Skip to main content
SilverbackDestruction Services

Compliance

The standards, and where we actually stand against them

If sensitive records are disposed of improperly, the liability lands on the organisation that owned the data — not on the vendor who carried it away. That is the whole reason this page exists, and the reason it ends with a list of what we cannot yet claim.

NAID AAA certification

Not certifiedNo application filed

NAID AAA, administered by i-SIGMA, is the certification most destruction solicitations name. Silverback does not hold it, and no application has been filed. Saying “certification in progress” on a page a contracting officer reads would imply something is in flight, and nothing is.

It could not be, yet. The audit needs a facility to inspect, vehicles to physically inspect, screened employees with files already on record, and ninety consecutive days of recorded CCTV in hand before the auditor arrives. Certification is the intention; the operation is being built to each line opposite so that it is a formality rather than a rebuild.

  • Scheduled and unannounced audits

    Scheduled audits every two years, with random unannounced audits layered on, and annual reapplication

  • Physical security

    Access control, alarm, and surveillance for facility and vehicles

  • Operational procedures

    Written and followed for collection, transport, and destruction

  • Employee screening and training

    Background screening before any access to customer information, plus documented security training

  • Recordkeeping

    Tracking that reconciles every container from collection to destruction

  • Destruction specification

    Equipment operated and verified against the specification claimed, per media type

  • Surveillance history

    Ninety consecutive days of recorded CCTV already on hand at the time of audit

NIST SP 800-88 Rev. 2

The standard defines three categories of sanitization. Clear overwrites data using the device’s own interfaces. Purge renders recovery infeasible even with laboratory techniques. Destroy makes the media itself unusable. Once media leaves organisational control, Destroy is the category that applies, and it is the only one we perform.

Destroy techniques under NIST SP 800-88 Rev. 2 and the media each applies to
TechniqueResultApplied to
DisintegrationCut repeatedly against a screen until nothing passes intactDrives, tape, optical media, badges
PulverizationCrushed and broken down to fragments and dustPlatters, circuit boards, solid-state media
ShreddingCross-cut on equipment operated to its manufacturer specificationPaper, film, drives, optical media
MeltingMetal reduced past any recoverable formDrive platters and metal carriers
IncinerationBurned to complete combustion at a licensed facilityMaterial a regulator requires be burned

What “destroyed” has to mean, by media

Almost every vendor site in this industry quotes a particle size in millimetres or a 5/8 inch figure. Those numbers are marketing, or they are foreign-government endorsements repeated out of context. The i-SIGMA certification specification sets no fixed particle size for paper at all, and for drives it sets an outcome rather than a dimension. Here is what it actually requires.

  • Paper and printed media

    The manufacturer's specification for the equipment in use, within a 1/16 inch deviant tolerance

    There is no single NAID particle size for paper. The 5/8 inch figure quoted across the industry is vendor marketing, not a requirement, and we do not print it.

  • Microfiche and microfilm

    1/8 inch maximum dimension

    One of the few media types with an explicit dimensional requirement.

  • Hard disk drives

    Damaged to the point where the platters will not engage

    An outcome requirement, not a size. A drive that still spins has not been destroyed, whatever it measures.

  • Solid-state media

    Damaged to the point where they are unable to be used

    Applies to SSDs, thumb drives, and memory cards, where a single surviving chip can hold the whole record.

FBI CJIS Security Policy

Any private contractor providing records management, ITAD, or IT support to a criminal justice agency falls inside the policy. Criminal justice information includes fingerprint and biometric data, criminal history and identity history records, stolen property records, wanted and missing person data, and NICS data.

The consequences of getting this wrong are not commercial. They run to suspension of NCIC, NICS, and NGI access, loss of federal grant funding, and criminal exposure for unauthorised disclosure.

One correction worth making, because most vendor sites in this industry get it wrong: the CJIS Security Policy does not reference NIST SP 800-88 anywhere. MP-6 sets its own requirements, listed opposite. We build to SP 800-88 Rev. 2 as our own sanitization framework — that is our choice of method, not a CJIS mandate, and we will not present it as one.

§5.8 Media Protection — control MP-6

  • Digital media sanitized or destroyed before disposal, release out of agency control, or reuse — by overwriting at least three times, or by degaussing
  • Inoperable digital media destroyed rather than sanitized
  • Non-digital media destroyed by crosscut shredding or incineration
  • Destruction witnessed, or carried out only by authorised personnel
  • Chain of custody and a certificate naming the method used

Personnel security — §5.12 / control PS-3

Every individual with access to CJI-bearing media must be screened before that access is granted, and the screening has to be on record with the agency. Silverback has no employees yet, so there is nothing to screen and nothing to represent. The screening requirement is written into the hiring process ahead of the first hire rather than added afterwards.

We also hold no facility clearance and do not handle classified material. An FCL cannot be self-applied for — DCSA requires sponsorship by a government contracting activity or a cleared prime against a real procurement — so no page here will imply one.

