Get started with tScrub

From account to Certificate of Destruction in eight steps. No vendor hardware, no lock-in — just a script you can read and a trail you can prove.

01

Create your account

Register at tscrub.com/register as a personal or company account, verify your email, then sign in.

02

Get a licence

Every tScrub appliance needs a licence — even the free tier. Free licences are self-serve from your dashboard Licences page and self-sign their reports (tamper-evident, not attributable). Paid licences (pay-as-you-go, Team, Enterprise) add vendor-signed (attributable) reports and a digitally signed certificate — they're issued by the tScrub team, so contact us.

03

Download the appliance and licence

Download the bootable appliance ISO from the Download page, then sign in and issue your .lic from your dashboard's Licences page.

04

Boot the appliance

Boot the ready-to-go tScrub appliance image from USB or PXE and run it. No installation needed.

Secure Boot is supported: on the first boot on a machine, shim opens MokManager — Enroll MOK → Continue → Yes, then reboot. (Alternatively, disable Secure Boot.)

05

Run a sanitisation job

tScrub prompts for a 5-digit Chain of Custody ID, discovers every drive and maps it to its strongest NIST 800-88 method, then wipes all supported drives in parallel — capturing pre- and post-wipe SMART data.

06

Get the report out

The report (CSV + signature + manifest) is written to the boot USB automatically, or you can push it straight to your dashboard (tscrub_api_token=) or over FTP/SFTP (tscrub_output=ftp:… / tscrub_output=sftp:…) — all built into the tScrub appliance image.

07

Generate a Certificate of Destruction

Back in the dashboard, upload the report files on the Reports page, then select the Chain of Custody ID on the Certificates page to generate a consolidated, printable Certificate of Destruction — device annex (Annex A) plus pre/post SMART annex (Annex B). Every certificate carries a verification QR code; paid licences additionally get a digitally signed PDF.

08

Verify anytime

Anyone can scan the certificate's QR code — or visit tscrub.com/verify?cert=COD-… — to view the issuance record, including a SHA-256 of the PDF itself. Signed (paid) certificates show a full verification; free-tier certificates are marked self-signed and not independently attributable.

Command reference

tscrub                          # full run (wipes all supported drives)
tscrub --dry-run                # discover and classify, wipe nothing
tscrub --output /mnt/usb        # write the report to /mnt/usb
tscrub --license /path/x.lic    # supply the licence explicitly
tscrub verify report.csv        # verify a report (SHA-256 + signature)

Full documentation: tscrub.com/docs.

Ready to wipe with a verifiable trail?

Create a free account and issue your first licence — or contact us about signed reports and support.