Skip to main content
Sanitization and imaging station at the VIG Dallas facility
STN 04 · SANITIZATION · WIPE LOGNIST SP 800-88 Rev. 1 · per serial
QC GATE · HARD STOPNo pass without a verified log
INDUSTRY · FINANCIAL SERVICESR2v3 Certified · #274644 · Dallas, TX

Retire customer-data hardware with controls that survive the walkthrough.

For banks, insurers, broker-dealers, and FinTech operators retiring hardware that touched customer financial data. Every storage-bearing device is sanitized to NIST SP 800-88 Rev. 1 with PCI-acceptable Purge or Destroy methods per media type, and the serial-level audit trail is issued with the Settlement Report — ready for your auditor’s control-effectiveness binder.

ALIGNS WITHGLBA Safeguards RuleSOX §404 (internal controls)PCI-DSSState breach-notification lawsNIST SP 800-88
The stakes · customer financial data

What financial-services teams need from ITAD.

Not marketing requirements — the ones your compliance office actually reviews when retired hardware leaves the building.

NEED 01 · THE DATA

Customer financial data is everywhere

Trading workstations, retired ATMs and branch hardware, work-from-home laptops, and even imaging hardware can carry account numbers, SSNs, and transaction histories. Every one needs a verified wipe, not a blanket attestation.

ANSWERED AT STN 04 · WIPE LOG
NEED 02 · THE CONTROLS

SOX requires documented controls — including disposal

Internal-control attestations now routinely include the disposition of IT assets. “We threw it out” doesn’t satisfy a SOX 404 walkthrough. A per-serial disposal record does.

ANSWERED AT STN 05 · FINAL CERT
NEED 03 · THE CARD DATA

PCI media-destruction obligations

PCI DSS §9.8.2 requires media containing cardholder data to be destroyed so it cannot be reconstructed — and demands proof. The method has to match the media, and the record has to satisfy your QSA.

ANSWERED AT STN 04 · WIPE LOG
NEED 04 · THE VENDOR FILE

A vendor your compliance file can defend

Vendor review asks who touches your media, under which certifications, audited by whom. The answers have to be third-party-verifiable — not self-declared.

ANSWERED BY R2v3 #274644 · audited annually
Verified capability · mapped to the requirement

What we run against each need.

Every line below is a verified, third-party-audited capability — no promises that aren’t written at a station on the Dallas floor.

NEED 01Verified per drive

NIST SP 800-88 Rev. 1, aligned to PCI

STN 04 · WIPE LOG

PCI-acceptable Purge or Destroy methods per media type, with the Certificate of Destruction your QSA expects. Method, result, date, and technician recorded per drive. The wipe gate is a hard stop — no device advances without a completed, verified log.

Spec →
NEED 02Documented controls

SOX-friendly settlement reports, one line per serial

STN 05 · FINAL CERT

Serial-level audit trail issued with the Settlement Report — drops directly into your auditor’s control-effectiveness binder. Our record on the process it documents: zero data incidents, ever.

Crosswalk →
NEED 03Examiner-ready custody

100% serialized chain of custody, five stages

BOL → FINAL CERT

Sealed, manifested transport on your schedule — custody transfers at your dock, on paper. Every pallet is reconciled against your manifest within 48 hours. Documentation suitable for FFIEC, state-DFS, or federal-banking examiner review on request.

Walk it →
NEED 04Third-party verification

R2v3 — Responsible Recycling · #274644

SERI R2v3 Standard

Scope: IT Asset Disposition & Refurbishment, certified by Amtivo (ANAB-accredited) · SERI, independently audited annually, valid through March 2029 — verifiable on the SERI directory. Backed by ISO 9001, ISO 14001, and ISO 45001 management-system registrations.

Certs →

What this does — and doesn’t — claim. No vendor can make a financial institution GLBA-, SOX-, or PCI-compliant, and we won’t claim to. VIG supports your compliance program: third-party-verified process controls, per-serial records, and the disposal documentation your internal controls require. Your program stays yours; ours documents its disposal controls.

Custody & reporting evidence

The paper trail, before you commit.

Five stages. One record per serial. Zero gaps. Each station below writes a named document — the same language our auditors see.

01PickupSealed, manifested transport on your schedule.BOL ISSUED
02ReceivingReconciled against your manifest within 48 hours.INTAKE SCAN
03SerializationEvery asset tagged, photographed, and recorded.ASSET RECORD
04SanitizationNIST 800-88 destruction, verified per drive.WIPE LOG
05DispositionResale, redeploy, or certified recycling.FINAL CERT

What lands in your file

Certificate of Destruction · per serial
48-hour intake reconciliation report
Per-device disposition report · one line per serial
Settlement statement · device, grade, channel

Certificate records and controlled QC documents are viewable in the client portal. Nothing here is a download — originals are available for inspection on request.

Live floor
84Lots live right now
4,195Units in stock
Browse live lots →
Pallet operations in the receiving area at the VIG Dallas facility
Open a work order · free valuation · no minimums

Ready to retire your fleet?

Send us your asset list and get a free valuation within one business day — no minimums, no commitment. Free pickup for 50+ unit lots in Texas. Serialized Certificate of Destruction included with every job.

(682) 716-2740 · Mon–Fri · 8:00 AM – 5:00 PM CT · 2630 Andjon Drive, Dallas, TX 75220

Get a quote