Arc ITAD

Arc ITAD Secure IT asset disposition, data destruction, and electronics recovery for businesses, schools, healthcare, and public sector organizations.

Most equipment in disposition now is encrypted by default. A modern laptop, phone, or tablet stores everything as cipher...
06/17/2026

Most equipment in disposition now is encrypted by default. A modern laptop, phone, or tablet stores everything as ciphertext, scrambled by a key in the hardware. Sanitizing it does not always mean overwriting the data block by block. Destroy the key the device used, and the contents become permanently unreadable. NIST SP 800-88 recognizes this as cryptographic erase. The catch is verification: it only holds if the device was encrypting from first use and the key destruction can be confirmed. Modern device tooling like Phonecheck, with its MacCheck, WinCheck, and Chromecheck modules, runs this kind of erase at the device level and logs the result.

Districts do not retire student devices in a steady trickle. It happens over the summer, in the gap between school years...
06/12/2026

Districts do not retire student devices in a steady trickle. It happens over the summer, in the gap between school years.

That compresses a year of disposition into a few weeks. A 1:1 district can move thousands of Chromebooks and laptops off its books before students return, each one carrying grades, logins, and years of student activity.

The compressed timeline does not lower the bar. A student device leaving district custody still holds education records protected under FERPA, whether it leaves in June or January.

A summer retirement that holds up is planned like one: scope set before the last bell, a named custody contact, and sanitization documented per device.

arcITAD runs K-12 disposition on the academic calendar for that reason.

FERPA is the student-privacy law every district knows. It's also just the floor.FERPA bars the unauthorized disclosure o...
06/09/2026

FERPA is the student-privacy law every district knows. It's also just the floor.

FERPA bars the unauthorized disclosure of student records, but it does not prescribe how data has to be secured or destroyed, and it does not audit anyone. At least 128 student-privacy laws across more than 40 states fill that gap.

That shows up at disposal. Retired student devices left at a recycler still hold education records, and several states regulate how that data has to be destroyed.

Documented sanitization, tied to each device, is how a district puts the data beyond reach and can prove it did.

A vendor's certifications page lists ISO 9001, ISO 14001, and ISO 45001, and most reviews check the box and move on. The...
06/01/2026

A vendor's certifications page lists ISO 9001, ISO 14001, and ISO 45001, and most reviews check the box and move on. The badges are real and audited. They're also not about your data.

Those three certify how a facility is run: quality management, environmental management, and worker health and safety.

None of them describes how a drive is sanitized or how custody is documented after a device leaves your building.

That is a separate question with its own standards. NIST SP 800-88 covers sanitization and R2v3 covers the partners a device routes through after the facility.

When you evaluate a vendor on data handling, those are the standards to check.

A leased fleet reaches end of term and goes back to the lessor. The lease closes and the hardware comes off the books. A...
05/28/2026

A leased fleet reaches end of term and goes back to the lessor.

The lease closes and the hardware comes off the books. At this point, the asset side of the transaction is settled.

The data side usually is not. A lessor's obligation is the return condition of the equipment, not the record of how the data on it was handled. Whatever sanitization happens after the return happens on their timeline, under their documentation.

Very little of it comes back to you in a form you can put in an audit file.

So the fleet is gone and the paper trail went with it. Months later a cyber-insurance renewal or an FTC Safeguards Rule review asks how a specific serial was sanitized, and the honest answer is that the organization handed that question to a third party and never got it back.

A defensible return keeps the data trail on your side of the line.

Corporate hardware does not leave through one door. Upgrades, leased returns, offboarding boxes, and the storage closet ...
05/26/2026

Corporate hardware does not leave through one door.

Upgrades, leased returns, offboarding boxes, and the storage closet that nobody has opened in two years are all disposition events, whether or not they were treated as one.

Each is a device that held corporate data leaving the organization's control.

A real program treats them the same way: verified sanitization per device, a certificate tied to the serial, and a reconciliation file matching what left against what was processed.

Verizon just released the 2026 Data Breach Investigations Report. Headline: 48 percent of breaches now involve a third p...
05/20/2026

Verizon just released the 2026 Data Breach Investigations Report. Headline: 48 percent of breaches now involve a third party, up 60 percent year over year.

Most of that number is software supply chain risk. Some of it is physical. An ITAD vendor is a third party with access to the drives that came out of production hardware, and a drive that leaves the building without verified sanitization is the same data exposure as a drive still inside it.

Defensible disposition produces a sanitization certificate per device, a reconciliation file matching pickup to processing, and R2v3 downstream accountability for what happens after the device leaves the facility.

Third-party risk dashboards usually do not include disposition. The 48 percent does not care.

Two healthcare IT vendors have signed identical BAAs. One wipes every drive to NIST SP 800-88 Purge with a per-device ce...
05/11/2026

Two healthcare IT vendors have signed identical BAAs. One wipes every drive to NIST SP 800-88 Purge with a per-device certificate, while the other runs a factory reset and ships the laptops to a recycler. Both have a signed BAA on file but only one has a defensible disposition.

A defensible disposition for PHI-bearing devices needs three things the BAA does not contain:
→ The sanitization standard the vendor follows
→ A per-device certificate that names the method and tool
→ A chain of custody from the facility to verified destruction.

The BAA covers the responsibility and the closeout package covers the rest.

A Chromebook closeout and an iPhone closeout do not produce the same sanitization certificate. The implementation is dif...
05/07/2026

A Chromebook closeout and an iPhone closeout do not produce the same sanitization certificate. The implementation is different.

Chromebook storage is eMMC. Sanitization runs through the device's verified factory reset, which performs a cryptographic erase while preserving the OS. The certificate names the device serial and the method.

iPhone and iPad storage is NAND with a hardware-backed Secure Enclave. The Purge method here is also cryptographic erase. The Secure Enclave destroys the media encryption key, and the data on the flash chip becomes ciphertext. The certificate names the IMEI or serial and the method.

Both paths meet NIST SP 800-88 Purge. They look different on paper because the work is different.

A closeout package that shows the same certificate for a laptop and a phone has not actually documented the work.

Every arcITAD project ends with the same four-part closeout: reconciliation, sanitization certificates, disposition reco...
05/04/2026

Every arcITAD project ends with the same four-part closeout: reconciliation, sanitization certificates, disposition record, and financial closeout.

Clients and device types change from one project to the next. The deliverable structure does not.

The closeout package is what an auditor will read six months later, without our process notes and without our team on the phone. Everything they need should already be in the documents.

Address

Warminster, PA
18974

Alerts

Be the first to know and let us send you an email when Arc ITAD posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Share