You deleted it. Now prove it.
Local Android removal with honest receipts; separate organization-service evidence workflows.
Built for: A practice owner who has to destroy a client's record and still be able to show, years later, exactly what was destroyed and who authorized it · The one person at a small firm who gets asked "where is the disposal record?" and currently has nothing but a memory and a screenshot · An IT lead retiring old laptops, phones and drives who needs the paperwork to match what physically happened to each device · A records or compliance owner running retention schedules and legal holds, who needs deletion to respect both without anyone remembering to check
Standalone Android - updated September 19, 2026
Your files stay with you.
Native, offline and deliberately limited
The personal Android app is native Kotlin. It needs no account, ASL server, Internet permission, subscription or in-app purchase. Google Play handles the planned one-time app purchase. Version 2.0.3, build 7, is a signed Android candidate under final accessibility review, not a public release. The store listing is being prepared. Availability requires completion of that review and Google Play approval.
Choose a file with Android's system picker, review its name and limits, type the exact SHRED phrase, then confirm. Cancel leaves the selected file untouched. Use a disposable sample while testing.
The only executable operation is provider-confirmed logical deletion. It does not overwrite flash storage, empty a provider's trash, remove backups, wipe a device or execute the other 17 reference profiles.
Records with clear boundaries
Receipts are local records of the provider result, not signed organization-service certificates. The optional personal audit is off by default and records an Android Keystore HMAC chain. Version 2.0.3 preserves audit history and offers explicit recovery that preserves the old log without claiming to restore lost history. A pending local record is saved before removal. Unconfirmed outcomes are labeled honestly and never retried automatically; failure to save final evidence does not relabel provider-accepted deletion as a failed removal.
The production build protects app screens and confirmation dialogs, with English and Spanish help and all 18 reference profiles. The Android picker, keyboard, provider and browser are separate apps with their own privacy behavior. Only logical deletion is executable. Pixel 8 acceptance is not recorded for this release; see Google Play for actual availability.
Independent product, official reference sources
ASL LLC does not represent a government or claim government endorsement or certification. Standards are explanatory references, not approval of this app. Historical overwrite recipes are marked as legacy.
- NIST SP 800-88 Rev. 2
- UK NCSC media sanitisation
- Canadian Centre for Cyber Security ITSP.40.006
- NSA media destruction guidance
The organization-service information below describes a separate integration, not a network dependency or a promise that the Android app enforces an organization's legal holds.
The problem
ASL Shredder exists because of this.
You deleted the file months ago. Now someone wants proof. A client asks for their record to be destroyed and wants it in writing. A contract ends and the other side wants written confirmation that their data is gone. An auditor asks what happened to the old backup drive in the closet.
You did the right thing at the time, and you have nothing to show for it. Or worse, you have a certificate from a tool that printed a green checkmark and a famous standard's name, and you have no idea whether that sentence is true.
Most erasure tools were designed for hard drives that spin. On the solid-state storage inside nearly every laptop and phone sold today, writing over a file does not necessarily touch the place the old data actually lives. The drive's own controller quietly writes somewhere else and leaves the original sitting in a spare cell.
Cloud sync, snapshots and backups do the same thing to you from the other direction: the copy you can see is the only copy you deleted. A tool that reports "35 passes complete, data unrecoverable" on that storage is not lying about the passes.
It is lying about the conclusion. That false confidence is the part that fails you later, in front of a regulator, an auditor, or opposing counsel. The second half of the problem is the record. Who authorized the destruction. Whether a legal hold was in force at that moment.
Whether the retention clock had actually run out or someone just wanted the drive space back. What was actually done, in terms specific enough to mean something. And whether any of it can be checked by a person who was not in the room and has a reason to doubt you.
If the answer to all of that is a spreadsheet row that anyone with the file open could edit, you do not have evidence. You have a note.
What changes
- The order is inverted. It decides what may honestly be claimed before it acts, instead of acting and then writing a certificate to match.
- It refuses, in plain language, and tells you what would be needed instead. If your current tool has never once refused you, it is not checking anything.
- A higher pass count is never sold as stronger assurance. The 35-pass and 1-to-99 options exist for policy matching and say so on their own labels.
