Auto Secure Login

ASL Shredder — Source library

Public documentation snapshot: 2026-09-08

Original published page

You deleted it. Now prove it.

Removes data, then issues a signed receipt that claims only what was actually proven.

Original published page

You deleted it. Now prove it.

Built for: A practice owner who has to destroy a client's record and still be able to show, years later, exactly what was destroyed and who authorized it · The one person at a small firm who gets asked "where is the disposal record?" and currently has nothing but a memory and a screenshot · An IT lead retiring old laptops, phones and drives who needs the paperwork to match what physically happened to each device · A records or compliance owner running retention schedules and legal holds, who needs deletion to respect both without anyone remembering to check

Original published page

ASL Shredder exists because of this.

You deleted the file months ago. Now someone wants proof. A client asks for their record to be destroyed and wants it in writing. A contract ends and the other side wants written confirmation that their data is gone. An auditor asks what happened to the old backup drive in the closet. You did the right thing at the time, and you have nothing to show for it. Or worse, you have a certificate from a tool that printed a green checkmark and a famous standard's name, and you have no idea whether that sentence is true. Most erasure tools were designed for hard drives that spin. On the solid-state storage inside nearly every laptop and phone sold today, writing over a file does not necessarily touch the place the old data actually lives. The drive's own controller quietly writes somewhere else and leaves the original sitting in a spare cell. Cloud sync, snapshots and backups do the same thing to you from the other direction: the copy you can see is the only copy you deleted. A tool that reports "35 passes complete, data unrecoverable" on that storage is not lying about the passes. It is lying about the conclusion. That false confidence is the part that fails you later, in front of a regulator, an auditor, or opposing counsel. The second half of the problem is the record. Who authorized the destruction. Whether a legal hold was in force at that moment. Whether the retention clock had actually run out or someone just wanted the drive space back. What was actually done, in terms specific enough to mean something. And whether any of it can be checked by a person who was not in the room and has a reason to doubt you. If the answer to all of that is a spreadsheet row that anyone with the file open could edit, you do not have evidence. You have a note.

Original published page

ASL Shredder exists because of this.

The order is inverted. It decides what may honestly be claimed before it acts, instead of acting and then writing a certificate to match.

Original published page

ASL Shredder exists because of this.

It refuses, in plain language, and tells you what would be needed instead. If your current tool has never once refused you, it is not checking anything.

Original published page

ASL Shredder exists because of this.

A higher pass count is never sold as stronger assurance. The 35-pass and 1-to-99 options exist for policy matching and say so on their own labels.

Original published page

ASL Shredder exists because of this.

Familiar standard names are shown with their real status. The DoD-style profiles are marked as historical vendor conventions, because overwrite specifications were removed from the underlying US requirement in 2006.

Original published page

ASL Shredder exists because of this.

The receipt is scoped to the evidence that exists, and no receipt is issued at all when a required piece of that evidence is missing.

Original published page

ASL Shredder exists because of this.

The organization record has no edit and no delete route at all, so "an administrator fixed the log" is not a thing that can happen.

Original published page

ASL Shredder exists because of this.

Product separation is enforced by asking the product itself to confirm who is an administrator, rather than trusting a shared global-admin assumption.

Original published page

How ASL Shredder works, start to finish.

