ITAD for data centers and IT operations in Mexico
Every refresh cycle pushes hundreds of data-bearing media out of your site, along with residual value almost nobody appraises before scrapping it. We sanitize with a certificate per serial number, recover what has a market, and hand you a file that reconciles against your inventory.
Business and institutional clients only — minimum 20 units per pickup.
- Certificate per serial number
- Reconciled to your inventory
- Maintenance windows
- Residual value recovered
Why retiring IT hardware looks nothing like retiring office equipment
An office retires thirty laptops every three years. A data center or a serious IT operation retires density: hundreds of storage media in a single move, each one holding live data until the second it is sanitized, inside a window that cannot slip, against an inventory somebody will have to reconcile afterwards.
That changes the underlying problem. It is not enough for the material to leave and be recycled — you have to be able to prove, medium by medium, what was done to each one. And running alongside it is a second conversation that usually gets lost: the hardware you are retiring is still worth money, and once it goes out the door as generic scrap, that value is gone.
What leaves an IT site
Servers and compute nodes
Rack and blade, with their memory, CPUs and controllers. This is where most of the residual value sits, and where appraising before recovery pays off most.
Storage media
HDDs, SSDs, NVMe, full arrays and backup tape. Each technology sanitizes differently — this is the exact point where improvised processes break.
Network and transport gear
Switches, routers, firewalls, patch panels and optics. Transceivers are small, easy to forget and carry a real secondary market.
Power and backup
UPS units, battery banks and PDUs. Batteries are a separate stream with their own rules and are segregated at pickup.
Racks, rails and structure
Cabinets, rails, cable management and structured cabling. Low value per unit, high volume, and guaranteed to be in the way if it does not leave with the rest.
The spares cage
Replacement drives, power supplies, memory and cards kept "just in case" for platforms already retired. Usually discovered last, and usually holding data.
The storage media problem, at scale
This is the technical point where improvised processes break, because not every medium sanitizes the same way — and applying the wrong method produces a certificate that proves nothing:
- Spinning hard drives. Accept verified overwrite, degaussing or physical destruction. The most flexible case, and the one everybody pictures.
- SSD and NVMe. Degaussing does not work: there is no magnetic domain to disrupt in a flash cell. The route is verified erasure using NIST 800-88 methods, or physical destruction of the chip — destroying the enclosure does not destroy the memory.
- Backup tape. Magnetic media, so degaussing or destruction both apply. Usually the oldest thing on site and the one holding the most history.
- Encryption at rest. Not the same as sanitization. Cryptographic erase is recognized within the standard, but it depends on the implementation supporting it and on verified key destruction. Confirmed per model, not assumed.
That is why the certificate we issue states the level applied — Clear, Purge or Destroy — and not just the word "wiped". The full deliverable is described on certified data destruction.
Reconciliation is what turns a removal into evidence
A security auditor rarely asks whether you recycled. They ask something else: of the 412 drives your inventory says were in that rack, where is the certificate for each one? A removal that does not reconcile by serial number against your asset register or CMDB leaves gaps, and gaps surface months later, when nobody remembers what happened to that lot.
So we start from the inventory and close against it. What left is compared to what was declared, and discrepancies get explained at the time rather than during the audit.
The value walking out the door
In a data center, value recovery is not a footnote: recent-generation servers, memory, CPUs, switches and optics have a real secondary market. Transceivers are the favourite example — they fit in a pocket, they stay plugged into the switch heading for scrap, and they are worth considerably more than they weigh.
We appraise the lot and tell you what is worth keeping to place yourself and what should go to material recovery, always by composition and never at a flat rate per kilo. On mid-sized projects that revenue covers a considerable share of the removal cost. See asset valuation and buyback and server and network equipment purchase. When the material leaves by the pallet — boards, supplies, cabling — the route is production scrap buyback.
How an orderly removal runs
- 01
Inventory and pre-reconciliation
We record what is leaving against your asset register or CMDB. A removal that does not reconcile by serial number leaves gaps your audit will find later.
- 02
Set the sanitization level
By media type and by policy: verified erasure for anything being reused, physical destruction for anything that cannot leave intact under any circumstances.
- 03
Work the maintenance window
We schedule inside your window, with an agreed rack sequence and named personnel. Your production does not stop for the removal.
- 04
Sanitize and certify
Every medium is processed and certified per serial number, with method, level, date and operator. Reconciliation closes against the opening inventory.
- 05
Where the value is, and whose it is
We tell you what is worth placing yourself — that revenue is yours in full — and what we buy on material composition.