- Familiar standard names are shown with their real status. The DoD-style profiles are marked as historical vendor conventions, because overwrite specifications were removed from the underlying US requirement in 2006.
- The receipt is scoped to the evidence that exists, and no receipt is issued at all when a required piece of that evidence is missing.
- The organization record has no edit and no delete route at all, so "an administrator fixed the log" is not a thing that can happen.
- Product separation is enforced by asking the product itself to confirm who is an administrator, rather than trusting a shared global-admin assumption.
What it does
How ASL Shredder works, start to finish.
ASL Shredder inverts the usual order. Before anything is destroyed, it decides what could honestly be claimed about this specific item on this specific storage, and it will refuse the operation rather than produce a claim it cannot back. Only then does it act. Only then does it sign a receipt, and the receipt is scoped to exactly the evidence that actually exists.
There are five levels of removal, and they are deliberately not interchangeable. Delete removes the active copy and says so plainly, including that backups and storage remnants may remain. Verified clear overwrites and reads back every pass, and is offered only for a confirmed magnetic disk with no copy-on-write or snapshot state.
Key destruction makes remaining copies unreadable, and is allowed only when the item has its own unique key and every recoverable copy of that key is accounted for. Managed device wipe applies only to a device your organization actually manages. Physical destruction attestation records an approved operator's evidence; it never pretends an app on your desk degaussed or incinerated anything.
Each level produces different wording on the receipt, because each level proves a different thing. Before any of that runs, the request has to clear a gate. Was this person authorized for this item. Is a human actually present right now. Is there a legal hold, in which case nothing happens at all.
Has the retention period genuinely expired, or has someone with the authority recorded a valid override. Are the backups resolved, because an irreversible claim cannot be made while a recoverable copy is unknown or retained. Then you type a confirmation phrase built from that exact item, not a checkbox and not a generic yes, and the entire policy is evaluated a second time in the instant before execution.
If a hold landed while the confirmation sat on your screen, the operation aborts. The decision is made by the shared service, not by whichever app you happen to be holding. Each desktop and phone app mirrors the same rules so it can tell you early what will and will not be allowed, but that local answer is advisory: the service is the authority, and every app is deliberately narrower than the full library rather than more permissive.
A phone cannot talk itself into a claim the service would refuse. What you get back is a signed receipt. It names the operation, the assurance level earned, when it completed, and the evidence behind the claim. It does not contain the file's name, its path, its contents, or the phrase you typed; identity appears only as one-way fingerprints.
The signature makes tampering visible, so changing a single character causes verification to fail. That receipt is the artifact that survives the conversation you are dreading, and it is deliberately worded so it cannot be quoted back at you as an overclaim. For organizations, the design puts a running record around the destructive moment: requested, allowed or denied, confirmed, started, finished, and every time someone views or exports it.
It can be added to and never edited or removed. There is no edit route and no delete route for anyone, including an administrator, because those routes do not exist in the product. Each product and each organization gets its own separated record with its own keys and its own administrator identity, and before anyone is granted administrator access, Shredder asks that product to confirm the person really is an administrator of that exact organization.
Clinical destruction records are held to a longer minimum keep-period than engineering ones. On the personal apps, the equivalent local log ships switched off; turn it on and it stays on your device and still never records a filename. Alongside all of this sits a library of 18 sanitization profiles, and its honesty is the point.
Current guidance sits in one group. The historical overwrite recipes people still ask for by name (HMG, DoD-style three and seven pass, Schneier, VSITR, RCMP, the exact 35-pass Gutmann sequence) sit in another, labeled legacy in the interface and in the evidence. Operator-defined runs of 1 to 99 random passes are labeled as operator-defined rather than as any standard.
Managed and physical operations are listed so you can see what a real purge or destroy would require, and are marked as things a client application cannot perform. At no point is a higher pass count presented as stronger assurance.
Features
Organization service and platform capabilities.
Capabilities depend on the platform and integration. The standalone Android app supports only document-provider logical deletion and local records; it does not provide the organization-service controls described below.
