Search SecureTrace
Jump to a file, transfer or page
Disposal & destruction
Every expired or revoked transfer owes a destruction confirmation. Retention runs from the day the link died — ISO 27001 A.5.11 / A.8.10.
Outstanding2Awaiting vendor attestation
Overdue0Past 30 days
Certificates issued0Sealed and attached
| Transfer | Vendor | State | Confirmation due | Disposal | Action |
|---|---|---|---|---|---|
| TRF-2026-0102showroom-photography-selects.zip | Sunrise Auto Parts Trading | RevokedInternal | 09 Aug 2026in 5 days | Scheduled | ISMS admin only |
| TRF-2026-0109thermal-test-report-q2.pdf | Nippon Seiki Design Studio | ExpiredConfidential | 23 Aug 2026in 19 days | Scheduled | ISMS admin only |
How disposal is evidenced
What an auditor is shown for A.5.11 and A.8.10
When a link expires or is revoked, the recipient loses access immediately — but the copy they already downloaded is outside this system. That gap is the reason A.5.11 exists, and it is closed by attestation rather than by technology.
- The transfer dies and a disposal record opens against it automatically.
- A destruction confirmation is requested from the named recipient, giving them 30 days to attest.
- Their attestation is written to the transfer's own timeline, against their identity — not a checkbox on this page.
- A sealed certificate of destruction is issued and attached, and the retention clock on the internal copy continues to run independently.
The prototype records the attestation and issues the certificate. It cannot prove the vendor actually deleted anything — no system can. What it proves is that the organisation asked, tracked, and holds a dated record of the answer.