Before equipment is returned, resold, donated, recycled, transferred, or destroyed, obtain a current Statement of Volatility or equivalent manufacturer document, inventory each storage component, select a media-specific technique, verify the result, and validate the final disposition.
Data Destruction Inc. can scope equipment destruction and component-level media processing when reuse or verified sanitization is not available.
Why Hidden Storage Creates Disposition Risk
A device can look like an appliance while functioning as a computer with several storage layers. The chassis serial number alone does not reveal every place where data persists.
Equipment can retain:
- Configuration files
- Administrator usernames
- Password hashes or secrets
- VPN keys and pre-shared keys
- TLS private keys and certificates
- Routing and firewall rules
- Network diagrams and addresses
- Packet captures
- Event and audit logs
- Print, scan, fax, and copy images
- Address books
- Email and file-transfer destinations
- Cached documents
- Job histories
- Voicemail and recordings
- Call logs and contact lists
- Firmware images
- License files
- Cloud enrollment tokens
- Remote-management credentials
- Customer or patient information
Removing the asset from the network does not remove this information.
Which Devices Commonly Contain Overlooked Storage?
| Equipment | Possible storage | Typical retained information |
|---|---|---|
| Routers and switches | eMMC, NAND, NOR flash, NVRAM, removable flash, service modules | Configuration, keys, logs, firmware, crash files |
| Firewalls and secure gateways | SSD, HDD, flash, TPM, removable modules | Rules, VPN material, logs, packet captures, certificates |
| Wireless controllers and access points | Flash, eMMC, removable storage | SSIDs, credentials, certificates, client and event records |
| Copiers and multifunction printers | HDD, SSD, flash, RAM, fax storage | Document images, queues, address books, audit logs |
| Standalone printers and scanners | Flash, cards, internal drive | Jobs, scans, network settings, destinations |
| VoIP phones and PBX appliances | Flash, SD card, storage drive | Contacts, call logs, voicemail, provisioning secrets |
| Video-conference systems | eMMC, SSD, removable cards | Contacts, recordings, meeting data, credentials |
| UPS and power-management appliances | Flash, cards, controllers | Network configuration, credentials, event logs |
| Lab, medical, and industrial equipment | HDD, SSD, flash, compact flash, controller modules | Results, images, recipes, patient or process data |
| Servers and storage arrays | Multiple HDDs, SSDs, boot modules, cache, management controllers | Application data, snapshots, logs, keys, management records |
The exact list is model and firmware dependent.
What Is a Statement of Volatility?
A Statement of Volatility, sometimes called a Letter of Volatility, identifies memory and storage components and can describe what they retain, whether they are removable, and how they are cleared.
NIST SP 800-88 Rev. 2 advises organizations to ask manufacturers for this device-specific information when identifying information storage media.
A useful statement should address:
- Component type
- Volatile or nonvolatile behavior
- Capacity
- Data purpose
- Physical location
- Removability
- User access
- Reset behavior
- Sanitization command
- Encryption
- Key location
- Service replacement process
- Verification method
- Firmware and hardware versions covered
A Statement of Volatility is evidence, not the final decision
Vendor documents can use different definitions and levels of detail. Confirm that the statement matches the exact model, revision, options, modules, and firmware.
Volatile memory can still require handling controls
RAM usually loses content after power removal, but batteries, capacitors, low-power states, or special memory technologies can affect persistence. Follow manufacturer and governing procedures rather than assuming that unplugging always clears every component immediately.
Why a Factory Reset May Be Insufficient
Factory reset is a device function, not a universal sanitization method. It can remove configuration pointers while leaving logs, caches, remapped storage, document images, recovery partitions, or separate modules unchanged.
Establish whether reset:
- Overwrites user-addressable storage
- Regenerates encryption keys
- Removes private keys and certificates
- Clears crash dumps
- Clears packet captures
- Clears print or scan images
- Clears fax memory
- Clears address books
- Clears management-controller storage
- Affects removable cards
- Affects added SSDs or HDDs
- Returns licenses or cloud enrollment
- Produces a completion log
NIST defines Clear by the effect on user-addressable storage, not by a button label.
Hidden Storage in Routers and Switches
Network devices can retain operational details that expose infrastructure and credentials even when they do not hold ordinary user files.
Inspect:
- Startup and running configuration
- NVRAM
- Boot flash and secondary flash
- USB, SD, compact flash, and service cards
- Crash dumps and core files
- Packet captures
- Event and security logs
- VPN and authentication material
- SSH host keys
- TLS certificates and private keys
- SNMP communities and credentials
- TACACS+, RADIUS, LDAP, and API secrets
- Cloud-management enrollment
- Line cards and route processors
- High-availability peer configuration
A reset on the main processor may not sanitize an installed storage module or removable card.
