At a Glance
What this capability includes.
This page covers the wipe tools, SSD handling, method options, verification outputs, and review data available in the sanitization capability.
Software wipe/overwrite
Native Overwriter, GNU shred, and GNU dd options for whole-drive sanitization.
SSD handling
TRIM/UNMAP and sanitize paths are used where the drive and connection expose usable support.
Method options
Shield-399 presents wipe methods that fit the connected drive and suppresses unsafe or unsupported paths.
Verification outputs
Selected-block sampling, full-surface checks, and filesystem-signature results can be retained for review.
Capability Boundaries
01 / Safety Gate
Destination drives only.
Drive wiping is destructive, so Shield-399 only performs sanitization against destination drives. Source drives remain write-protected and are not eligible for wipe operations.
- Target drive must be set as a destination drive
- Source drives are excluded from sanitization workflows
- Explicit operator confirmation is required before execution
- The operation record includes selected method and target drive information
Primary Wipe Tools
02 / Overwrite Engines
Software overwrite options.
Shield-399 provides multiple software-overwrite engines for destination-drive wiping when direct overwrite is the appropriate method or device-assisted erase is unavailable.
- Selectable software-overwrite engines include the native Overwriter, GNU shred, and GNU dd
- Configurable native overwrite passes from 1 to 100, with Basic (1), Standard (3), High (7), and Maximum (35) presets
- Zero fill, one fill, and cryptographic random data
- Whole-drive overwrite across the detected addressable device size
03 / SSD Handling
SSD discard and sanitize paths.
Solid-state media is handled differently from spinning media. For supported SSD paths, Shield-399 can issue TRIM/UNMAP through native discard operations and can use device sanitize paths when exposed as usable through the connection.
- TRIM/UNMAP across the target drive where supported
- Bridge profiles can enable required provisioning-mode workarounds
- Bridge profiles can suppress TRIM when support is reported incorrectly or behaves unsafely
- USB SCSI SANITIZE can be used when exposed as usable through the bridge
- Software overwrite remains the fallback path when device-assisted methods are not available
04 / Device Sanitize
Device-assisted sanitization.
Some drives and bridges expose device-level sanitize paths. Shield-399 evaluates what is actually usable through the connected path instead of assuming the underlying media can receive every command.
- Known unreliable bridge and command combinations can be suppressed
- Documented bridge workarounds can be applied where supported
- ATA Secure Erase is not treated as a normal USB sanitization method
- NVMe sanitize is only used when the detected path exposes usable support
- USB SCSI SANITIZE, verified TRIM/UNMAP, or software overwrite can be recommended as safer paths
05 / Method Options
Eligible wipe options.
Shield-399 evaluates the target drive, media type, reported capabilities, USB bus path, and bridge behavior before presenting wipe options. The operator selects from the methods considered usable for that drive and connection path.
- Quick Add creates one job for each active Destination drive. Shield-399 selects an eligible method based on detected hardware.
- Rotational versus solid-state media checks
- TRIM/UNMAP, ATA security, NVMe sanitize, USB bus, and bridge behavior evaluation
- Recommended method returned from available methods
- Unsafe or unsupported methods are suppressed or fail with an explanatory error
Run Control
06 / Progress
Progress and cancellation.
Sanitization operations report progress during execution and can be cancelled by the operator. Cancelled operations are recorded as cancelled and are not reported as complete.
- Bytes written or sectors processed
- Percentage complete
- Current pass or phase where available
- Verification phase and progress when post-wipe verification is running
- Cancellation status retained in the operation record
Verification + Review
07 / Verification
Wipe verification.
When enabled, Shield-399 records the verification result with the wipe operation. Available checks can include selected-block sampling, full-surface verification, and filesystem-signature checks.
- Sampled verification reads selected 4 KiB blocks and records the number checked and failed
- Zero-fill and one-fill samples are compared with the selected pattern. Random-pattern overwrite is checked for remaining recognizable filesystem and partition signatures
- Full-surface verification reads the entire addressable target sequentially and is available for native zero-fill overwrites
- Filesystem and partition signature checks look for remaining recognizable structures
08 / Errors
Read and write errors.
If overwrite encounters unwritable regions or verification encounters unreadable regions, the condition is recorded as an operation error or verification failure. The current verification record does not provide a per-sector bad-sector map.
- Verification read failures are reported as failed samples or failed verification blocks
- Overwrite write failures are recorded as operation errors
- Verification status, samples checked, failed sample count, and method-specific details can be reviewed later
- Per-sector observed values and sampled block positions are not currently persisted
09 / Formatting
Post-wipe formatting.
Drive formatting is separate from sanitization. When formatting is queued against the same drive as a preceding wipe, the platform records the dependency and will not start formatting unless sanitization completes successfully.
- Supported target filesystems include NTFS, exFAT, FAT32, EXT4, EXT3, XFS, Btrfs, F2FS, and HFS+ where utilities are available
- Dependent formatting is cancelled if the wipe fails or is cancelled
- Formatting records include filesystem, volume label, partition scheme, quick or full format setting, status, timing, and tool execution ID
10 / Records
Sanitization run records.
Sanitization records show what tool ran, who ran it, what drive was targeted, which wipe method was selected, how far it progressed, whether it completed, and—when verification is enabled—what verification showed.
- Target
- Device path, model, serial, size, drive type, and SSD flag where available.
- Method
- Selected wipe method, whole-drive scope, pass count, and overwrite patterns.
- Execution
- Tool version, operator, case or session association, timestamps, status, errors, bytes processed, and final progress.
- Verification
- Mode, outcome, sample counts, failed samples, duration, and filesystem-signature findings where applicable.
- Review
- Records are available through the network dashboard and touchscreen interfaces.
Sanitization is destructive and destination-only. Verification and method behavior depend on the exact method, device path, target release, and connected hardware.