Compliance
The standards, and where we actually stand against them
If sensitive records are disposed of improperly, the liability lands on the organisation that owned the data — not on the vendor who carried it away. That is the whole reason this page exists, and the reason it ends with a list of what we cannot yet claim.
NAID AAA certification
Not certifiedNo application filedNAID AAA, administered by i-SIGMA, is the certification most destruction solicitations name. Silverback does not hold it, and no application has been filed. Saying “certification in progress” on a page a contracting officer reads would imply something is in flight, and nothing is.
It could not be, yet. The audit needs a facility to inspect, vehicles to physically inspect, screened employees with files already on record, and ninety consecutive days of recorded CCTV in hand before the auditor arrives. Certification is the intention; the operation is being built to each line opposite so that it is a formality rather than a rebuild.
Scheduled and unannounced audits
Scheduled audits every two years, with random unannounced audits layered on, and annual reapplication
Physical security
Access control, alarm, and surveillance for facility and vehicles
Operational procedures
Written and followed for collection, transport, and destruction
Employee screening and training
Background screening before any access to customer information, plus documented security training
Recordkeeping
Tracking that reconciles every container from collection to destruction
Destruction specification
Equipment operated and verified against the specification claimed, per media type
Surveillance history
Ninety consecutive days of recorded CCTV already on hand at the time of audit
NIST SP 800-88 Rev. 2
The standard defines three categories of sanitization. Clear overwrites data using the device’s own interfaces. Purge renders recovery infeasible even with laboratory techniques. Destroy makes the media itself unusable. Once media leaves organisational control, Destroy is the category that applies, and it is the only one we perform.
| Technique | Result | Applied to |
|---|---|---|
| Disintegration | Cut repeatedly against a screen until nothing passes intact | Drives, tape, optical media, badges |
| Pulverization | Crushed and broken down to fragments and dust | Platters, circuit boards, solid-state media |
| Shredding | Cross-cut on equipment operated to its manufacturer specification | Paper, film, drives, optical media |
| Melting | Metal reduced past any recoverable form | Drive platters and metal carriers |
| Incineration | Burned to complete combustion at a licensed facility | Material a regulator requires be burned |
What “destroyed” has to mean, by media
Almost every vendor site in this industry quotes a particle size in millimetres or a 5/8 inch figure. Those numbers are marketing, or they are foreign-government endorsements repeated out of context. The i-SIGMA certification specification sets no fixed particle size for paper at all, and for drives it sets an outcome rather than a dimension. Here is what it actually requires.
Paper and printed media
The manufacturer's specification for the equipment in use, within a 1/16 inch deviant tolerance
There is no single NAID particle size for paper. The 5/8 inch figure quoted across the industry is vendor marketing, not a requirement, and we do not print it.
Microfiche and microfilm
1/8 inch maximum dimension
One of the few media types with an explicit dimensional requirement.
Hard disk drives
Damaged to the point where the platters will not engage
An outcome requirement, not a size. A drive that still spins has not been destroyed, whatever it measures.
Solid-state media
Damaged to the point where they are unable to be used
Applies to SSDs, thumb drives, and memory cards, where a single surviving chip can hold the whole record.
FBI CJIS Security Policy
Any private contractor providing records management, ITAD, or IT support to a criminal justice agency falls inside the policy. Criminal justice information includes fingerprint and biometric data, criminal history and identity history records, stolen property records, wanted and missing person data, and NICS data.
The consequences of getting this wrong are not commercial. They run to suspension of NCIC, NICS, and NGI access, loss of federal grant funding, and criminal exposure for unauthorised disclosure.
One correction worth making, because most vendor sites in this industry get it wrong: the CJIS Security Policy does not reference NIST SP 800-88 anywhere. MP-6 sets its own requirements, listed opposite. We build to SP 800-88 Rev. 2 as our own sanitization framework — that is our choice of method, not a CJIS mandate, and we will not present it as one.
§5.8 Media Protection — control MP-6
- Digital media sanitized or destroyed before disposal, release out of agency control, or reuse — by overwriting at least three times, or by degaussing
- Inoperable digital media destroyed rather than sanitized
- Non-digital media destroyed by crosscut shredding or incineration
- Destruction witnessed, or carried out only by authorised personnel
- Chain of custody and a certificate naming the method used
Personnel security — §5.12 / control PS-3
Every individual with access to CJI-bearing media must be screened before that access is granted, and the screening has to be on record with the agency. Silverback has no employees yet, so there is nothing to screen and nothing to represent. The screening requirement is written into the hiring process ahead of the first hire rather than added afterwards.
