Auto Secure LoginPlatform
InternalApiAndroidWindowsMacosData protection & digital trust

You deleted it. Now prove it.

Local Android removal with honest receipts; separate organization-service evidence workflows.

Built for: A practice owner who has to destroy a client's record and still be able to show, years later, exactly what was destroyed and who authorized it · The one person at a small firm who gets asked "where is the disposal record?" and currently has nothing but a memory and a screenshot · An IT lead retiring old laptops, phones and drives who needs the paperwork to match what physically happened to each device · A records or compliance owner running retention schedules and legal holds, who needs deletion to respect both without anyone remembering to check

18sanitization profiles in the client standards library, with current guidance separated from historical recipes, asserted by a test so a profile cannot quietly go missing
1of those 18 the phone app will actually execute, a provider-confirmed delete, asserted by the same test so a later build cannot quietly widen what the phone claims
35passes in the Gutmann sequence, checked pass by pass against the exact patterns in the original 1996 paper
1–99operator-defined random pass range, refused at both ends so a policy number cannot silently become zero passes or an endless run

Standalone Android - updated September 19, 2026

Your files stay with you.

Native, offline and deliberately limited

The personal Android app is native Kotlin. It needs no account, ASL server, Internet permission, subscription or in-app purchase. Google Play handles the planned one-time app purchase. Version 2.0.3, build 7, is a signed Android candidate under final accessibility review, not a public release. The store listing is being prepared. Availability requires completion of that review and Google Play approval.

Choose a file with Android's system picker, review its name and limits, type the exact SHRED phrase, then confirm. Cancel leaves the selected file untouched. Use a disposable sample while testing.

The only executable operation is provider-confirmed logical deletion. It does not overwrite flash storage, empty a provider's trash, remove backups, wipe a device or execute the other 17 reference profiles.

Records with clear boundaries

Receipts are local records of the provider result, not signed organization-service certificates. The optional personal audit is off by default and records an Android Keystore HMAC chain. Version 2.0.3 preserves audit history and offers explicit recovery that preserves the old log without claiming to restore lost history. A pending local record is saved before removal. Unconfirmed outcomes are labeled honestly and never retried automatically; failure to save final evidence does not relabel provider-accepted deletion as a failed removal.

The production build protects app screens and confirmation dialogs, with English and Spanish help and all 18 reference profiles. The Android picker, keyboard, provider and browser are separate apps with their own privacy behavior. Only logical deletion is executable. Pixel 8 acceptance is not recorded for this release; see Google Play for actual availability.

Android privacy notice · App terms · Support

Independent product, official reference sources

ASL LLC does not represent a government or claim government endorsement or certification. Standards are explanatory references, not approval of this app. Historical overwrite recipes are marked as legacy.

The organization-service information below describes a separate integration, not a network dependency or a promise that the Android app enforces an organization's legal holds.

The problem

ASL Shredder exists because of this.

You deleted the file months ago. Now someone wants proof. A client asks for their record to be destroyed and wants it in writing. A contract ends and the other side wants written confirmation that their data is gone. An auditor asks what happened to the old backup drive in the closet.

You did the right thing at the time, and you have nothing to show for it. Or worse, you have a certificate from a tool that printed a green checkmark and a famous standard's name, and you have no idea whether that sentence is true.

Most erasure tools were designed for hard drives that spin. On the solid-state storage inside nearly every laptop and phone sold today, writing over a file does not necessarily touch the place the old data actually lives. The drive's own controller quietly writes somewhere else and leaves the original sitting in a spare cell.

Cloud sync, snapshots and backups do the same thing to you from the other direction: the copy you can see is the only copy you deleted. A tool that reports "35 passes complete, data unrecoverable" on that storage is not lying about the passes.

It is lying about the conclusion. That false confidence is the part that fails you later, in front of a regulator, an auditor, or opposing counsel. The second half of the problem is the record. Who authorized the destruction. Whether a legal hold was in force at that moment.

Whether the retention clock had actually run out or someone just wanted the drive space back. What was actually done, in terms specific enough to mean something. And whether any of it can be checked by a person who was not in the room and has a reason to doubt you.

If the answer to all of that is a spreadsheet row that anyone with the file open could edit, you do not have evidence. You have a note.

