Open & auditable data erasure

Verifiable disk sanitisation for regulated IT.

tScrub erases NVMe, SATA, and SCSI drives to NIST 800-88 Clear, Purge, and Destroy levels — then hands you a verifiable, audit-ready chain-of-custody report you can turn into a Certificate of Destruction.

  • ✓ Single self-contained script — inspect every line
  • ✓ Boot our ready-to-go ISO from USB or PXE
  • ✓ Chain of custody with per-drive final status & certification
  • ✓ Erase to reuse — reclaim drives for redeployment, resale, or recycling
tscrub — sanitise session
operator@tscrub:~$
Aligns with NIST 800-88 GDPR HIPAA ISO 27001
Capabilities

Built for the drives your auditors ask about

Every capability maps to a defensible Clear, Purge, or Destroy outcome — with a report to prove it.

See compliance mapping →

NVMe sanitise

Crypto, block, and overwrite sanitise, plus format fallback — with live SSTAT progress monitoring.

ATA secure erase

Enhanced and standard security erase for SATA/ATA drives, with frozen-drive handling.

SED / OPAL unlock

PSID revert for locked self-encrypting drives, plus detection of BIOS Block SID lockdown (0x4286).

Chain of custody

COCID, drive serials, and per-drive final status — a verifiable CSV report, plus a Certificate of Destruction you can generate in seconds.

SMART capture

Pre- and post-wipe SMART health — status, temperature, power-on hours, and wear — recorded for every drive.

Open & auditable

One self-contained script. Your security team can read exactly what runs on the appliance.

Runs on your own hardware

Boot from USB or PXE on hardware you already own. No locked-down vendor box required.

Built for teams that answer to auditors

From regulated enterprises to IT asset disposal, tScrub gives you a defensible record of every drive.

Financial services

Evidence for decommissioned systems subject to FCA, PRA, and contractual data-handling rules.

Healthcare

A verifiable trail for media holding patient data, supporting UK GDPR and NHS requirements.

ITAD & refurbishers

A repeatable, branded wipe process you can show to your own clients.

Data centres

PXE-boot tScrub across fleets and keep a per-machine record on decommission.

From boot to certificate in four steps

  1. 1

    Boot

    Boot Linux from USB or PXE and run the script. tScrub needs zero installation.

  2. 2

    Discover & classify

    Every drive is detected and mapped to its best Purge or Clear capability.

  3. 3

    Sanitize

    Live progress across all drives, with frozen and blocked drives flagged.

  4. 4

    Report

    A chain-of-custody CSV with method, certification, final status, and pre/post SMART — upload it to generate a Certificate of Destruction.

Compliance

Mapped to NIST 800-88 outcomes

Every wipe method maps to a defensible Clear, Purge, or Destroy outcome — so the report survives an audit.

Explore compliance →

# method → NIST 800-88

NVMe Crypto Purge → Purge

ATA Enhanced Erase → Purge

ATA Secure Erase → Clear

Frozen / locked → Destroy

The open alternative to Blancco

Same compliance outcome, without the lock-in. Open source, run on your own hardware, transparent pricing.

See the comparison

Questions?

Find answers on certification, running tScrub on your own hardware, and edge cases.

Read the FAQ →

Ready to wipe with a verifiable trail?

Download the bootable appliance image, or see pricing for signed reports and support.