No personnel yet

Chain of custody

Six transfers, each one signed

Custody moves in one direction and the order is the evidence, so these are numbered because they are genuinely a sequence. A break at any step is an exception, and an exception is written into the record rather than out of it.

  1. 01

    Container placed and locked

    A locked console or bin is sited at your facility. Only the container is at your address; the key is not.

    Captured: Container ID and placement location on the service agreement

  2. 02

    Sealed before it moves

    The container is closed and closed with a numbered tamper-evident seal in front of your staff member. That number is the thread through everything that follows.

    Captured: Seal number, technician ID, customer signature, timestamp

  3. 03

    Transported locked

    The vehicle is locked and tracked for the whole route. Nothing is opened, consolidated, or transferred between vehicles in transit.

    Captured: Route log with departure and arrival timestamps

  4. 04

    Received and reconciled

    Seals are checked against the manifest at the plant. A seal that does not match is an exception, and an exception is written into the record rather than out of it.

    Captured: Seal verification, weight, receiving signature

  5. 05

    Destroyed under observation

    Destruction is performed by the stated method under camera. You may witness it in person, on site or at the plant.

    Captured: Method, standard, operator ID, destruction timestamp

  6. 06

    Certificate issued

    The Certificate of Destruction is generated from the record above, not typed up afterwards. Every seal number reconciles or the certificate does not issue.

    Captured: Certificate number, authorised signature, retained copy

Witnessing, stated accurately

MP-6 allows destruction to be witnessed or carried out only by authorised personnel. Where a customer needs the witness, it has to be a person: the CJIS glossary states that cameras or other electronic means used to monitor a physically secure location do not constitute an escort. Several competitors market a live video feed as CJIS-compliant witnessing. It is not, and if you are writing a statement of work, that distinction is worth putting in it explicitly.

Regulatory obligations we work to

  • FBI CJIS Security Policy

    §5.8 Media Protection, control MP-6 · screening at §5.12 (v5.9.5) / PS-3 (v6.1)

    Digital media sanitized or destroyed before disposal, release out of agency control, or reuse, by overwriting at least three times or by degaussing; inoperable digital media destroyed outright; non-digital media destroyed by crosscut shredding or incineration; and the destruction witnessed or carried out only by authorised personnel.

    Applies to: Law enforcement, courts, corrections, and their contractors

  • NIST SP 800-88 Rev. 2

    Guidelines for Media Sanitization, final 26 September 2025

    Sanitization categorised as Clear, Purge, or Destroy, selected against the confidentiality of the data and whether the media leaves organisational control, with verification and a record of what was done.

    Applies to: Federal information systems and anything that inherits from them

  • HIPAA Privacy and Security Rules

    45 CFR §164.310(d)(2), §164.530(c)

    Protected health information must be rendered unreadable, indecipherable, and unable to be reconstructed. Disposal is a covered function, which makes the destruction vendor a business associate.

    Applies to: Covered entities and their business associates

  • FACTA Disposal Rule

    16 CFR Part 682

    Reasonable measures to protect against unauthorised access to consumer report information on disposal, including burning, pulverizing, or shredding, or contracting with a vendor engaged in the business of record destruction.

    Applies to: Anyone who uses a consumer report for a business purpose

  • GLBA Safeguards Rule

    16 CFR Part 314

    A written information security program covering the secure disposal of customer information, with oversight of the service providers who carry it out.

    Applies to: Financial institutions as defined by the FTC

What we do not yet hold

The list most vendor sites leave out

Silverback is a new company. None of the following exists yet, and none of it is claimed anywhere else on this site. It is here in one place so you can check it against anything else you read.

  • NAID AAA certified

    Not held

    NAID AAA granted by i-SIGMA after a passed audit. It cannot be applied for meaningfully before there is a facility to inspect, vehicles to inspect, screened employees with files on record, and ninety consecutive days of CCTV history already recorded. No application is in flight — this is an intention, not a pending status.

  • Registered in SAM.gov

    Not held

    SAM.gov registration in Active status, with the UEI and CAGE code populated in brand.ts.

  • Insured

    Not held

    Policies bound and certificates of insurance in hand.

  • Background-screened personnel

    Not held

    At least one employee hired and screened. There are no employees yet.

  • Past performance

    Not held

    A completed contract with a customer willing to be named as a reference.

Insurance

Not bound

Commercial general liability

$2M minimum — the NAID AAA floor at spec 4.24(N)

Not bound

Professional / cyber liability

Data-breach and errors-and-omissions cover

Not bound

Commercial auto

Owned and hired vehicles carrying sealed containers

Not bound

Workers' compensation

Statutory, all employees

Certificates of insurance are issued to the customer as additional insured once the policies are bound. Ask for the current position before you rely on it — and see the past performance section for the same treatment of contract history.