End-of-support devices need timely removal
Unsupported edge devices can create active cyber risk before disposition. Maintain an inventory, migrate services, remove network trust, sanitize storage, and close the asset record.
Hidden Storage in Firewalls and Security Appliances
Firewalls, VPN concentrators, secure web gateways, intrusion systems, and load balancers can contain high-value secrets and traffic records.
Special items include:
- Private keys
- VPN configurations
- Pre-shared keys
- Authentication databases
- Packet captures
- Decrypted traffic logs
- Threat samples
- Geo and identity policy
- High-availability synchronization data
- Virtual appliance images
- TPM-bound credentials
- Hardware security modules
Coordinate key revocation and certificate replacement before the unit leaves control. Sanitizing local storage does not revoke a copied credential.
Hidden Storage in Copiers and Multifunction Printers
Digital copiers can retain document images and administrative data on internal drives and flash. Leased equipment creates added risk because it can be returned and placed with another customer.
The FTC copier-security guide advises businesses to address copier hard drives throughout acquisition, use, return, and disposal.
Inspect:
- Internal HDD or SSD
- Embedded flash
- Fax storage
- Job image storage
- Print and scan queues
- Address books
- Email and SMB destinations
- Authentication records
- Audit logs
- Document-server functions
- Removable cards
- Controller boards
- Optional print servers
Lease contracts should assign drive ownership
Before signing or renewing a lease, define:
- Who owns each drive
- Whether the client can retain it
- Who performs sanitization
- Which procedure applies
- Whether the client can witness it
- Evidence delivered
- Handling of failed drives
- Subcontractor access
- Replacement-module handling
Do not wait until pickup day to negotiate data protection.
Printer Drums, Fusers, and Non-Digital Residual Information
Some equipment can retain information outside ordinary digital storage. Toner-based printers and copiers can involve image-bearing components as well as nonvolatile memory.
For organizations within its scope, the current NSA/CSS Policy Manual 9-12 includes procedures for toner-based printers that address nonvolatile memory, the organic photoconductor drum, and fuser unit. These classified procedures should not be copied into ordinary commercial work without confirming applicability, safety, and authorization.
Vendor service technicians should identify replaceable parts that can retain documents or image traces.
Phones, Conference Systems, and Collaboration Devices
Communications devices can store credentials, contacts, meetings, recordings, and remote-management enrollment.
Check:
- Local recordings
- Voicemail
- Contacts and favorites
- Call history
- Calendar and meeting information
- Wi-Fi credentials
- SIP credentials
- Device certificates
- Management tokens
- USB or SD cards
- Paired Bluetooth devices
- Cloud tenant registration
- Diagnostic logs
Remove the device from the cloud tenant and revoke credentials in addition to processing local storage.
Medical, Laboratory, Manufacturing, and OT Equipment
Specialized equipment can contain standard storage devices behind proprietary panels or service contracts.
Examples include:
- Medical imaging and diagnostic systems
- Laboratory analyzers
- CNC and manufacturing controllers
- Test and measurement instruments
- Building-management systems
- Security panels
- Video recorders
- Industrial gateways
- Kiosks and point-of-sale equipment
The manufacturer or authorized service organization may need to remove storage without damaging calibrated or regulated equipment. Contract terms should permit client control of data-bearing components.
Media-Specific Sanitization Is Required
After identifying storage, apply a technique suitable for each component rather than one procedure to the entire chassis.
Possible components include:
- Magnetic HDD
- SATA or NVMe SSD
- eMMC or UFS
- NAND or NOR flash
- SD, microSD, compact flash, or USB media
- NVRAM
- TPM or secure element
- Volatile RAM
- Optical media
- Magnetic tape
Degaussing does not work on flash. HDD overwriting does not sanitize a separate boot card. A factory reset does not destroy a removed drive.
For SSD-specific decisions, see SSD Shredding and Chip-Level Destruction and Why Degaussing Does Not Work on SSDs.
Cryptographic Erase and Key Revocation
Cryptographic erase can support Purge only if all target data was encrypted before storage and all required keys and recovery paths are sanitized.
Embedded devices complicate this because:
- Encryption can cover only selected partitions
- Factory keys may be shared
- Cloud recovery copies may exist
- Keys can be escrowed
- A TPM may protect keys without exposing the sanitization process
- Reset can rotate a credential without sanitizing data keys
- Vendor service modes may bypass assumptions
Request vendor evidence for encryption scope, key hierarchy, key sanitization, and reset behavior. Revoke external certificates, API keys, tokens, and cloud registrations separately.
Verification and Validation
Verification confirms that the selected operation completed on each identified component. Validation determines whether the complete device result is acceptable.
