← All Resources
September 22, 2026 Vibrant Technologies Blog ITADData SecurityData SanitizationChain of CustodyCompliance

What to Ask Your ITAD Vendor: 21 Questions That Separate Good Answers From Good Marketing

What to Ask Your ITAD Vendor: 21 Questions That Separate Good Answers From Good Marketing

Every vendor says certified, secure, and sustainable. These questions are designed so that the answer reveals whether it's true.


Every IT asset disposition provider's website makes the same three claims. The data is secure. The process is certified. The recycling is responsible. None of those words cost anything to write, and none of them help you choose.

The questions below are built differently. Each is specific enough that a vague answer is itself informative. They're organized by what you're actually trying to protect, because that's how the risk lands on your side of the contract.

A practical note before starting: ask in writing. A capable vendor answers these quickly and specifically, often with a sample document attached. The level of detail in the reply tells you as much as the content.

Protecting the Data

What's in your sanitization scope beyond the drives?

Modern servers hold data in management controllers, RAID cache and metadata, boot modules, persistent memory, and platform firmware. A good answer names these unprompted and describes what happens to each — factory reset of the iDRAC or iLO, controller configuration cleared, TPM ownership released, boot media treated as a drive. If the answer is entirely about hard drives, the scope is a generation out of date. We covered this in depth in The Drive Is Not the Server.

Which sanitization standard do you follow, and which revision?

NIST withdrew SP 800-88 Revision 1 on September 26, 2025, and Revision 2 no longer specifies techniques itself — it points to IEEE 2883, NSA specifications, or an organizationally approved standard. A current vendor can tell you which technique standard they've adopted. One still citing Revision 1 without mentioning Revision 2 hasn't updated their paperwork, and it's reasonable to wonder what else hasn't been updated.

What happens to a drive that fails erasure?

This is one of the most revealing questions on the list. A failed wipe is a decision point, not a completed job. A good answer describes a defined escalation — typically to physical destruction — with the failure and the outcome both documented against the serial number. Worth worrying about: any answer suggesting the drive is simply retried until it passes, or marked complete after an attempt.

How do you verify, and what does verification produce?

Sanitization without verification is an assertion. Ask what the verification step is and what record it leaves behind.

Can you sanitize on-site, and when would you recommend it?

The point isn't whether they offer it. It's whether they can explain when data sensitivity justifies keeping media inside your building until it's sanitized, and when off-site processing under controlled custody is reasonable.

Protecting the Books

Do your certificates list serial numbers, or quantities?

A certificate reading "42 drives destroyed" cannot be reconciled against a fixed asset register listing 42 individual serial numbers. Only asset-level documentation lets finance close out a disposal properly. This is the single most useful question on the list for a controller, and we explain why in Chain of Custody Is a Finance Problem.

How long after pickup do we receive serialized reporting?

Ask for a number of business days, not "promptly." Reporting that arrives months later arrives after your quarter has closed.

Will your settlement report reconcile to our asset register?

The best test is to ask for a sample report and hand it to someone on your finance team. If they can match it line by line to the subledger, the process works. If it takes a spreadsheet and three emails, it doesn't.

How long do you retain records, and can we retrieve them later?

You'll want records available for at least as long as your own longest retention obligation. Ask how you'd request a certificate from four years ago, and how long it would take.

Protecting the Chain

How is custody documented at the moment of pickup?

The trail has to start before the equipment leaves your building. Look for a signed transfer record with asset-level detail, not a count of pallets.

Who physically transports the equipment?

The vendor's own personnel and vehicles, or a third-party carrier? Neither is automatically wrong, but you should know which, and what controls apply — locked or sealed vehicles, tracking, and whether the load goes directly to the processing facility or stops elsewhere.

Who are your downstream processors, by name?

Your vendor's subcontractor is still your exposure. Some material will always go downstream for commodity recovery, and that's normal. What isn't normal is a vendor who can't or won't tell you where.

Protecting the Recovery

How do you value equipment — whole unit, or component by component?

A whole-unit quote is simpler and often right. But for equipment where a component such as memory carries a large share of the secondary-market value, a component-level valuation can recover materially more. A capable vendor can produce both and explain the difference. We looked at why this matters more than it used to in Your Retired Servers Appreciated.

How is revenue share calculated, and when is it paid?

Ask for the formula in writing, what costs are deducted before the share applies, and the payment timeline after settlement.

What reduces or voids an asset's value?

Common examples are devices still locked to an account, missing components, or physical damage. Knowing the list in advance is the difference between an expected settlement and an unpleasant one.

Protecting the Environmental Claim

Which certifications do you hold, and at which facility?

Certifications apply to specific facilities, so confirm the certificate covers the site that will actually process your equipment. Then ask what each one covers, because they address different risks.

R2v3, administered by Sustainable Electronics Recycling International, is a risk-based framework for electronics reuse and recycling that covers data security, environmental and worker safety, and downstream management, with some international export permitted under documented tracking. e-Stewards, created by the Basel Action Network, is more prescriptive and prohibits the export of hazardous electronic waste to developing countries. NAID AAA, administered by i-SIGMA, is specific to data destruction and includes unannounced audits. ISO 14001, 9001, and 45001 certify environmental, quality, and occupational health and safety management systems respectively; they speak to operational maturity rather than recycling practice specifically.

No single certification covers everything, and a certificate is a floor rather than a guarantee. The useful follow-up is to ask how the vendor's certifications map to the risks you care most about.

What does "zero landfill" mean in your process?

It's a common claim and a reasonable one to probe. Ask what happens to materials that can't be reused or recycled, and whether the claim is verified.

Can you provide reportable data for our sustainability reporting?

If your organization reports on waste or environmental impact, ask what the vendor can provide — typically weight by material and by outcome, such as reuse, recycling, or destruction — and in what format.

Protecting Yourself From the Vendor

What insurance do you carry, and at what limits?

Ask specifically about coverage relevant to a data incident and an environmental incident, not just general liability, and request certificates of insurance.

What does the contract say about indemnification?

If a data breach is traced to equipment in the vendor's custody, who bears the cost? This belongs in the contract, not in a sales conversation.

Can we audit you or visit the facility?

A vendor confident in its process welcomes a site visit. Hesitation here is worth noting.

What the Answers Tell You

None of these questions is a trap. Any competent vendor, including the ones you won't choose, should be able to answer most of them clearly. That's the point.

What separates providers isn't whether they claim security, certification, and sustainability. Everyone does. It's whether they can describe, specifically and in writing, how each claim is achieved and what evidence you'll receive. A vendor who finds these questions tedious has told you something. A vendor who sends back a sample certificate, a sample settlement report, and a named downstream list before you've finished asking has told you something too.


Vibrant Technologies has provided secure, documented IT asset disposition since 1998. We're R2v3 certified and hold ISO 9001, 14001, and 45001 certifications, and we're happy to answer every question on this list in writing. Request a valuation

This article is general guidance and not legal or compliance advice. Confirm requirements specific to your organization with your own advisors.


Sources