How is data wiped after rental termination?

How is data wiped after rental termination?

Oracle Cloud Infrastructure (OCI), data wiping isn't just a simple "delete" command; it is a multi-layered decommissioning process designed to meet the highest security standards (like NIST 800-88).

Whether you are deleting a single volume or terminating your entire tenancy, OCI uses automated "cleansing" protocols to ensure that no digital footprint of your data remains for the next tenant.

1. The Immediate "Logical" Delete

When you terminate an instance or delete a block volume, the first thing OCI does is sever the logical connection.

  • The Action: The pointers to your data are removed, and the storage blocks are marked as "unallocated" in the cloud control plane.

  • The Result: Even before the physical wipe begins, the data is immediately inaccessible to your own users and the OCI APIs.

2. Automated Disk Sanitization (NIST Standards)

Once storage is unallocated, OCI’s automated backend processes take over to sanitize the physical media.

  • Standard Storage: OCI follows NIST SP 800-88 guidelines for media sanitization. For standard virtualized storage, this involves overwriting the blocks with zeros or random patterns before that physical space can be reassigned to another customer.

  • Bare Metal & NVMe: Because Bare Metal tenants have direct access to physical hardware, the "clean up" is more aggressive. After termination, the server undergoes an automated disk and firmware-level wipe. This process clears not just the data on the drives, but also any configuration data stored in the hardware's non-volatile memory.

3. Cryptographic Erasure (The "Kill Switch")

If you use Customer-Managed Keys (CMK), you have a secondary, instantaneous way to "wipe" your data.

  • The Process: By deleting the master encryption key in your OCI Vault (or revoking access from an external HSM), the data on the disks becomes cryptographically erased.

  • The Result: Even if a malicious actor physically stole the hard drives from an Oracle data center, the data would be nothing but random "noise" that is mathematically impossible to decrypt.

4. Tenancy Deletion: The 30-Day Safety Net

If you decide to leave OCI entirely and delete your Tenancy, Oracle adds a cooling-off period to prevent accidental "catastrophic" data loss.

  • Suspension Phase: When you request tenancy deletion, all resources are immediately suspended (shut down), and billing stops.

  • The 30-Day Window: Your data remains in a "locked" state for 30 days. During this time, you can contact Oracle Support to reverse the deletion if it was a mistake.

  • Permanent Purge: After 30 days, the "Work Request" completes, and all resources—including identity data, metadata, and storage—are permanently purged and the hardware is sanitized for the next user.


Summary Table: Wiping Methods by Resource

Resource TypeWiping MethodStandard
Virtual MachinesLogical detachment + Block OverwriteNIST 800-88 "Clear"
Bare MetalFull Disk & Firmware ScrubNIST 800-88 "Purge"
Object StorageMetadata deletion + Pointer removalInternal Purge Protocol
Encrypted DataKey Deletion (Cryptographic Erase)Instant Irretrievability

Pro-Tip: The Sanitization Certificate

For specialized hardware like OCI Roving Edge devices (which are physically shipped to your location), OCI provides a Sanitization Certificate feature. Before returning the device, you can trigger a "Deep Wipe" (which can take 10–20 hours) and the device will generate a cryptographic certificate proving the data was destroyed.

Looking for servers Rental ?

Call Our Expert :


  • (call for rental enquiries)

Email us :