Five levels of removal, each with a claim you can defend
Delete the active copy. Overwrite and read back on a confirmed magnetic disk. Destroy the key so what remains cannot be read. Trigger a wipe on a device your organization manages. Record an approved operator's physical destruction. Each level earns different wording on the receipt, because each proves a different thing, and Shredder will not let you borrow the stronger sentence for the weaker action.
It refuses when it cannot prove the claim
Ask for an overwrite on a phone, a solid-state drive, a virtual disk, or storage it cannot positively identify, and Shredder declines and tells you why. Most tools would run the passes and print the certificate anyway. The refusal is the feature: a receipt that would not survive a challenge is worse than no receipt at all, because you would have relied on it.
A legal hold is a full stop
If the item is under a legal hold, nothing runs. If a retention period is still counting down, nothing runs unless someone with the authority records a valid, auditable override. These are not warnings you can click through. The destruction simply never starts, and the denial itself is written into the record. A test covers every destructive mode, so a hold cannot be bypassed by picking a different one.
The last-second re-check
Policy is evaluated when you ask, and again in the instant before anything is destroyed. If a hold was placed, retention changed, ownership changed, or the item itself changed while the confirmation sat on screen, the operation aborts. A confirmation you started ten minutes ago can never destroy something that became protected nine minutes ago.
You type the item's name, not "yes"
Confirmation is an exact phrase built from the specific item in front of you. It expires after five minutes, and it is bound to that one item, that one organization, and the one person who started it. A confirmation for one file cannot be redirected to another, and a colleague cannot finish a destruction you began.
A receipt that states only what was observed
Every completed removal produces a signed receipt naming the action, the assurance level it actually earned, the time, and the evidence behind it. If a required piece of that evidence is missing, no receipt is issued at all. Change one character and verification fails, so the receipt is checkable by someone who was not there and has no reason to trust you. It carries no filename, no path and no contents.
18 standards profiles, honestly sorted
The library separates today's guidance from the historical overwrite recipes people still request by name: HMG one and three pass, DoD-style three and seven pass, Schneier, VSITR, RCMP, and the exact 35-pass Gutmann sequence from the 1996 paper. Legacy entries are labeled legacy on screen and in the evidence. Pass count is never presented as stronger assurance.
Custom pass plans, without the theater
If an internal policy or a customer contract demands a specific number of passes, you can set any count from 1 to 99 random passes with full read-back after each one. It is offered because policies exist, and it is presented as operator-defined rather than as a standard, so nobody downstream can mistake the number for a certification.
Managed and physical operations are recorded, never faked
Key destruction, drive-level sanitize commands, enrolled-device wipes, degaussing, shredding and incineration all appear in the library, and none of them can be performed by an application on your desk. Shredder records the operator's evidence and refuses to claim any of them happened without device identity, authorization, completion and validation.
An organization record that even an administrator cannot rewrite
Every step around the destructive moment is written to a running record: requested, allowed, denied, confirmed, started, finished, and every view or export. There is no edit and no delete, for anyone, because no such route exists in the product. An administrator may read it, export it, and set how long it is kept, with a recorded reason. That is the entire list of administrator powers.
One organization can never read another
Each product and each organization gets its own separated record, its own keys and its own administrator identity. Before anyone receives administrator access, Shredder asks that product to confirm the person really is an administrator of that exact organization. Two organizations that happen to share a name still cannot see one another's records, and a token issued for one product is refused by another.
Clinical records keep a longer floor
The clinical tier holds destruction records for a minimum of 2,190 days against 365 days for the engineering tier, with a 2,555-day default for both and room to extend to 36,500. An organization can raise its own floor with a recorded reason. It cannot drop below the tier minimum, and setting a retention period never quietly deletes anything on its own.
Names, filenames and contents never enter the record
Records hold action codes, outcomes, timestamps, an operation number, and one-way fingerprints of the item and the person. No patient name, no clinical note, no repository, no path, no file contents, no confirmation phrase, and no raw organization or person identifier is stored. Anything submitted outside that short list is rejected outright rather than quietly saved.
