What's actually in a Certificate of Redaction
An auditor asks: what does CBR Labs ship with each redacted tablet? A field-by-field walkthrough of the Certificate of Redaction and the evidence packet behind it.
“What proves it” is the question we get most often from compliance teams. The answer is a single sheet of paper (and a folder of evidence behind it) that travels with the device for the life of the program. We call it the Certificate of Redaction.
The certificate, field by field
Every certificate is one page, signed in wet ink, and tied to a single serial number. The fields are deliberately boring:
- Device identity. Make, model, model number, and manufacturer serial number. For Apple devices, also the IMEI(s) where present pre-redaction.
- Order reference. The customer’s PO or contract number, the date received, and the date completed.
- Scope of work. A line per component removed: front camera, rear camera, primary microphone, secondary microphone, speakers, Wi-Fi radio, Bluetooth controller, cellular modem, GPS, NFC, UWB — whichever applied to this unit’s scope.
- Method. For each line, the technique used: die removal, controller removal, trace cut, antenna severance, port seal. Auditors care about the verb.
- Verification. What we tested to confirm inert: e.g. “Wi-Fi: scanned 2.4 GHz and 5 GHz, no association attempted; OS reports no Wi-Fi hardware.”
- Technician. The badge ID of the person who performed the work and the badge ID of the QA reviewer. Both are background-checked staff.
- Chain of custody. A reference to the COC packet ID. Receipt signature, work-area entry/exit times, and shipment signature are all in the packet.
- Disclosures. One sentence on warranty impact and one on the independent-service-provider posture (Apple/Samsung/Google are not affiliated). Procurement auditors expect to see this.
The evidence packet
The certificate is a summary. The evidence packet is the substance. For each device, the packet contains:
- Photos at four stages: intake (sealed, with tamper-evident label), pre-redaction (open, with serial visible), post-redaction (open, with each removal area visible), and final pack (closed, in shipping protection).
- Per-component close-ups for any line item that the customer’s scope flagged as audit-significant. A camera removal that matters to a SCIF accreditor gets its own close-up. A speaker removal typically does not.
- Signed COC log: receipt, work-area entry, redaction completion, QA, pack, ship.
- Hash manifest of the photo set so the packet can be re-verified later without trusting our filesystem.
What it deliberately does not contain
The certificate is not a configuration report. It does not list installed apps, MDM enrollment status, or iOS version. Those are runtime properties; they change. The certificate documents a permanent physical change. Mixing the two confuses what was redacted with what is configured, and auditors notice.
How customers use it
For most programs the certificate lives in the asset record and the photos live in the evidence vault. For SCIF accreditation packages, the certificate goes in the SSP/IS appendix and the photos go in the artifact binder. For healthcare, the disclosure paragraph goes in the BAA attachment. Same artifact, different homes.
If you want a redacted (no pun intended) sample of the certificate and a representative evidence packet, ask for one. We email it within a business day — anonymized, no real serials.
See a real sample
Email us and we'll send an anonymized certificate and evidence packet so your auditor can review the format before you commit.