What changes

  • The order is inverted. It decides what may honestly be claimed before it acts, instead of acting and then writing a certificate to match.
  • It refuses, in plain language, and tells you what would be needed instead. If your current tool has never once refused you, it is not checking anything.
  • A higher pass count is never sold as stronger assurance. The 35-pass and 1-to-99 options exist for policy matching and say so on their own labels.
  • Familiar standard names are shown with their real status. The DoD-style profiles are marked as historical vendor conventions, because overwrite specifications were removed from the underlying US requirement in 2006.
  • The receipt is scoped to the evidence that exists, and no receipt is issued at all when a required piece of that evidence is missing.
  • The organization record has no edit and no delete route at all, so "an administrator fixed the log" is not a thing that can happen.
  • Product separation is enforced by asking the product itself to confirm who is an administrator, rather than trusting a shared global-admin assumption.

What it does

How ASL Shredder works, start to finish.

ASL Shredder inverts the usual order. Before anything is destroyed, it decides what could honestly be claimed about this specific item on this specific storage, and it will refuse the operation rather than produce a claim it cannot back. Only then does it act. Only then does it sign a receipt, and the receipt is scoped to exactly the evidence that actually exists.

There are five levels of removal, and they are deliberately not interchangeable. Delete removes the active copy and says so plainly, including that backups and storage remnants may remain. Verified clear overwrites and reads back every pass, and is offered only for a confirmed magnetic disk with no copy-on-write or snapshot state.

Key destruction makes remaining copies unreadable, and is allowed only when the item has its own unique key and every recoverable copy of that key is accounted for. Managed device wipe applies only to a device your organization actually manages. Physical destruction attestation records an approved operator's evidence; it never pretends an app on your desk degaussed or incinerated anything.

Each level produces different wording on the receipt, because each level proves a different thing. Before any of that runs, the request has to clear a gate. Was this person authorized for this item. Is a human actually present right now. Is there a legal hold, in which case nothing happens at all.

Has the retention period genuinely expired, or has someone with the authority recorded a valid override. Are the backups resolved, because an irreversible claim cannot be made while a recoverable copy is unknown or retained. Then you type a confirmation phrase built from that exact item, not a checkbox and not a generic yes, and the entire policy is evaluated a second time in the instant before execution.

If a hold landed while the confirmation sat on your screen, the operation aborts. The decision is made by the shared service, not by whichever app you happen to be holding. Each desktop and phone app mirrors the same rules so it can tell you early what will and will not be allowed, but that local answer is advisory: the service is the authority, and every app is deliberately narrower than the full library rather than more permissive.

A phone cannot talk itself into a claim the service would refuse. What you get back is a signed receipt. It names the operation, the assurance level earned, when it completed, and the evidence behind the claim. It does not contain the file's name, its path, its contents, or the phrase you typed; identity appears only as one-way fingerprints.

The signature makes tampering visible, so changing a single character causes verification to fail. That receipt is the artifact that survives the conversation you are dreading, and it is deliberately worded so it cannot be quoted back at you as an overclaim. For organizations, the design puts a running record around the destructive moment: requested, allowed or denied, confirmed, started, finished, and every time someone views or exports it.

It can be added to and never edited or removed. There is no edit route and no delete route for anyone, including an administrator, because those routes do not exist in the product. Each product and each organization gets its own separated record with its own keys and its own administrator identity, and before anyone is granted administrator access, Shredder asks that product to confirm the person really is an administrator of that exact organization.

Clinical destruction records are held to a longer minimum keep-period than engineering ones. On the personal apps, the equivalent local log ships switched off; turn it on and it stays on your device and still never records a filename. Alongside all of this sits a library of 18 sanitization profiles, and its honesty is the point.

Current guidance sits in one group. The historical overwrite recipes people still ask for by name (HMG, DoD-style three and seven pass, Schneier, VSITR, RCMP, the exact 35-pass Gutmann sequence) sit in another, labeled legacy in the interface and in the evidence. Operator-defined runs of 1 to 99 random passes are labeled as operator-defined rather than as any standard.

Managed and physical operations are listed so you can see what a real purge or destroy would require, and are marked as things a client application cannot perform. At no point is a higher pass count presented as stronger assurance.

Features

Organization service and platform capabilities.

Capabilities depend on the platform and integration. The standalone Android app supports only document-provider logical deletion and local records; it does not provide the organization-service controls described below.

01

Five levels of removal, each with a claim you can defend

Delete the active copy. Overwrite and read back on a confirmed magnetic disk. Destroy the key so what remains cannot be read. Trigger a wipe on a device your organization manages. Record an approved operator's physical destruction. Each level earns different wording on the receipt, because each proves a different thing, and Shredder will not let you borrow the stronger sentence for the weaker action.

02

It refuses when it cannot prove the claim

Ask for an overwrite on a phone, a solid-state drive, a virtual disk, or storage it cannot positively identify, and Shredder declines and tells you why. Most tools would run the passes and print the certificate anyway. The refusal is the feature: a receipt that would not survive a challenge is worse than no receipt at all, because you would have relied on it.