A phone app that stays out of your files
The phone app only ever sees the single document you hand it through the system picker and never asks for access to everything on your storage. The production Android build blocks screenshots, keeps its own backup and device transfer switched off, and refuses unencrypted network connections. Its interface is fully translated into Spanish as well as English, and the optional personal log is off until you switch it on.
Proof
Numbers we can stand behind.
Every figure below comes from the product's own release record or test suite, not from a marketing estimate.
- For organization integrations, the service decides authorization and assurance. The standalone Android app is separate and offline, with provider-confirmed logical deletion only.
Where it runs
Surfaces and status.
Android release preparation was updated September 21, 2026 for version 2.0.3, build 7. Older internal and candidate artifacts remain retained. The separate organization service and other-platform descriptions retain their historical dates; this Android work did not deploy or retest that service, Windows or macOS.
Works with
Worth more together.
Products on this platform share one sign-in, one support queue, and one engineering standard. These pair naturally with ASL Shredder.
ASL Therapy
Clinical records carry the strictest disposal expectations, which is why the clinical tier is the one that holds destruction records to a 2,190-day minimum and refuses to run at all on a clinical retention block or a legal hold. The Therapy-side integration kit is written; ask us where its wiring stands before you plan around it.
Explore →Repo Runner
Engineering evidence has its own retention story, so it is defined as a separate non-clinical tier with a 365-day floor and its own administrators, who can never see the clinical side. The Repo Runner integration kit is written; ask us where its wiring stands before you plan around it.
Explore →ASL Files
Stored objects are what people usually mean when they ask for something to be deleted. Shredder is designed to act on them through the product that owns them, so nothing has to be copied elsewhere to be destroyed.
Explore →ASL Vault
Key destruction is only honest when every recoverable copy of a key is accounted for. Proper key custody is the missing piece that would turn "we deleted it" into a claim that what remains cannot be read.
Explore →ASL Recovery Center
It answers the opposite question: what can still be pulled back off a disk. Seeing what recovery can do is the fastest way to understand why a pass count is not a promise.
Explore →ASL Scan
Disposal is one control inside a wider posture review. If you are already being assessed on hardening and data handling, the destruction record is the evidence that closes the retention and disposal questions.
Explore →What is new
Recent progress.
This product ships often. The most recent verified changes, newest first.
the Android app was rebuilt as a fully native application and re-tested end to end. Unit tests, a clean build, an isolated launch on an emulator, and the complete safe-removal journey on both an emulator and a physical phone, each producing a local evidence receipt.
The exact tested build is recorded with its own fingerprint so that artifact can be identified later, and the previous source is kept beside it for comparison rather than deleted. Version 1.2.0 build 3, the one-time purchase model, the single-document file boundary, receipts and the optional personal log all carried through the rebuild, and no running service was changed or restarted by that work.
As of 2026-09-02 the destruction service itself is still on its 2026-08-10 release, confirmed active and answering its health check. No new integration wiring, signing, store listing or Mac build landed in this period.
Pricing
The standalone Android app is priced at US $4.99 once through Google Play, with local currency and tax differences shown by the Store. There is no subscription or in-app purchase. Public availability depends on Play approval. Organization services and the separate Windows product are not included in the Android purchase; contact us about those products.
Talk to us about ASL ShredderQuestions buyers ask
Straight answers.
What does it cost?
The standalone Android app uses a one-time Google Play purchase, with no subscription or in-app purchase. Public sale is not yet confirmed; use the actual Store listing for the final price when released. Organization pricing and the separate Windows product are not the Android purchase.
Can we actually use it today, or is this a roadmap?
Be careful how you read this one. The destruction service is genuinely deployed, running and answering its health check as of 2026-09-02, and the policy core, the receipts and the tamper-evident record are all real and tested. But it has no public address, Android is available only in internal testing, while public distribution is unverified, and the integrations into the products that would call it are written as complete boundaries whose wiring into live product source is not something we will claim here.
So the honest answer is that this is working internal capability, not something you can switch on this week. Ask us where a specific product stands and we will tell you plainly.
We already have a secure erase tool. Why change?
