From account to Certificate of Destruction in eight steps. No vendor hardware, no lock-in — just a script you can read and a trail you can prove.
Register at tscrub.com/register as a personal or company account, verify your email, then sign in.
Every tScrub appliance needs a licence — even the free tier. Free licences are self-serve from your dashboard Licences page and self-sign their reports (tamper-evident, not attributable). Paid licences (pay-as-you-go, Team, Enterprise) add vendor-signed (attributable) reports and a digitally signed certificate — they're issued by the tScrub team, so contact us.
Download the bootable appliance ISO from the Download page, then sign in and issue your .lic from your dashboard's Licences page.
Boot the ready-to-go tScrub appliance image from USB or PXE and run it. No installation needed.
Secure Boot is supported: on the first boot on a machine, shim opens MokManager — Enroll MOK → Continue → Yes, then reboot. (Alternatively, disable Secure Boot.)
tScrub prompts for a 5-digit Chain of Custody ID, discovers every drive and maps it to its strongest NIST 800-88 method, then wipes all supported drives in parallel — capturing pre- and post-wipe SMART data.
The report (CSV + signature + manifest) is written to the boot USB automatically, or you can push it straight to your dashboard (tscrub_api_token=) or over FTP/SFTP (tscrub_output=ftp:… / tscrub_output=sftp:…) — all built into the tScrub appliance image.
Back in the dashboard, upload the report files on the Reports page, then select the Chain of Custody ID on the Certificates page to generate a consolidated, printable Certificate of Destruction — device annex (Annex A) plus pre/post SMART annex (Annex B). Every certificate carries a verification QR code; paid licences additionally get a digitally signed PDF.
Anyone can scan the certificate's QR code — or visit tscrub.com/verify?cert=COD-… — to view the issuance record, including a SHA-256 of the PDF itself. Signed (paid) certificates show a full verification; free-tier certificates are marked self-signed and not independently attributable.
tscrub # full run (wipes all supported drives) tscrub --dry-run # discover and classify, wipe nothing tscrub --output /mnt/usb # write the report to /mnt/usb tscrub --license /path/x.lic # supply the licence explicitly tscrub verify report.csv # verify a report (SHA-256 + signature)
Full documentation: tscrub.com/docs.
Create a free account and issue your first licence — or contact us about signed reports and support.