Records Destruction Certificate Generator
Generate a certificate of destruction that records what was destroyed, when, by which method, under whose authority and against which retention rule, with checks for the fields auditors ask about.
Last reviewed by the Radiatus Cloud team
Going for ISO 27001, SOC 2, HIPAA or GDPR?
Radiatus runs end-to-end compliance & GRC programs.
Deletion you cannot evidence is deletion you did not do
An organisation that deletes data correctly but keeps no record of it is in the same position, when asked, as one that never deleted anything. The certificate is the evidence, and it is what turns a routine disposal into something defensible: a document naming what was destroyed, when, by what method, under whose authority and against which retention rule. Producing it after the fact from memory is not the same exercise, because the details that matter are exactly the ones nobody remembers.
The method determines whether destruction actually occurred
Deleting a file marks its blocks as reusable; it does not remove the data. On modern solid-state storage, overwriting a specific file is not reliably possible at all because the controller writes elsewhere, which is why cryptographic erasure, destroying the key rather than the data, has become the recommended method for encrypted media. NIST SP 800-88 distinguishes clear, purge and destroy, and a certificate that says "deleted" without saying which of those happened records an intention rather than an outcome.
Backups and copies are where destruction fails
The most common defect in a destruction record is that it covers the primary system and nothing else. Data that has been removed from a database but persists in nightly backups, in an analytics warehouse, in a support ticket and in a departed employee's export has not been destroyed. A certificate that does not name the copies considered is silent on the question an auditor will ask first.
Related tools
- SOC 2 Evidence Readiness — Interactive checklist to gauge your SOC 2 evidence readiness.
- Privacy Policy Checker — Check if your policy covers standard requirements (GDPR/CCPA basics).
- Compliance Req Finder — Find which standards (ISO, SOC2, HIPAA) apply to your industry/region.
- Audit Readiness Planner — Plan your compliance audit timeline (SOC2, ISO) backwards from deadline.
Frequently Asked Questions
Why does the destruction method matter?
Because deleting a file marks its blocks reusable rather than removing the data. NIST SP 800-88 distinguishes clear, purge and destroy, and a record saying only "deleted" states an intention rather than an outcome.
What is cryptographic erasure?
Destroying the encryption key rather than the data, which renders the ciphertext unrecoverable. It is the recommended method for encrypted solid-state media, where overwriting a specific file is not reliably possible.
Must backups be covered?
They are where destruction most often fails. Data removed from a database but surviving in nightly backups, an analytics warehouse or a support ticket has not been destroyed, and a certificate silent on copies is silent on the first question an auditor asks.
Who should authorise a destruction?
Someone accountable for the records rather than the person performing the disposal. Separating the two is what makes the record evidence rather than an assertion by the one party with a reason to make it.
How long should the certificate be kept?
Longer than the records it describes, and usually indefinitely. It is small, and it is the only proof the disposal was authorised and carried out properly.
Privacy & Security
Everything runs in your browser; nothing is uploaded.
How to Use
Enter the disposal details to generate the certificate.
Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.
Related Tools
SOC 2 Evidence Readiness
ComplianceInteractive checklist to gauge your SOC 2 evidence readiness.
Privacy Policy Checker
ComplianceCheck if your policy covers standard requirements (GDPR/CCPA basics).
Compliance Req Finder
ComplianceFind which standards (ISO, SOC2, HIPAA) apply to your industry/region.