03

A legal hold is a full stop

If the item is under a legal hold, nothing runs. If a retention period is still counting down, nothing runs unless someone with the authority records a valid, auditable override. These are not warnings you can click through. The destruction simply never starts, and the denial itself is written into the record. A test covers every destructive mode, so a hold cannot be bypassed by picking a different one.

04

The last-second re-check

Policy is evaluated when you ask, and again in the instant before anything is destroyed. If a hold was placed, retention changed, ownership changed, or the item itself changed while the confirmation sat on screen, the operation aborts. A confirmation you started ten minutes ago can never destroy something that became protected nine minutes ago.

05

You type the item's name, not "yes"

Confirmation is an exact phrase built from the specific item in front of you. It expires after five minutes, and it is bound to that one item, that one organization, and the one person who started it. A confirmation for one file cannot be redirected to another, and a colleague cannot finish a destruction you began.

06

A receipt that states only what was observed

Every completed removal produces a signed receipt naming the action, the assurance level it actually earned, the time, and the evidence behind it. If a required piece of that evidence is missing, no receipt is issued at all. Change one character and verification fails, so the receipt is checkable by someone who was not there and has no reason to trust you. It carries no filename, no path and no contents.

07

18 standards profiles, honestly sorted

The library separates today's guidance from the historical overwrite recipes people still request by name: HMG one and three pass, DoD-style three and seven pass, Schneier, VSITR, RCMP, and the exact 35-pass Gutmann sequence from the 1996 paper. Legacy entries are labeled legacy on screen and in the evidence. Pass count is never presented as stronger assurance.

08

Custom pass plans, without the theater

If an internal policy or a customer contract demands a specific number of passes, you can set any count from 1 to 99 random passes with full read-back after each one. It is offered because policies exist, and it is presented as operator-defined rather than as a standard, so nobody downstream can mistake the number for a certification.

09

Managed and physical operations are recorded, never faked

Key destruction, drive-level sanitize commands, enrolled-device wipes, degaussing, shredding and incineration all appear in the library, and none of them can be performed by an application on your desk. Shredder records the operator's evidence and refuses to claim any of them happened without device identity, authorization, completion and validation.

10

An organization record that even an administrator cannot rewrite

Every step around the destructive moment is written to a running record: requested, allowed, denied, confirmed, started, finished, and every view or export. There is no edit and no delete, for anyone, because no such route exists in the product. An administrator may read it, export it, and set how long it is kept, with a recorded reason. That is the entire list of administrator powers.

11

One organization can never read another

Each product and each organization gets its own separated record, its own keys and its own administrator identity. Before anyone receives administrator access, Shredder asks that product to confirm the person really is an administrator of that exact organization. Two organizations that happen to share a name still cannot see one another's records, and a token issued for one product is refused by another.

12

Clinical records keep a longer floor

The clinical tier holds destruction records for a minimum of 2,190 days against 365 days for the engineering tier, with a 2,555-day default for both and room to extend to 36,500. An organization can raise its own floor with a recorded reason. It cannot drop below the tier minimum, and setting a retention period never quietly deletes anything on its own.

13

Names, filenames and contents never enter the record

Records hold action codes, outcomes, timestamps, an operation number, and one-way fingerprints of the item and the person. No patient name, no clinical note, no repository, no path, no file contents, no confirmation phrase, and no raw organization or person identifier is stored. Anything submitted outside that short list is rejected outright rather than quietly saved.

14

A phone app that stays out of your files

The phone app only ever sees the single document you hand it through the system picker and never asks for access to everything on your storage. The production Android build blocks screenshots, keeps its own backup and device transfer switched off, and refuses unencrypted network connections. Its interface is fully translated into Spanish as well as English, and the optional personal log is off until you switch it on.

Proof

Numbers we can stand behind.

Every figure below comes from the product's own release record or test suite, not from a marketing estimate.

18sanitization profiles in the client standards library, with current guidance separated from historical recipes, asserted by a test so a profile cannot quietly go missing
1of those 18 the phone app will actually execute, a provider-confirmed delete, asserted by the same test so a later build cannot quietly widen what the phone claims
35passes in the Gutmann sequence, checked pass by pass against the exact patterns in the original 1996 paper
1–99operator-defined random pass range, refused at both ends so a policy number cannot silently become zero passes or an endless run
2,190 daysminimum keep-period for a clinical destruction record, against 365 days for the engineering tier
2,555 daysdefault keep-period for a destruction record in both organization tiers before anyone changes it
36,500 dayslongest retention an organization may set for its own destruction record, with a recorded reason
6.87:1lowest contrast ratio measured across the product's colour pairs; every measured pair clears WCAG AA for normal text
  • For organization integrations, the service decides authorization and assurance. The standalone Android app is separate and offline, with provider-confirmed logical deletion only.