Verify:
- Exact asset, model, hardware revision, and firmware
- Installed options and modules
- Statement of Volatility version
- Storage-component inventory
- Reset or sanitize procedure
- Tool and version
- Completion logs
- Errors and inaccessible components
- Removed-media serial numbers
- Physical-destruction output
Validate:
- All storage components were included
- Technique matches each media technology
- Credentials were revoked externally
- Lease or transfer terms were met
- Errors were resolved or escalated
- Reuse or destruction route is approved
A successful reset can fail validation if a removable SSD was missed.
A Practical Hidden-Storage Inspection Workflow
- Identify make, model, serial number, revision, options, and firmware.
- Photograph front, rear, service bays, and installed modules.
- Obtain the current Statement of Volatility and service manual.
- Compare the document with the physical unit.
- Inventory internal, removable, and replaceable storage.
- Export required configuration and records.
- Migrate services and revoke trust.
- Remove cloud enrollment and management accounts.
- Assign Clear, Purge, or Destroy to each component.
- Apply the media-specific technique.
- Verify component-level results.
- Validate the complete asset.
- Reinstall blank or replacement media if reusing the chassis.
- Update inventory and configuration records.
- Issue the certificate and downstream disposition record.
What Should Procurement Require?
Buy and lease equipment with end-of-life sanitization in mind.
Require vendors to provide:
- Statement of Volatility
- Complete storage map
- Supported Clear and Purge operations
- Encryption and key-sanitization details
- Verification outputs
- Drive-retention option
- Failed-part handling
- Client approval before part return
- Sanitization responsibilities at lease end
- Service-technician custody rules
- Firmware support period
- Cloud deregistration procedure
- Removal instructions for data-bearing modules
Equipment without an adequate sanitization path may need physical destruction, reducing residual value.
Certificate and Custody Evidence
A Certificate of Destruction or sanitization record should identify:
- Parent equipment serial number
- Removed storage serial numbers
- Equipment type and model
- Each storage technology
- Clear, Purge, or Destroy assignment
- Technique and tool
- Verification result
- Validator
- Date and location
- Operator and witness
- Exceptions
- Chassis and component disposition
Use chain-of-custody controls when drives, controller boards, or full appliances move to another location.
Hidden Storage Decision Framework
- Treat the equipment as data-bearing until assessed.
- Identify exact model, options, and firmware.
- Obtain a Statement of Volatility.
- Physically inspect installed components.
- Map data and credentials to each component.
- Migrate required services and records.
- Revoke external trust and cloud enrollment.
- Decide reuse, return, resale, recycling, or destruction.
- Assign a method to every storage component.
- Verify each result.
- Validate the complete device.
- Reconcile parent and removed-component serial numbers.
- Document custody and final disposition.
Data Destruction Inc. provides equipment destruction, hard-drive shredding, SSD destruction, and component-level custody for approved projects.
Frequently Asked Questions
Do routers store data after power is removed?
Yes. Configuration, firmware, logs, certificates, keys, and crash data can persist in nonvolatile storage.
Is factory reset enough for a network switch?
Not automatically. Confirm what the reset covers, inspect removable and optional storage, verify completion, and validate the result.
Do office copiers contain hard drives?
Many digital copiers and multifunction devices contain HDDs, SSDs, or flash, but the exact storage depends on model and options.
Can a leased copier be returned after deleting the address book?
Deleting the address book may leave document images, logs, credentials, and other storage unchanged. Follow the lease and manufacturer sanitization procedure.
What is a Statement of Volatility?
It is a manufacturer document describing memory and storage components, persistence, and clearing behavior for a product.
Does removing the hard drive sanitize an appliance?
Not necessarily. Embedded flash, boot cards, management controllers, or other modules may remain.
Can hidden flash storage be degaussed?
No. Flash is nonmagnetic and requires an approved logical or physical technique.
Should private keys be revoked after device sanitization?
Yes when copied keys, certificates, or trust relationships may remain elsewhere. Local sanitization and external revocation solve different risks.
What if the manufacturer has no Statement of Volatility?
Use service documentation, component inspection, vendor engineering support, and a risk decision. If storage cannot be identified or sanitized, destruction can be appropriate.
Request an Equipment Storage Assessment
Provide equipment types, manufacturers, models, quantities, lease status, service location, reuse plan, and evidence requirements. Data Destruction Inc. will identify the storage-assessment and destruction scope before work begins.
Request an Equipment Destruction Quote
Call: (866) 850-7977
Sources
- NIST, NIST SP 800-88 Rev. 2, September 2025.
- NIST, NIST SP 800-88 Rev. 2 PDF, Sections 4.3 through 4.5 and Appendix B.
- FTC, Digital Copier Data Security: A Guide for Businesses.
- NSA/CSS, Policy Manual 9-12, February 19, 2026.
- CISA, BOD 26-02: Mitigating Risk From End-of-Support Edge Devices.