ASL Shredder inverts the usual order. Before anything is destroyed, it decides what could honestly be claimed about this specific item on this specific storage, and it will refuse the operation rather than produce a claim it cannot back. Only then does it act. Only then does it sign a receipt, and the receipt is scoped to exactly the evidence that actually exists. There are five levels of removal, and they are deliberately not interchangeable. Delete removes the active copy and says so plainly, including that backups and storage remnants may remain. Verified clear overwrites and reads back every pass, and is offered only for a confirmed magnetic disk with no copy-on-write or snapshot state. Key destruction makes remaining copies unreadable, and is allowed only when the item has its own unique key and every recoverable copy of that key is accounted for. Managed device wipe applies only to a device your organization actually manages. Physical destruction attestation records an approved operator's evidence; it never pretends an app on your desk degaussed or incinerated anything. Each level produces different wording on the receipt, because each level proves a different thing. Before any of that runs, the request has to clear a gate. Was this person authorized for this item. Is a human actually present right now. Is there a legal hold, in which case nothing happens at all. Has the retention period genuinely expired, or has someone with the authority recorded a valid override. Are the backups resolved, because an irreversible claim cannot be made while a recoverable copy is unknown or retained. Then you type a confirmation phrase built from that exact item, not a checkbox and not a generic yes, and the entire policy is evaluated a second time in the instant before execution. If a hold landed while the confirmation sat on your screen, the operation aborts. The decision is made by the shared service, not by whichever app you happen to be holding. Each desktop and phone app mirrors the same rules so it can tell you early what will and will not be allowed, but that local answer is advisory: the service is the authority, and every app is deliberately narrower than the full library rather than more permissive. A phone cannot talk itself into a claim the service would refuse. What you get back is a signed receipt. It names the operation, the assurance level earned, when it completed, and the evidence behind the claim. It does not contain the file's name, its path, its contents, or the phrase you typed; identity appears only as one-way fingerprints. The signature makes tampering visible, so changing a single character causes verification to fail. That receipt is the artifact that survives the conversation you are dreading, and it is deliberately worded so it cannot be quoted back at you as an overclaim. For organizations, the design puts a running record around the destructive moment: requested, allowed or denied, confirmed, started, finished, and every time someone views or exports it. It can be added to and never edited or removed. There is no edit route and no delete route for anyone, including an administrator, because those routes do not exist in the product. Each product and each organization gets its own separated record with its own keys and its own administrator identity, and before anyone is granted administrator access, Shredder asks that product to confirm the person really is an administrator of that exact organization. Clinical destruction records are held to a longer minimum keep-period than engineering ones. On the personal apps, the equivalent local log ships switched off; turn it on and it stays on your device and still never records a filename. Alongside all of this sits a library of 18 sanitization profiles, and its honesty is the point. Current guidance sits in one group. The historical overwrite recipes people still ask for by name (HMG, DoD-style three and seven pass, Schneier, VSITR, RCMP, the exact 35-pass Gutmann sequence) sit in another, labeled legacy in the interface and in the evidence. Operator-defined runs of 1 to 99 random passes are labeled as operator-defined rather than as any standard. Managed and physical operations are listed so you can see what a real purge or destroy would require, and are marked as things a client application cannot perform. At no point is a higher pass count presented as stronger assurance.

Original published page

Everything in the current release.

Each of these is built and working today. Nothing on this list is a roadmap item.

Original published page

Five levels of removal, each with a claim you can defend

Delete the active copy. Overwrite and read back on a confirmed magnetic disk. Destroy the key so what remains cannot be read. Trigger a wipe on a device your organization manages. Record an approved operator's physical destruction. Each level earns different wording on the receipt, because each proves a different thing, and Shredder will not let you borrow the stronger sentence for the weaker action.

Original published page

It refuses when it cannot prove the claim

Ask for an overwrite on a phone, a solid-state drive, a virtual disk, or storage it cannot positively identify, and Shredder declines and tells you why. Most tools would run the passes and print the certificate anyway. The refusal is the feature: a receipt that would not survive a challenge is worse than no receipt at all, because you would have relied on it.

Original published page

A legal hold is a full stop

If the item is under a legal hold, nothing runs. If a retention period is still counting down, nothing runs unless someone with the authority records a valid, auditable override. These are not warnings you can click through. The destruction simply never starts, and the denial itself is written into the record. A test covers every destructive mode, so a hold cannot be bypassed by picking a different one.

Original published page

The last-second re-check

Policy is evaluated when you ask, and again in the instant before anything is destroyed. If a hold was placed, retention changed, ownership changed, or the item itself changed while the confirmation sat on screen, the operation aborts. A confirmation you started ten minutes ago can never destroy something that became protected nine minutes ago.

Original published page

You type the item's name, not "yes"

Confirmation is an exact phrase built from the specific item in front of you. It expires after five minutes, and it is bound to that one item, that one organization, and the one person who started it. A confirmation for one file cannot be redirected to another, and a colleague cannot finish a destruction you began.

