Revised

Credentials, rebuilt around what a buyer actually asks

Now aligned to the approved design system in website-build-standards/references/DESIGN.md, which I had not read when I first built this. Antic is back on the H1 and H2, buttons are full pills again, and cards carry a shadow with no border. Those three were mine to get wrong, not yours.

And the page is reordered. It now opens with the three questions a buyer has, instead of opening with our certifications. Registration numbers, insurance and EWC codes have moved into one compact block at the foot, labelled for procurement. "What we do not hold" is gone.

Page begins

Home / Credentials

How you know we did what we said we did

Three questions come up on almost every first call. Here are the answers, with the evidence behind each one.

Question one

Is the data actually gone?

Every drive is erased in line with current guidance from the National Cyber Security Centre, formerly HMG Infosec Standard 5. The software we use is ADISA certified.

A drive that fails erasure is physically destroyed at our own site rather than passed on. So is any drive where you would rather have destruction than a wipe.

Proof: a Certificate of Data Destruction listing every device by serial number.

Question two

Who handles my equipment?

Our own staff, in our own tracked vehicles, a minimum of two on every collection. All operational staff are security vetted with enhanced DBS as standard, and further checks can be arranged where your site requires them.

Collection and transport are never subcontracted. Equipment is unloaded into our own alarmed, CCTV monitored facility with no public access.

Proof: a Waste Transfer Note signed by both parties on the day.

Question three

What do I get, and when?

Four documents. One on the day of collection, two within 28 working days, and a carbon report whenever you ask for it.

They are what you reconcile your asset register against, and what you would put in front of your own auditor or the Information Commissioner's Office.

Proof: see redacted samples of all four, below.

The paperwork

Four documents, and what each one proves

This is the part that matters at audit, so it is worth being specific about which document answers which question.

DocumentWhat it provesWhen
Waste Transfer NoteThat the equipment left your site legally, into the hands of a registered waste carrier. This is the duty of care record, and the one an environmental inspector asks for.On the day
Asset Inventory SheetExactly what we took, item by item. What you reconcile your own asset register against, and what tells you nothing went missing.28 working days
Certificate of Data DestructionThat the data is gone, with a manifest listing every device by serial number. Your record of processing, and your evidence of erasure.28 working days
CO2 reportThe carbon saved by reuse rather than replacement, calculated from the itemised list rather than an estimate.On request

Look at the real thing before you commit

Redacted samples of all four documents, exactly as you would receive them. No form, no email address required.

Download the sample pack

Certifications

What we hold, and what each one actually covers

A badge on its own tells you nothing, so here is a plain sentence on each. All three are certified through Citation, and we will send the certificates themselves on request.

ISO 27001

Information security

How we protect information: physical access, staff vetting, how records are kept and what happens when something goes wrong. If you only check one, check this one, because it is the one that speaks to what you are actually worried about.

ISO 9001

Quality management

Running to a documented, repeatable process. A collection follows the same steps whoever does it, problems get logged and closed rather than quietly fixed, and your paperwork is the same paperwork every time.

ISO 14001

Environmental management

Measuring and reducing environmental impact rather than asserting it. This is what sits underneath our reuse figures and our carbon reporting, and why those numbers are calculated the same way every quarter.

ADISA

Two claims, kept apart

The data erasure software we use is ADISA certified. Terraguard itself is working towards ADISA accreditation as an organisation and is not certified yet, so you will not see us claim that it is. We are going through assessment now.

The small print

Registration and insurance detail

Everything a procurement or legal team needs to verify us, in one place. Most buyers will never need this section.

Company and registrations

All numbers below can be checked against the public register.

Registered name
Terra Guard Technologies Limited
Company number
16064080
VAT number
480856070
Waste carrier licence
CBDU609517, upper tier
S2 waste exemption
WEX473365, Wiltshire Council
EWC codes
160214, 160213
ICO registration
On request
Insurance
PI, goods in transit, public liability, cyber

Where responsibility sits. You remain the data controller for any personal data on the equipment. Liability sits with you until collection and with us from the point of collection onwards. Before we arrive you are responsible for releasing BIOS passwords, cloud locks and mobile device management enrolments.

On third parties. Collection and transport are never subcontracted. A drive that fails erasure, or hardware needing specialist repair, is occasionally sent to an external facility. If that matters for your contract, ask and you will get a straight answer about which facility and what they hold.

Insurance limits and certificates are supplied on request rather than published, because the figure that matters is the one on the actual schedule.

Page ends

What moved, and why

Up top, taking the space: the three questions. Is the data gone, who touches my kit, what do I get and when. Each one ends with the document that proves it, so the claim and the evidence sit together.

Second, because it converts: the four documents, then the sample pack. A sceptical IT manager inspecting your actual paperwork before committing is worth more than any badge. I have made it ungated, no email required, because gating it would undo the point.

Third: the certifications, reordered so ISO 27001 leads. It is the one your buyer cares about. ADISA sits alongside, with the software and the organisation kept clearly apart.

At the foot, small: company number, VAT, licences, EWC codes, insurance, the data controller position and the honest note about failed drives going to a third party. All true, all needed by procurement, none of it persuading anybody. The heading says most buyers will never need it, which is a signal in itself.

Gone: what we do not hold.

Mockup, 15 September 2026. Not published, not live. ICO registration shows "on request" until the number is verified against the register in the correct legal name.