Ask it to do a 35-pass overwrite on a solid-state drive. Most tools will happily run it and print a certificate. Shredder will refuse and tell you what would honestly finish the job on that storage instead. If your current tool has never once refused you, it is not checking anything, and you will find out what its certificates were worth on the day one of them is challenged.
Do we have to migrate or move our data?
No. Shredder does not hold your data and does not want a copy. It is designed to act on the item where it already lives, through the product that owns it, and it only ever receives an opaque reference to that item, not its contents, not its name and not its path. There is no import step and nothing to move.
What happens to our evidence if we stop using it?
The receipts you have already been issued keep working. Each one is self-contained and carries the identifier of the key that signed it, so it can be checked against the published verification key rather than by asking us to vouch for it, and a receipt from three years ago still verifies after you leave. Your organization's destruction record can be exported before you go, complete with its own integrity check. Nothing about ending the relationship makes past evidence unreadable.
What is actually stored about our files and our people?
Action codes, outcomes, timestamps, an operation number, and one-way fingerprints of the item and the person. There are no filenames, no paths, no file contents, no clinical notes, no repository names, no confirmation phrases and no raw identifiers for the organization or the person. Anything submitted outside that short controlled list is rejected rather than quietly saved, and clinical exports are still handled as sensitive even so.
Will this make us compliant with HIPAA?
No product can make you compliant, and anyone who tells you otherwise is selling. Shredder implements technical controls that map to the Security Rule's audit, integrity, authentication and transmission objectives, and it holds clinical destruction records to a longer minimum keep-period than the general tier. Your compliance also depends on your policies, your agreements, your training and your state's own record rules, which frequently set retention periods that federal rules do not.
Why will it not wipe my phone or my SSD the way other apps claim to?
Because the storage will not let it, and saying otherwise would be a lie in writing. Flash storage moves data as it writes, so the block you are allowed to overwrite is often not the block your old data is sitting in. On those devices Shredder performs the removal the system will actually confirm, records exactly that and nothing more, and shows you the operations that can honestly finish the job: key destruction, a drive-level command, a managed-device wipe, or physical destruction by an approved operator.
Who decides what is allowed, the app or the service?
The organization service decides organization requests. The standalone Android app does not connect to it: it asks Android to delete only the document you selected and records the provider result locally. It does not enforce organization retention policy or offer managed wipe.
What should I know before I rely on it?
We would rather you hear this from us than discover it later. As of 2026-09-02:
- Nothing here is purchasable or reachable by an outside organization today. The service runs inside the ASL platform with no public address, and Android is now in internal testing, not verified as public.
- The two product integrations are written as complete boundaries but the repository's build-and-QA record states they were not wired into their live product source, and nothing later in the repository supersedes that. Ask us for the current wiring status rather than assuming it.
- Android now has a signed internal-testing release and a separate 2.0.1 candidate, not a verified public release. Other-platform statements in this historical section were not reverified by the Android review.
- The Mac app is the narrowest of the three. It carries the same 18-profile library for reference, but the modes it can actually run are delete and one-, three- or seven-pass overwrite, not the full library.
- Overwrite is offered only for a confirmed magnetic disk with no copy-on-write or snapshot state. On phones, solid-state drives, virtual disks and anything it cannot positively identify, the answer is deletion plus an honest record, not an overwrite.
- Key destruction is not enabled for existing ASL-stored objects, because unique per-object keys and the disposition of every backup copy are not proven end to end. Those paths advertise deletion only until that changes.
- Setting a retention period is policy, not action. Today the record keeps everything and nothing is automatically removed when a period expires; automatic disposal needs a separately reviewed step that preserves holds and creates its own disposal evidence.
- A receipt attests the recorded evidence and the policy outcome. It is not a warranty that the hardware behaved contrary to its own documented characteristics.
- No conformance to IEEE 2883 is claimed. The full normative text requires licensed access, and ASL does not claim conformance from a public abstract.
- Selecting a familiar standard name does not create compliance or certification, and Shredder says so inside the product itself. The DoD-style profiles are historical vendor conventions, not a current requirement.
You deleted it. Now prove it.
Local Android removal with honest receipts; separate organization-service evidence workflows.
Prefer email? contact@autosecurelogin.com