Original published page

A receipt that states only what was observed

Every completed removal produces a signed receipt naming the action, the assurance level it actually earned, the time, and the evidence behind it. If a required piece of that evidence is missing, no receipt is issued at all. Change one character and verification fails, so the receipt is checkable by someone who was not there and has no reason to trust you. It carries no filename, no path and no contents.

Original published page

18 standards profiles, honestly sorted

The library separates today's guidance from the historical overwrite recipes people still request by name: HMG one and three pass, DoD-style three and seven pass, Schneier, VSITR, RCMP, and the exact 35-pass Gutmann sequence from the 1996 paper. Legacy entries are labeled legacy on screen and in the evidence. Pass count is never presented as stronger assurance.

Original published page

Custom pass plans, without the theater

If an internal policy or a customer contract demands a specific number of passes, you can set any count from 1 to 99 random passes with full read-back after each one. It is offered because policies exist, and it is presented as operator-defined rather than as a standard, so nobody downstream can mistake the number for a certification.

Original published page

Managed and physical operations are recorded, never faked

Key destruction, drive-level sanitize commands, enrolled-device wipes, degaussing, shredding and incineration all appear in the library, and none of them can be performed by an application on your desk. Shredder records the operator's evidence and refuses to claim any of them happened without device identity, authorization, completion and validation.

Original published page

An organization record that even an administrator cannot rewrite

Every step around the destructive moment is written to a running record: requested, allowed, denied, confirmed, started, finished, and every view or export. There is no edit and no delete, for anyone, because no such route exists in the product. An administrator may read it, export it, and set how long it is kept, with a recorded reason. That is the entire list of administrator powers.

Original published page

One organization can never read another

Each product and each organization gets its own separated record, its own keys and its own administrator identity. Before anyone receives administrator access, Shredder asks that product to confirm the person really is an administrator of that exact organization. Two organizations that happen to share a name still cannot see one another's records, and a token issued for one product is refused by another.

Original published page

Clinical records keep a longer floor

The clinical tier holds destruction records for a minimum of 2,190 days against 365 days for the engineering tier, with a 2,555-day default for both and room to extend to 36,500. An organization can raise its own floor with a recorded reason. It cannot drop below the tier minimum, and setting a retention period never quietly deletes anything on its own.

Original published page

Names, filenames and contents never enter the record

Records hold action codes, outcomes, timestamps, an operation number, and one-way fingerprints of the item and the person. No patient name, no clinical note, no repository, no path, no file contents, no confirmation phrase, and no raw organization or person identifier is stored. Anything submitted outside that short list is rejected outright rather than quietly saved.

Original published page

A phone app that stays out of your files

The phone app only ever sees the single document you hand it through the system picker and never asks for access to everything on your storage. The released build blocks screenshots, keeps its own backup and device transfer switched off, and refuses unencrypted network connections. Its interface is fully translated into Spanish as well as English, and the optional personal log is off until you switch it on.

Original published page

Numbers we can stand behind.

Every figure below comes from the product's own release record or test suite, not from a marketing estimate.

Original published page

Numbers we can stand behind.

The service decides, not the app in your hand. Each app mirrors the same rules to answer you early, but that local answer is advisory and every app is deliberately narrower than the full library, so a phone can never be more generous than the service.

Original published page

Surfaces and status.

Status as of 2026-09-02. The destruction service is deployed and running, and on 2026-09-02 it was independently confirmed active and answering its health check on the 2026-08-10 release. That is real, but it is internal: the service has no public address by design, no outside organization can reach it, and the repository's own build-and-QA record for that release states that the two product integrations are complete boundaries that were not wired into their live product source, which nothing later in the repository supersedes. None of the apps are distributed either. The Android app (1.2.0, build 3) passed unit tests, a clean build, an isolated launch and a complete removal journey on both an emulator and a physical phone on 2026-08-22, each producing a local evidence receipt, but its store package is unsigned and no listing exists. The Windows app carries embedded version 1.2.0.0 and passes real overwrite, read-back and receipt tests including a 35-pass run, and is not signed for distribution. The Mac source has never been compiled. Nothing here is purchasable or reachable by an outside user today, so the honest label is Internal rather than Early access.