Where it runs

Surfaces and status.

API
Api · 0.3.0, confirmed active and answering its health check 2026-09-02Running inside the ASL platform and reachable only from within it; no public address by design, and no outside organization can call it today
AND
Android · 2.0.3 (build 7), native Kotlin candidateOffline native Android with local evidence, optional audit, English and Spanish help. Final accessibility review is pending. This candidate is not public; current Pixel acceptance is not claimed.
WIN
Windows · 1.2.0.0Built and tested, including real overwrite, read-back and 35-pass runs against disposable files; not signed for public distribution
MAC
Macos · 1.2 sourceIn development. Source is complete and carries the same 18-profile library, but it has never been compiled, signed or notarized on a Mac, and its executable modes are limited to delete and one-, three- or seven-pass overwrite

Android release preparation was updated September 21, 2026 for version 2.0.3, build 7. Older internal and candidate artifacts remain retained. The separate organization service and other-platform descriptions retain their historical dates; this Android work did not deploy or retest that service, Windows or macOS.

Works with

Worth more together.

Products on this platform share one sign-in, one support queue, and one engineering standard. These pair naturally with ASL Shredder.

TH
Early access

ASL Therapy

Clinical records carry the strictest disposal expectations, which is why the clinical tier is the one that holds destruction records to a 2,190-day minimum and refuses to run at all on a clinical retention block or a legal hold. The Therapy-side integration kit is written; ask us where its wiring stands before you plan around it.

Explore →
RR
Early access

Repo Runner

Engineering evidence has its own retention story, so it is defined as a separate non-clinical tier with a 365-day floor and its own administrators, who can never see the clinical side. The Repo Runner integration kit is written; ask us where its wiring stands before you plan around it.

Explore →
FI
Live

ASL Files

Stored objects are what people usually mean when they ask for something to be deleted. Shredder is designed to act on them through the product that owns them, so nothing has to be copied elsewhere to be destroyed.

Explore →
VA
Internal

ASL Vault

Key destruction is only honest when every recoverable copy of a key is accounted for. Proper key custody is the missing piece that would turn "we deleted it" into a claim that what remains cannot be read.

Explore →
RC
Live

ASL Recovery Center

It answers the opposite question: what can still be pulled back off a disk. Seeing what recovery can do is the fastest way to understand why a pass count is not a promise.

Explore →
SC
Live

ASL Scan

Disposal is one control inside a wider posture review. If you are already being assessed on hardening and data handling, the destruction record is the evidence that closes the retention and disposal questions.

Explore →

What is new

Recent progress.

This product ships often. The most recent verified changes, newest first.

  • the Android app was rebuilt as a fully native application and re-tested end to end. Unit tests, a clean build, an isolated launch on an emulator, and the complete safe-removal journey on both an emulator and a physical phone, each producing a local evidence receipt.

    The exact tested build is recorded with its own fingerprint so that artifact can be identified later, and the previous source is kept beside it for comparison rather than deleted. Version 1.2.0 build 3, the one-time purchase model, the single-document file boundary, receipts and the optional personal log all carried through the rebuild, and no running service was changed or restarted by that work.

    As of 2026-09-02 the destruction service itself is still on its 2026-08-10 release, confirmed active and answering its health check. No new integration wiring, signing, store listing or Mac build landed in this period.

Pricing

The standalone Android app is priced at US $4.99 once through Google Play, with local currency and tax differences shown by the Store. There is no subscription or in-app purchase. Public availability depends on Play approval. Organization services and the separate Windows product are not included in the Android purchase; contact us about those products.

Talk to us about ASL Shredder
Honest by default. We publish the standard each product meets and the limits of each safeguard next to the feature, not in a footnote. If you cannot find an answer on this page, the assistant in the corner reads only these pages and will say so rather than guess.

Questions buyers ask

Straight answers.

What does it cost?

The standalone Android app uses a one-time Google Play purchase, with no subscription or in-app purchase. Public sale is not yet confirmed; use the actual Store listing for the final price when released. Organization pricing and the separate Windows product are not the Android purchase.

Can we actually use it today, or is this a roadmap?

Be careful how you read this one. The destruction service is genuinely deployed, running and answering its health check as of 2026-09-02, and the policy core, the receipts and the tamper-evident record are all real and tested. But it has no public address, Android is available only in internal testing, while public distribution is unverified, and the integrations into the products that would call it are written as complete boundaries whose wiring into live product source is not something we will claim here.

