06/17/2026
Most equipment in disposition now is encrypted by default. A modern laptop, phone, or tablet stores everything as ciphertext, scrambled by a key in the hardware. Sanitizing it does not always mean overwriting the data block by block. Destroy the key the device used, and the contents become permanently unreadable. NIST SP 800-88 recognizes this as cryptographic erase. The catch is verification: it only holds if the device was encrypting from first use and the key destruction can be confirmed. Modern device tooling like Phonecheck, with its MacCheck, WinCheck, and Chromecheck modules, runs this kind of erase at the device level and logs the result.