erasure?

Destroying the encryption key rather than the data, which renders the ciphertext unrecoverable. It is the recommended method for encrypted solid-state media, where overwriting a specific file is not reliably possible.

Must backups be covered?

They are where destruction most often fails. Data removed from a database but surviving in nightly backups, an analytics warehouse or a support ticket has not been destroyed, and a certificate silent on copies is silent on the first question an auditor asks.

Who should authorise a destruction?

Someone accountable for the records rather than the person performing the disposal. Separating the two is what makes the record evidence rather than an assertion by the one party with a reason to make it.

How long should the certificate be kept?

Longer than the records it describes, and usually indefinitely. It is small, and it is the only proof the disposal was authorised and carried out properly.

Privacy & Security

Everything runs in your browser; nothing is uploaded.

Data: None
Client-side-Side
Active
v1.0

How to Use

Enter the disposal details to generate the certificate.

Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.