Most people think of shredding as a one-step process: paper goes in, confetti comes out, problem solved. For a casual piece of junk mail, that's roughly true. For tax records, customer files, payroll, medical information, account statements, signed contracts, or anything else covered by HIPAA, GLBA, FACTA, PCI DSS, or your own customer privacy promises, it isn't. There is a whole industry built around the gap between "I shredded it" and "it has been destroyed in a way I can prove," and most office shredders sit firmly on the wrong side of that line.
This guide walks through what secure destruction actually looks like in 2026: the certification that matters, the particle sizes the standards call for, why the shredder under your desk almost certainly doesn't meet them, what a certificate of destruction is and why auditors care, the difference between on-site and off-site shredding, what to do with hard drives and other digital media, and what mailnow.ai will arrange on your behalf when you ask us to destroy something.
NAID AAA certification: the standard that auditors look for
NAID AAA Certification is issued by i-SIGMA (the International Secure Information Governance & Management Association, formerly NAID) and is the de facto industry credential for secure data destruction vendors in North America. It exists because there is no single federal law that says "this is how you destroy a customer record." Instead, regulators point at a moving target — "reasonable measures," "appropriate safeguards," "industry standard" — and NAID AAA is what most auditors, insurers, and regulators have settled on as the answer.
A NAID AAA-certified vendor has been audited (announced and unannounced) on operational security, employee screening and training, chain of custody, equipment and particle sizes, insurance coverage, and certificate of destruction practices. Critically, certification covers specific service types — paper, micro-media (CDs, DVDs, microfiche), hard drives, solid-state drives, and so on — and a vendor may be certified for some and not others. When you're vetting a shredding provider, ask which service types they're certified for, not just whether they hold the certification.
Particle sizes: strip-cut vs. cross-cut vs. micro-cut
Paper shredders are categorized in the U.S. and internationally by DIN 66399, which defines security levels P-1 through P-7 based on the maximum particle size produced. The smaller the particle, the harder the document is to reconstruct. Most office shredders fall in the P-2 to P-4 range; truly secure destruction typically requires P-5 or higher.
| Level | Cut style | Max particle size | Typical use |
|---|---|---|---|
| P-1 | Strip-cut | ≤ 12 mm wide strips | General internal documents — not secure |
| P-2 | Strip-cut | ≤ 6 mm wide strips | Internal documents — not secure for personal data |
| P-3 | Cross-cut | ≤ 320 mm² particles | Sensitive personal data — minimum for many office contexts |
| P-4 | Cross-cut | ≤ 160 mm² particles, ≤ 6 mm wide | Confidential personal data — common office "secure" level |
| P-5 | Cross-cut / micro-cut | ≤ 30 mm² particles, ≤ 2 mm wide | Highly confidential — financial, legal, medical, HR |
| P-6 | Micro-cut | ≤ 10 mm² particles, ≤ 1 mm wide | Secret data — regulated industries, classified-adjacent |
| P-7 | Micro-cut | ≤ 5 mm² particles, ≤ 1 mm wide | Top-secret / national-security-grade destruction |
For most regulated business contexts — anything covered by HIPAA, GLBA, attorney-client privilege, payroll and HR records, or customer financial data — P-4 is a defensible floor and P-5 is the level most NAID AAA-certified vendors run their industrial shredders at by default. Strip-cut (P-1, P-2) is essentially decorative for sensitive documents; reconstruction by hand, by scanner, or by AI-assisted tooling is well-documented and not particularly difficult.
Why most office shredders aren't compliant
The shredder in the corner of your office is almost certainly not what your compliance officer thinks it is. There are several reasons, and they all compound.
- Particle size: most consumer and small-office shredders top out at P-3 or P-4 cross-cut. They look like they're producing tiny pieces, but the pieces are well above what the standards require for sensitive personal data.
- Chain of custody: there isn't one. Documents sit in an unlocked bin next to the shredder, sometimes for days. Anyone in the office — or anyone who walks through the office — can read, photograph, or remove them before they're destroyed.
- Operator verification: nobody is auditing whether the right documents went into the shredder, whether the bin was emptied to a secure waste stream, or whether the shred bag actually made it to a locked dumpster.
- Maintenance and jams: an office shredder that jams halfway through a stack often gets restarted with the half-shredded documents pulled back out and abandoned in the bin or recycling.
- Recycling commingling: many offices empty the shred bag straight into the regular recycling, where it sits in an unlocked container at the curb. Recovered shredded paper has been the source of multiple high-profile data breaches.
- No certificate of destruction: there is no document, no signature, and no audit trail proving anything was destroyed. If a regulator or plaintiff asks "what happened to that record on March 14," the answer is "we think we shredded it."
For a single household or a sole proprietor handling their own mail, an office shredder is fine for routine junk and low-sensitivity documents. For a business that holds anyone else's regulated data — patients, clients, customers, employees — it is not a substitute for a documented destruction process.
Certificates of destruction and why auditors care
A Certificate of Destruction (COD) is the paper trail that turns "we shredded it" into something defensible. A proper COD names the customer, identifies the destruction service, lists the date and location of destruction, describes what was destroyed (containers, weight, or asset list with serial numbers for digital media), states the destruction method and the particle size achieved, and is signed by the destruction operator. NAID AAA-certified vendors issue CODs as a matter of course; office shredders, by definition, do not.