Original published page

Worth more together.

Products on this platform share one sign-in, one support queue, and one engineering standard. These pair naturally with ASL Shredder.

Original published page

ASL Therapy

Clinical records carry the strictest disposal expectations, which is why the clinical tier is the one that holds destruction records to a 2,190-day minimum and refuses to run at all on a clinical retention block or a legal hold. The Therapy-side integration kit is written; ask us where its wiring stands before you plan around it.

Original published page

Repo Runner

Engineering evidence has its own retention story, so it is defined as a separate non-clinical tier with a 365-day floor and its own administrators, who can never see the clinical side. The Repo Runner integration kit is written; ask us where its wiring stands before you plan around it.

Original published page

ASL Files

Stored objects are what people usually mean when they ask for something to be deleted. Shredder is designed to act on them through the product that owns them, so nothing has to be copied elsewhere to be destroyed.

Original published page

ASL Vault

Key destruction is only honest when every recoverable copy of a key is accounted for. Proper key custody is the missing piece that would turn "we deleted it" into a claim that what remains cannot be read.

Original published page

ASL Recovery Center

It answers the opposite question: what can still be pulled back off a disk. Seeing what recovery can do is the fastest way to understand why a pass count is not a promise.

Original published page

ASL Scan

Disposal is one control inside a wider posture review. If you are already being assessed on hardening and data handling, the destruction record is the evidence that closes the retention and disposal questions.

Original published page

Recent progress.

This product ships often. The most recent verified changes, newest first.

Original published page

Recent progress.

2026-08-22 the Android app was rebuilt as a fully native application and re-tested end to end. Unit tests, a clean build, an isolated launch on an emulator, and the complete safe-removal journey on both an emulator and a physical phone, each producing a local evidence receipt. The exact tested build is recorded with its own fingerprint so that artifact can be identified later, and the previous source is kept beside it for comparison rather than deleted. Version 1.2.0 build 3, the one-time purchase model, the single-document file boundary, receipts and the optional personal log all carried through the rebuild, and no running service was changed or restarted by that work. As of.

Original published page

Recent progress.

2026-09-02 the destruction service itself is still on its.

Original published page

Recent progress.

2026-08-10 release, confirmed active and answering its health check. No new integration wiring, signing, store listing or Mac build landed in this period.

Original published page

Recent progress.

The personal app is designed around a one-time $9.99 lifetime purchase with no subscription, and that price is written into the app's own screens, but it is not listed for sale anywhere, so nobody can buy it today. Organization and platform use would be priced with the ASL product it protects, and no price list is published. Ask us and we will quote your situation.

Original published page

What does it cost?

The personal app is designed as a one-time $9.99 purchase with no subscription, and that price is set inside the app, but it is not listed for sale yet, so you cannot buy it today. Organization use would be priced with the ASL product it protects, and there is no published price list. Tell us what you are trying to prove and to whom, and we will quote that rather than pointing you at a pricing page.

Original published page

Can we actually use it today, or is this a roadmap?

Be careful how you read this one. The destruction service is genuinely deployed, running and answering its health check as of 2026-09-02, and the policy core, the receipts and the tamper-evident record are all real and tested. But it has no public address, the apps are built and not distributed, and the integrations into the products that would call it are written as complete boundaries whose wiring into live product source is not something we will claim here. So the honest answer is that this is working internal capability, not something you can switch on this week. Ask us where a specific product stands and we will tell you plainly.

Original published page

We already have a secure erase tool. Why change?

Ask it to do a 35-pass overwrite on a solid-state drive. Most tools will happily run it and print a certificate. Shredder will refuse and tell you what would honestly finish the job on that storage instead. If your current tool has never once refused you, it is not checking anything, and you will find out what its certificates were worth on the day one of them is challenged.

Original published page

Do we have to migrate or move our data?

No. Shredder does not hold your data and does not want a copy. It is designed to act on the item where it already lives, through the product that owns it, and it only ever receives an opaque reference to that item, not its contents, not its name and not its path. There is no import step and nothing to move.

Original published page

What happens to our evidence if we stop using it?

