Search SecureTrace

Jump to a file, transfer or page

Disposal & destruction

Every expired or revoked transfer owes a destruction confirmation. Retention runs from the day the link died — ISO 27001 A.5.11 / A.8.10.

Outstanding2Awaiting vendor attestation
Overdue0Past 30 days
Certificates issued0Sealed and attached
TransferStateDisposalAction
TRF-2026-0102showroom-photography-selects.zipRevokedInternalScheduledISMS admin only
TRF-2026-0109thermal-test-report-q2.pdfExpiredConfidentialScheduledISMS admin only
How disposal is evidenced
What an auditor is shown for A.5.11 and A.8.10

When a link expires or is revoked, the recipient loses access immediately — but the copy they already downloaded is outside this system. That gap is the reason A.5.11 exists, and it is closed by attestation rather than by technology.

  1. The transfer dies and a disposal record opens against it automatically.
  2. A destruction confirmation is requested from the named recipient, giving them 30 days to attest.
  3. Their attestation is written to the transfer's own timeline, against their identity — not a checkbox on this page.
  4. A sealed certificate of destruction is issued and attached, and the retention clock on the internal copy continues to run independently.

The prototype records the attestation and issues the certificate. It cannot prove the vendor actually deleted anything — no system can. What it proves is that the organisation asked, tracked, and holds a dated record of the answer.