The certification, recorded under project number ADPA059, confirms that Clear v1.1.0 was independently tested against the NIST 800-88r1, NIST 800-88r2, and IEEE 2883 data sanitization standards and is valid through August 3, 2029.
ADISA is a UK-based, UKAS-accredited certification body that independently tests data sanitization products and audits organizations that handle IT asset disposal. AAL5, delivered through ADISA's Product Assurance scheme, is the highest level of product-specific testing ADISA offers for data erasure software. For organizations that resell, redeploy, or retire IT equipment, it means Clear's erasure claims have been checked by a third party rather than taken on the vendor's word.
Clear is sold under its own product site, clearerase.ai, as part of 99 Technologies' broader technology portfolio. The certification applies specifically to the tested version, Clear 1.1.0.
What Is ADISA Certification?
ADISA certification is an independent verification process for organizations and products involved in the secure handling, sanitization, and disposal of information-bearing IT assets. ADISA, the Asset Disposal & Information Security Alliance, was founded in 2010 and is accredited by the United Kingdom Accreditation Service (UKAS). Two of its certification schemes, the ICT Asset Recovery Standard 8.0 and the Legal Services Operational Privacy Certification Scheme (LOCS:23), are formally approved by the UK Information Commissioner's Office as UK GDPR certification schemes.
In 2019, ADISA launched the ADISA Research Center (ARC), a dedicated testing laboratory that evaluates software and hardware data sanitization tools against recognized technical standards. This is the part of ADISA that certified Clear.
The distinction that matters here is between a vendor's own security claims and an independent evaluation of those claims. A company can say its erasure software renders data unrecoverable. ADISA's testing lab instead attempts to recover data from media that Clear has processed, using recovery techniques designed to simulate a real attacker, and only issues certification if the product withstands that attempt.
ADISA is not a government regulator, and its certification is not a legal requirement in most jurisdictions. It is a voluntary, independent assurance mechanism that organizations, auditors, and procurement teams can use to evaluate a vendor's claims.
Understanding ADISA's Certification Levels
ADISA's current Assurance Model (v2, published February 2025) defines six assurance levels, AAL1 through AAL6. The lower levels (AAL1–AAL3) cover unproven, self-assessed, or informally evaluated products and are explicitly out of scope for anything ADISA itself certifies. The levels relevant to buyers evaluating a certified product or organization are:
| Assurance Level | What It Represents | Key Distinction |
|---|---|---|
| AAL4 – Product Claims Test / ITAD Essentials | Independent validation of a vendor’s stated erasure claims or an audit of core ITAD process controls. | Formal, one-time assessment that is not recognized by a government authority. |
| AAL5 – Product Assurance | Rigorous, independent laboratory testing of erasure software against NIST 800-88 or IEEE 2883, including verification of sanitization commands across different storage media and interfaces. | The highest level of product-specific testing in ADISA’s scheme. |
| AAL6 – UK GDPR Schemes (ICT Asset Recovery Standard 8.0, LOCS:23) | Ongoing, formal assessment of an organization’s data-handling practices, recognized by the UK Information Commissioner’s Office. | Focuses on organizational and continuous compliance, rather than one-time testing of a specific software product. |
Clear's certification sits at AAL5. It is worth being precise about what that means: AAL5 is the highest tier ADISA offers for testing a specific software product's erasure capability. It sits below AAL6, which certifies an entire organization's ongoing IT asset disposition or data protection practices rather than a single product.
The two measure different things: one tests whether a tool does what it claims on a technical level; the other audits how a company runs its processes, so a product achieving AAL5 is not directly comparable to a company holding an AAL6 organizational certification.
What separates AAL5 from AAL4 is largely rigor and standards. AAL4's Product Claims Test validates a vendor's claims against ADISA's own testing methodology. AAL5's Product Assurance testing goes further, evaluating the software against externally recognized standards, NIST SP 800-88 (from the US National Institute of Standards and Technology) and IEEE 2883-2022 (from the Institute of Electrical and Electronics Engineers), and specifically checks that the software issues the correct sanitization commands for different storage media and interfaces, including modern SSD and NVMe drives that older testing approaches don't fully address.
AAL5 certification proves that the tested version of a product can sanitize the specific media types it was tested against, to the tested standard, at the time of testing. It does not certify every feature of the software, every storage type on the market, or future versions that haven't been separately evaluated.
What It Took to Get Certified
Clear's certification was issued under ADISA's Product Assurance scheme, administered by the ADISA Research Center. Under this scheme, a product is submitted for formal, independent testing rather than a paperwork review.
ADISA's lab evaluates whether the software issues the correct sanitization commands to the target storage media, behavior that differs across HDDs, SSDs, and NVMe drives because of how each type of storage handles data at the hardware level, and then attempts to recover data from the sanitized media using recovery techniques designed to simulate an actual attack.