The receipts you have already been issued keep working. Each one is self-contained and carries the identifier of the key that signed it, so it can be checked against the published verification key rather than by asking us to vouch for it, and a receipt from three years ago still verifies after you leave. Your organization's destruction record can be exported before you go, complete with its own integrity check. Nothing about ending the relationship makes past evidence unreadable.

Original published page

What is actually stored about our files and our people?

Action codes, outcomes, timestamps, an operation number, and one-way fingerprints of the item and the person. There are no filenames, no paths, no file contents, no clinical notes, no repository names, no confirmation phrases and no raw identifiers for the organization or the person. Anything submitted outside that short controlled list is rejected rather than quietly saved, and clinical exports are still handled as sensitive even so.

Original published page

Will this make us compliant with HIPAA?

No product can make you compliant, and anyone who tells you otherwise is selling. Shredder implements technical controls that map to the Security Rule's audit, integrity, authentication and transmission objectives, and it holds clinical destruction records to a longer minimum keep-period than the general tier. Your compliance also depends on your policies, your agreements, your training and your state's own record rules, which frequently set retention periods that federal rules do not.

Original published page

Why will it not wipe my phone or my SSD the way other apps claim to?

Because the storage will not let it, and saying otherwise would be a lie in writing. Flash storage moves data as it writes, so the block you are allowed to overwrite is often not the block your old data is sitting in. On those devices Shredder performs the removal the system will actually confirm, records exactly that and nothing more, and shows you the operations that can honestly finish the job: key destruction, a drive-level command, a managed-device wipe, or physical destruction by an approved operator.

Original published page

Who decides what is allowed, the app or the service?

The service. Each app mirrors the same rules so it can tell you early that an overwrite will not be permitted on the storage in front of you, but that local answer is advisory only and the service decides for real. Every app is also deliberately narrower than the full library rather than more permissive, so a compromised or out-of-date client cannot talk its way into a stronger claim than the service would allow.

Original published page

What should I know before I rely on it?

We would rather you hear this from us than discover it later. As of 2026-09-02:

Original published page

What should I know before I rely on it?

Nothing here is purchasable or reachable by an outside organization today. The service runs inside the ASL platform with no public address, and none of the apps are distributed.

Original published page

What should I know before I rely on it?

The two product integrations are written as complete boundaries but the repository's build-and-QA record states they were not wired into their live product source, and nothing later in the repository supersedes that. Ask us for the current wiring status rather than assuming it.

Original published page

What should I know before I rely on it?

The apps are not distributed. The Android app is built and tested but its store package is unsigned and unlisted, the Windows app is built but not signed for public distribution, and the Mac app's source has never been compiled on a Mac.

Original published page

What should I know before I rely on it?

The Mac app is the narrowest of the three. It carries the same 18-profile library for reference, but the modes it can actually run are delete and one-, three- or seven-pass overwrite, not the full library.

Original published page

What should I know before I rely on it?

Overwrite is offered only for a confirmed magnetic disk with no copy-on-write or snapshot state. On phones, solid-state drives, virtual disks and anything it cannot positively identify, the answer is deletion plus an honest record, not an overwrite.

Original published page

What should I know before I rely on it?

Key destruction is not enabled for existing ASL-stored objects, because unique per-object keys and the disposition of every backup copy are not proven end to end. Those paths advertise deletion only until that changes.

Original published page

What should I know before I rely on it?

Setting a retention period is policy, not action. Today the record keeps everything and nothing is automatically removed when a period expires; automatic disposal needs a separately reviewed step that preserves holds and creates its own disposal evidence.

Original published page

What should I know before I rely on it?

A receipt attests the recorded evidence and the policy outcome. It is not a warranty that the hardware behaved contrary to its own documented characteristics.

Original published page

What should I know before I rely on it?

No conformance to IEEE 2883 is claimed. The full normative text requires licensed access, and ASL does not claim conformance from a public abstract.

Original published page

What should I know before I rely on it?

Selecting a familiar standard name does not create compliance or certification, and Shredder says so inside the product itself. The DoD-style profiles are historical vendor conventions, not a current requirement.

Original published page

You deleted it. Now prove it.

Prefer email? contact@autosecurelogin.com

Original published page