- 06
Recycle and document
Whatever is not reused is recycled under Mexican NOM-161-SEMARNAT, with a disposal record and metrics for your reporting.
The physical side of the work — rack teardown, cable removal, packing and handling — is covered on equipment decommissioning.
Which frameworks apply, and what your audit will ask for
Three things run in parallel, and it is worth not confusing them:
- NIST 800-88 is the reference standard for media sanitization. It is a framework of methods, not a certification scheme: it defines the Clear, Purge and Destroy levels that appear on the certificate.
- NOM-161-SEMARNAT governs disposal of the resulting waste: your e-waste is special-handling waste under Mexican law and you must be able to demonstrate its destination. See the compliance guide.
- Mexico’s LFPDPPP and, if your organization operates under a framework such as ISO 27001, its media-disposal control — that is where our evidence fits. The framework is your organization’s, not ours; we produce the records that feed it.
Tonnage and landfill-diversion metrics are consolidated separately for your ESG reporting.
Colocation, hybrid cloud and third-party sites
Fewer and fewer companies retire hardware from a site they own. If your equipment lives in a colocation facility, ownership and data responsibility remain yours, but access belongs to the site operator: windows, credentials, escorts and material-egress rules. None of that is an obstacle when it is coordinated from the start, and all of it is a serious problem discovered on removal day. Put us in touch with the operator when the project is scheduled, not when we arrive.
Refresh is predictable — run it as a program
Unlike most sectors, here you know months ahead what is being retired: refresh cycles are planned and budgeted. That makes it possible to agree in advance the sanitization level per media type, the valuation method and the reporting format, so each cycle runs without renegotiating the process. Message us on WhatsApp or through the contact page and we will set it up.
IT hardware retirement questions
Our drives are encrypted. Isn’t that enough?
Encryption is not sanitization. Encryption at rest protects the data while the key stays under your control; the moment the medium leaves your perimeter, security depends on that key having been properly destroyed and on the implementation actually supporting it. Cryptographic erase is a recognized technique within NIST 800-88, but only where the device implements it correctly and key destruction is verified — and that has to be confirmed per model, not assumed. This is why our certificate states the level applied (Clear, Purge or Destroy) rather than just saying "wiped".
Can SSDs be degaussed?
No. Degaussing works on magnetic media — spinning hard drives and tape — because it disrupts the magnetic field holding the data. An SSD stores in flash memory cells with no magnetic domain to disrupt: running it through a degausser erases nothing and produces a false sense of compliance. For solid state the route is verified erasure using NIST 800-88 methods, or physical destruction of the chip rather than the enclosure.
What about backup tape?
It is the most overlooked stream and the one holding the most history: an eight-year-old tape can carry full backups of systems that no longer exist. Being magnetic media it accepts degaussing, and where policy requires it, physical destruction. Either way it enters the same per-serial-number certificate scheme.
Can you work inside our maintenance window?
Yes, and that is the normal way to do it. We agree the rack sequence, who enters, access credentials and hours, and the removal runs without touching what stays in production. For large volumes it is better to split the project across several windows rather than forcing it into one: the result is more orderly and reconciles better.
We are in a colocation facility. Does that change things?
It changes the logistics, not the substance. The equipment is yours and so is responsibility for the data, but access is controlled by the site operator: windows, credentials, escorts and material-egress rules are theirs. We have done it; what we ask is to be put in touch with the operator at planning time, not on removal day.
How much can we recover from retired hardware?
It depends on generation and condition, and in a data center it is usually more than people expect. Reasonably recent servers, memory, CPUs, switches and optics have a real secondary market; what does not is valued on recoverable material. We do not resell equipment: we destroy the drive and the machine stays with you, so if you place it, that income is yours in full. What we do buy are the parts with material value — boards, processors, memory — valued on composition and never at a flat rate per kilo. We appraise the lot and tell you what is worth placing yourself and what is worth sending to us.
What does our security audit actually receive?
The package an auditor can follow end to end: opening inventory reconciled against what left, a destruction or erasure certificate per serial number stating method and level applied, chain of custody with dates and responsible parties, and the final-destination record for the material under NOM-161-SEMARNAT. If your organization operates under a framework such as ISO 27001, that evidence is what feeds its media-disposal control.
And the UPS batteries?
They are handled as a separate stream from pickup onward, because they may fall under different rules than the rest of the e-waste. Mixing them onto the same pallet as compute equipment is a bad idea: segregating at source keeps a whole lot from getting documentally complicated over a few battery banks.
Refresh or decommission coming up?
Certified sanitization medium by medium, reconciliation against your inventory, and the residual value back in your budget.