"Clear went through several weeks of controlled testing under our Product Assurance scheme, more than thirty individual tests in total, which represents the highest level of assurance we currently offer for data sanitisation software. A result like this means an organisation isn't relying on a vendor's word alone; the testing has actually been carried out and verified," said Steve Mellings, Founder and CEO of ADISA, whose team conducted the evaluation.
Clear's certificate confirms compliance was verified against NIST 800-88r1, NIST 800-88r2, and IEEE 2883, which together cover both older and current sanitization guidance for traditional and flash-based storage.
The certification is scoped to the version tested, Clear 1.1.0, and remains valid until August 3, 2029. Product certifications of this kind typically apply to the exact version tested; a materially different future release would generally need its own evaluation to carry the same certification.
"Data sanitization demands zero margin for error. Achieving ADISA Assurance Level 5 means Clear was forensically stress-tested in an independent laboratory and withstood advanced data recovery attempts on every media type it was evaluated against. For our partners and customers, that turns an abstract product claim into verified, lab-backed trust, and it's the standard we intend to hold for every future release of Clear."
~ Muhammad Owais, Clear Team Lead
What ADISA Level 5 Means for Customers
Compliance Assurance
Independently verified erasure can support an organization's broader compliance and governance program, but it does not by itself make an organization compliant with a specific regulation.
Compliance obligations under frameworks like HIPAA or GDPR are set by law and depend on an organization's full set of practices, not on any single vendor's certification.
What Clear's AAL5 certification provides is documented, third-party evidence that the sanitization step of that process was tested to a recognized standard, evidence a compliance team can point to, rather than a vendor's unverified claim.
Audit Readiness
When an auditor asks how retired devices were sanitized, "we used software that passed independent testing against NIST 800-88 and IEEE 2883" is a more defensible answer than "our vendor says it's secure." Documented, standards-based erasure makes it easier to demonstrate, rather than simply assert, that data-handling requirements were followed.
Risk Reduction
Devices that are resold, redeployed, or recycled without proper sanitization carry the risk that residual data can be recovered by the next party who handles them. Certified erasure reduces that risk by verifying the software's ability to render data unrecoverable on tested media types.
It does not eliminate the possibility of a data breach through other channels, nor does it substitute for an organization's overall security program.
Resale and ITAD
Organizations that resell, redeploy, or recycle devices, including IT asset disposition (ITAD) providers, need sanitization they can defend if a device's provenance is ever questioned. A certified erasure step gives ITAD workflows a documented, independently tested basis for that defense.
Enterprise Procurement
During vendor security reviews, procurement and security teams often ask which certifications a data sanitization vendor holds. An independent, standards-based certification like AAL5 gives buyers a verifiable answer instead of relying solely on the vendor's own documentation.
How Clear Compares in the Industry
Several vendors in the data sanitization market hold ADISA product certifications at various levels, tested against different combinations of NIST 800-88 and IEEE 2883 for different storage types.
Certification scope varies meaningfully from product to product: some certifications cover only HDDs, others extend to SSDs, NVMe drives, mobile devices, or embedded storage, and the assurance level (Product Claims Test versus Product Assurance) reflects a real difference in testing rigor.
Buyers evaluating data sanitization software should look beyond the existence of a certification and check what it actually covers: which product version, which storage media, which standards, and which assurance level.
ADISA publishes its certified companies and products publicly, allowing any of these details to be verified directly rather than taken from marketing materials.
Frequently Asked Questions
What is ADISA Level 5 certification?
ADISA Level 5 (AAL5) is the level of ADISA product-specific testing for data sanitization software, requiring independent testing against recognized sanitization standards.
Why does ADISA certification matter for data sanitization?
It provides independent verification that a product's sanitization capabilities have been tested against recognized standards, rather than relying solely on the vendor's claims.
Is Clear's certification independently verified?
Yes. Clear 1.1.0 was tested by the ADISA Research Center and certified under project ADPA059 in accordance with NIST 800-88r1, NIST 800-88r2, and IEEE 2883.
What industries require ADISA-certified solutions?
ADISA certification is not generally required by law, but regulated industries and enterprise procurement teams may require or prefer independently verified data sanitization solutions.
How does this affect current Clear customers?
Customers using Clear 1.1.0 can reference its AAL5 certification as independent evidence of its tested sanitization capabilities against the applicable standards and media types.
What Comes Next
Clear's AAL5 certification is a documented, independently verified result for a specific version of the software, not a permanent guarantee. As storage technology evolves and new versions of Clear are released, maintaining that level of assurance requires continued independent evaluation.
For organizations evaluating data sanitization solutions, Clear now has a verifiable certification record covering a specific product version, recognized standards, independent testing, and a defined validity period.
See Clear's certification in action or talk to the 99 Technologies team about your data sanitization requirements.