If you ever face an audit, an investigation, a class-action discovery request, or a state attorney general inquiry, the COD is the document that closes the loop. "This record existed on this date, was scheduled for destruction on this date, and was destroyed by this NAID AAA-certified vendor on this date with a Certificate of Destruction we have on file" is a complete answer. "It went in the office shredder sometime that quarter" is not.
On-site vs. off-site shredding
NAID AAA-certified shredding generally comes in two flavors: on-site (mobile) and off-site (plant-based). Both can be fully compliant; they make different tradeoffs.
On-site shredding sends a truck with industrial shredders mounted inside it to your location. Locked collection bins are wheeled out, tipped into the truck, and shredded in place — you can watch through a viewing screen if you want to. The advantages: you never lose physical custody of the documents until they're already shredded, and the COD is issued on the spot. The tradeoffs: it is more expensive per pound, scheduling is less flexible, and the truck has to be able to physically reach your building.
Off-site (plant-based) shredding picks up locked, tamper-evident containers and transports them to a secure destruction facility. The advantages: it is less expensive at scale, more flexible for irregular volumes, and the plant equipment is typically larger and finer than what fits in a truck. The tradeoffs: there is a transit window during which documents are in transit (mitigated by locked containers, GPS-tracked vehicles, and chain-of-custody logs), and the COD is issued after destruction at the plant.
For most business contexts the choice is operational, not security-driven — both are appropriate when the vendor is NAID AAA-certified for the relevant service type and issues a COD. The wrong answer is a vendor who shows up with an unmarked van, no locked container, no certification, and no COD. That is not shredding; that is hauling.
Hard drives and digital media
Paper is the easy half. Digital media — hard drives, solid-state drives, USB sticks, backup tapes, optical discs, smartphones — is where most secure-destruction failures actually happen, because people assume "I deleted the files" or "I formatted the drive" is the same thing as destruction. It isn't.
DIN 66399 has a parallel set of security levels for digital media (H-1 through H-7 for magnetic media like hard drives, E-1 through E-3 for electronic media like SSDs, and so on). A NAID AAA-certified vendor with the digital-media endorsement will physically destroy hard drives — typically by shredding to a particle size appropriate to the media type — and issue a COD listing each drive's serial number. Solid-state drives require finer particle sizes than spinning hard drives, because the underlying flash chips are small enough that coarse shredding can leave recoverable fragments.
- Spinning hard drives (HDDs): physical shredding to ≤ 30 mm particles is the standard; degaussing alone is no longer sufficient for modern high-density drives and is meaningless for SSDs.
- Solid-state drives (SSDs) and flash media: physical shredding to ≤ 10 mm particles, because the flash chips themselves must be destroyed.
- Backup tapes: shredding (not bulk erasure alone), with serial-number-level COD entries.
- Optical media (CDs, DVDs, Blu-ray): shredding to ≤ 30 mm² particles per the optical-media security levels.
- Smartphones, tablets, and other devices with embedded storage: physical destruction of the device or, at minimum, the storage chips — a factory reset is not destruction.
What mailnow.ai provides on request
Every mailnow.ai account includes routine shredding of items you mark for destruction from your dashboard. Day-to-day, that's the right tool for the vast majority of mail — junk, expired statements, marketing, anything where the bar is "don't make this readable from a recycling bin."
For sensitive material that needs documented destruction — tax records, payroll, medical information, signed contracts, anything covered by HIPAA, GLBA, FACTA, or your own customer commitments — we can route the item through a NAID AAA-certified destruction partner on request. That includes secure custody from our facility to the destruction vendor, destruction at NAID AAA-certified particle sizes (P-5 or finer for paper, with appropriate levels for any media you ship to us), and a Certificate of Destruction returned to your account that names the item, the date, the vendor, and the method.
Hard drives and other digital media can be shipped to your mailnow.ai address and queued for the same NAID AAA-certified destruction workflow, with serial-number-level CODs. If you have a recurring need — quarterly purges, an annual retention sweep, an end-of-engagement client cleanup — we can set that up as a standing instruction so you don't have to make the request item-by-item. Reach out from your dashboard or through our contact page if you want to set this up for your account.
Quick reference: when each level of destruction is appropriate
| What you're destroying | Minimum acceptable method | COD needed? |
|---|---|---|
| General junk mail, marketing | Routine shredding | No |
| Old utility bills, expired statements | Cross-cut shredding (P-4) | Recommended |
| Tax records, payroll, HR files | NAID AAA, P-5 or finer | Yes |
| HIPAA-covered medical records | NAID AAA medical-grade, P-5 or finer | Yes — retain 6+ years |
| Client/legal files, signed contracts | NAID AAA, P-5 or finer | Yes |
| Spinning hard drives (HDDs) | NAID AAA physical shredding (≤ 30 mm) | Yes — by serial number |
| Solid-state drives, flash media | NAID AAA physical shredding (≤ 10 mm) | Yes — by serial number |
| Backup tapes, optical media | NAID AAA shredding for the media type | Yes — by serial number |
Destruction you can actually prove
The difference between casual shredding and secure destruction is not the size of the machine — it's the chain of custody, the certified particle size, and the documentation that ties a specific record to a specific destruction event. Office shredders skip all three. NAID AAA-certified vendors exist precisely so that you can answer the question "what happened to this record" with a date, a method, and a signed certificate, instead of a shrug.
If you'd like sensitive items in your mailnow.ai account routed through a NAID AAA-certified destruction partner — one-off, recurring, or for digital media you ship in — just ask, and we'll arrange it and return the certificate to your account.