So the honest answer is that this is working internal capability, not something you can switch on this week. Ask us where a specific product stands and we will tell you plainly.

We already have a secure erase tool. Why change?

Ask it to do a 35-pass overwrite on a solid-state drive. Most tools will happily run it and print a certificate. Shredder will refuse and tell you what would honestly finish the job on that storage instead. If your current tool has never once refused you, it is not checking anything, and you will find out what its certificates were worth on the day one of them is challenged.

Do we have to migrate or move our data?

No. Shredder does not hold your data and does not want a copy. It is designed to act on the item where it already lives, through the product that owns it, and it only ever receives an opaque reference to that item, not its contents, not its name and not its path. There is no import step and nothing to move.

What happens to our evidence if we stop using it?

The receipts you have already been issued keep working. Each one is self-contained and carries the identifier of the key that signed it, so it can be checked against the published verification key rather than by asking us to vouch for it, and a receipt from three years ago still verifies after you leave. Your organization's destruction record can be exported before you go, complete with its own integrity check. Nothing about ending the relationship makes past evidence unreadable.

What is actually stored about our files and our people?

Action codes, outcomes, timestamps, an operation number, and one-way fingerprints of the item and the person. There are no filenames, no paths, no file contents, no clinical notes, no repository names, no confirmation phrases and no raw identifiers for the organization or the person. Anything submitted outside that short controlled list is rejected rather than quietly saved, and clinical exports are still handled as sensitive even so.

Will this make us compliant with HIPAA?

No product can make you compliant, and anyone who tells you otherwise is selling. Shredder implements technical controls that map to the Security Rule's audit, integrity, authentication and transmission objectives, and it holds clinical destruction records to a longer minimum keep-period than the general tier. Your compliance also depends on your policies, your agreements, your training and your state's own record rules, which frequently set retention periods that federal rules do not.

Why will it not wipe my phone or my SSD the way other apps claim to?

Because the storage will not let it, and saying otherwise would be a lie in writing. Flash storage moves data as it writes, so the block you are allowed to overwrite is often not the block your old data is sitting in. On those devices Shredder performs the removal the system will actually confirm, records exactly that and nothing more, and shows you the operations that can honestly finish the job: key destruction, a drive-level command, a managed-device wipe, or physical destruction by an approved operator.

Who decides what is allowed, the app or the service?

The organization service decides organization requests. The standalone Android app does not connect to it: it asks Android to delete only the document you selected and records the provider result locally. It does not enforce organization retention policy or offer managed wipe.

What should I know before I rely on it?

We would rather you hear this from us than discover it later. As of 2026-09-02:

  • Nothing here is purchasable or reachable by an outside organization today. The service runs inside the ASL platform with no public address, and Android is now in internal testing, not verified as public.
  • The two product integrations are written as complete boundaries but the repository's build-and-QA record states they were not wired into their live product source, and nothing later in the repository supersedes that. Ask us for the current wiring status rather than assuming it.
  • Android now has a signed internal-testing release and a separate 2.0.1 candidate, not a verified public release. Other-platform statements in this historical section were not reverified by the Android review.
  • The Mac app is the narrowest of the three. It carries the same 18-profile library for reference, but the modes it can actually run are delete and one-, three- or seven-pass overwrite, not the full library.
  • Overwrite is offered only for a confirmed magnetic disk with no copy-on-write or snapshot state. On phones, solid-state drives, virtual disks and anything it cannot positively identify, the answer is deletion plus an honest record, not an overwrite.
  • Key destruction is not enabled for existing ASL-stored objects, because unique per-object keys and the disposition of every backup copy are not proven end to end. Those paths advertise deletion only until that changes.
  • Setting a retention period is policy, not action. Today the record keeps everything and nothing is automatically removed when a period expires; automatic disposal needs a separately reviewed step that preserves holds and creates its own disposal evidence.
  • A receipt attests the recorded evidence and the policy outcome. It is not a warranty that the hardware behaved contrary to its own documented characteristics.
  • No conformance to IEEE 2883 is claimed. The full normative text requires licensed access, and ASL does not claim conformance from a public abstract.
  • Selecting a familiar standard name does not create compliance or certification, and Shredder says so inside the product itself. The DoD-style profiles are historical vendor conventions, not a current requirement.

You deleted it. Now prove it.

Local Android removal with honest receipts; separate organization-service evidence workflows.

Prefer email? contact@autosecurelogin.com

Help / Ayuda