Skip to content
Hard drives prepared for certified secure data destruction

Evidence

Audit trails you can recompute.

Every donation and corporate assessment writes an append-only SHA-256 chain. The pages below show the ISO/IEC 27001:2022 controls that log maps to — and they do not invent a certificate number.

Not a membership seal

Logging is live. A certificate number is not listed.

ISO/IEC 27001 is a management-system standard. RecyclicTech implements the Annex A practices that an ITAD operator can actually run today: inventory, transfer, evidence, record protection, storage media, information deletion and logging. Company ISO 27001 or ADISA seals go on this site only with a registration number a buyer can check. Until then the trail is the proof.

How a record is written

Append. Hash. Never rewrite.

  1. 01A public reference is mintedEDU- for education donations, RT- for corporate assessments. That code is the only public key. There is no directory of people.
  2. 02Operational facts go on the logEquipment categories, origin country, courier, tracking presence, sanitisation method when it exists. Names, emails and street addresses stay on the job row, not on the hash chain.
  3. 03SHA-256 binds each event to the lastAlgorithm SHA-256. Chain recyclictech-v1. Each event stores the previous hash, a canonical input string, and the digest of that string.
  4. 04The table refuses editsUpdates and deletes on audit events raise an error. New facts are new rows. Pending stages on the evidence page stay blank until someone actually does the work.

ISO/IEC 27001:2022 Annex A

Controls this log implements

Cited by number so an auditor can map them. Described in operating language so a facilities manager can read them.

ControlTitleHow RecyclicTech uses it
A.5.9Inventory of information and other associated assetsEach donation or assessment opens an inventory event with equipment categories, counts and origin country — not a public listing of people.
A.5.12Classification of informationData-bearing kit is flagged on the record so sanitisation is not optional later in the chain.
A.5.14Information transferCourier collection, label issue and inbound transfer to the Rădăuți processing depot are written as transfer events.
A.5.28Collection of evidenceEvery event is hashed and chained to the previous event. The public reference is the capability to read that chain.
A.5.31Legal, statutory, regulatory and contractual requirementsGDPR consent is recorded as a boolean event. WEEE routing is recorded when processing completes.
A.5.33Protection of recordsThe audit table rejects updates and deletes. New facts are appended. Old rows are not rewritten.
A.7.10Storage mediaDrives and other media stay on the inventory until a sanitisation or destruction event closes them.
A.8.10Information deletionWhen sanitisation runs, the method (NIST 800-88 Clear / Purge / Destroy) is written. That event is not invented in advance.
A.8.15LoggingThis log. Actor is stored as a hash of an email, never the address itself. Payloads hold operational facts only.
A.8.16Monitoring activitiesOpening a trail re-computes each SHA-256 and reports whether the chain still verifies.

What you receive in writing

  • A hash-chained audit trail against the public reference, readable without an account.
  • A certificate of data destruction per drive or serial — when sanitisation has actually run.
  • Chain of custody, itemised asset report, WEEE / duty-of-care papers, ESG summary.
  • NIST 800-88 methods for Clear, Purge or Destroy. Physical shredding on request.

Sanitisation events are not pre-written at booking. If a line is still in “not yet recorded”, the work has not happened.

Tell us what you have

Stuck with retired IT inventory?

Free collection for organisations. We de-install, destroy the data, recycle what cannot be reused, document the job — and share residual value as a rebate.