We also hold no facility clearance and do not handle classified material. An FCL cannot be self-applied for — DCSA requires sponsorship by a government contracting activity or a cleared prime against a real procurement — so no page here will imply one.
Chain of custody
Six transfers, each one signed
Custody moves in one direction and the order is the evidence, so these are numbered because they are genuinely a sequence. A break at any step is an exception, and an exception is written into the record rather than out of it.
- 01
Container placed and locked
A locked console or bin is sited at your facility. Only the container is at your address; the key is not.
Captured: Container ID and placement location on the service agreement
- 02
Sealed before it moves
The container is closed and closed with a numbered tamper-evident seal in front of your staff member. That number is the thread through everything that follows.
Captured: Seal number, technician ID, customer signature, timestamp
- 03
Transported locked
The vehicle is locked and tracked for the whole route. Nothing is opened, consolidated, or transferred between vehicles in transit.
Captured: Route log with departure and arrival timestamps
- 04
Received and reconciled
Seals are checked against the manifest at the plant. A seal that does not match is an exception, and an exception is written into the record rather than out of it.
Captured: Seal verification, weight, receiving signature
- 05
Destroyed under observation
Destruction is performed by the stated method under camera. You may witness it in person, on site or at the plant.
Captured: Method, standard, operator ID, destruction timestamp
- 06
Certificate issued
The Certificate of Destruction is generated from the record above, not typed up afterwards. Every seal number reconciles or the certificate does not issue.
Captured: Certificate number, authorised signature, retained copy
Witnessing, stated accurately
MP-6 allows destruction to be witnessed or carried out only by authorised personnel. Where a customer needs the witness, it has to be a person: the CJIS glossary states that cameras or other electronic means used to monitor a physically secure location do not constitute an escort. Several competitors market a live video feed as CJIS-compliant witnessing. It is not, and if you are writing a statement of work, that distinction is worth putting in it explicitly.
Regulatory obligations we work to
FBI CJIS Security Policy
§5.8 Media Protection, control MP-6 · screening at §5.12 (v5.9.5) / PS-3 (v6.1)
Digital media sanitized or destroyed before disposal, release out of agency control, or reuse, by overwriting at least three times or by degaussing; inoperable digital media destroyed outright; non-digital media destroyed by crosscut shredding or incineration; and the destruction witnessed or carried out only by authorised personnel.
Applies to: Law enforcement, courts, corrections, and their contractors
NIST SP 800-88 Rev. 2
Guidelines for Media Sanitization, final 26 September 2025
Sanitization categorised as Clear, Purge, or Destroy, selected against the confidentiality of the data and whether the media leaves organisational control, with verification and a record of what was done.
Applies to: Federal information systems and anything that inherits from them
HIPAA Privacy and Security Rules
45 CFR §164.310(d)(2), §164.530(c)
Protected health information must be rendered unreadable, indecipherable, and unable to be reconstructed. Disposal is a covered function, which makes the destruction vendor a business associate.
Applies to: Covered entities and their business associates
FACTA Disposal Rule
16 CFR Part 682
Reasonable measures to protect against unauthorised access to consumer report information on disposal, including burning, pulverizing, or shredding, or contracting with a vendor engaged in the business of record destruction.
Applies to: Anyone who uses a consumer report for a business purpose
GLBA Safeguards Rule
16 CFR Part 314
A written information security program covering the secure disposal of customer information, with oversight of the service providers who carry it out.
Applies to: Financial institutions as defined by the FTC
What we do not yet hold
The list most vendor sites leave out
Silverback is a new company. None of the following exists yet, and none of it is claimed anywhere else on this site. It is here in one place so you can check it against anything else you read.
NAID AAA certified
Not heldNAID AAA granted by i-SIGMA after a passed audit. It cannot be applied for meaningfully before there is a facility to inspect, vehicles to inspect, screened employees with files on record, and ninety consecutive days of CCTV history already recorded. No application is in flight — this is an intention, not a pending status.
Registered in SAM.gov
Not heldSAM.gov registration in Active status, with the UEI and CAGE code populated in brand.ts.
Insured
Not heldPolicies bound and certificates of insurance in hand.
Background-screened personnel
Not heldAt least one employee hired and screened. There are no employees yet.
Past performance
Not heldA completed contract with a customer willing to be named as a reference.
Insurance
Commercial general liability
$2M minimum — the NAID AAA floor at spec 4.24(N)
Professional / cyber liability
Data-breach and errors-and-omissions cover
Commercial auto
Owned and hired vehicles carrying sealed containers
Workers' compensation
Statutory, all employees
Certificates of insurance are issued to the customer as additional insured once the policies are bound. Ask for the current position before you rely on it — and see the past performance section for the same treatment of contract history.