Serial Xtractor™
The intelligence layer for asset identification
Live in betaScanners have read barcodes and text for years. The hard part was never reading the label. It was knowing what was worth recording.
What happens on a scan
In under a second it captures and identifies the serial number. Against an asset list that's the whole cycle — a match saves immediately and automatically. Without an asset list, you configure the operator review time.
Scan
The unit captures an image of the device.
Xtract
Barcodes and printed text are read. The serial number is identified. Everything is recorded.
Destroy
With an append-only, auditable record.
You decide how much supervision it gets
The serial shows before it's written. Your operator has a configurable timeframe for review. Say nothing and it records.
Asset list
Scanning against a list of expected assets, an exact match records immediately. On to the next device.
Review window
No list, or no match — the serial is automatically identified and presented for operator review.
Held for review
Anything it can't read confidently waits for operator review. A held asset is a failsafe, not a fault.
A wrong serial is worse than a missing one. Nothing gets invented to force a match. Everything is recorded and searchable.
What comes out
Every session produces a timestamped certificate and an append-only manifest. Your certificate, your client's compliant record.
An integration that writes serials straight into your own system is in development — see the API.
- Your organization and your customer
- Date and time
- Serial, model and device type
- Destruction method
- Total devices by category
- An image of each asset
- Verification — who performed the sanitization, signed in ink
- Validation — who confirmed the method, signed in ink
One record, written as it happens
Every scan is written as its own entry at the moment of capture, with the image, the readings and the operator's decision beside it.
The record is append-only. An entry is written once, and a correction is a new entry rather than an overwrite.
This is what chain of custody means in practice. A spreadsheet can be edited by anyone who opens it, and nothing about it says so.
- Written once, never edited — corrections are new entries, not overwrites
- Every entry keeps its capture, its readings and the operator decision
- Each entry carries the capture time from the device's clock
Two people, two devices, neither of them ours
The operator is a signed-in user in your organization. The witness gets a link, opens the live manifest on their own device and watches it fill as each device is scanned.
The witness has their own concurrence block on the certificate, beside the operator's.
What this is not, yet — cryptographic signatures, or keys your own people hold. A signed, digest-bound attestation is on the roadmap. Today it is two named people, one of whom watched the record being made on a device we do not control.
- The witness needs no account and no app — a link and their own phone
- The link is read-only and expires after 12 hours
- Operator and witness each have their own block on the certificate
Questions
How accurate is it?
Our target is 99%. Our serial extraction model selects the correct serial number on 97.7% of legible drive labels within one character, 87.4% as an exact match, in under a second. Against a supplied asset list, matching is 100%. Measured in our lab on real storage devices, with five-fold cross-validation. All reads without an asset list wait for a configurable amount of time for for operator intervention, mitigating wrong serial number written to your manifest. The figure improves as we develop the model.
How do we know a record hasn't been altered?
Every scan is written once, as its own entry, at the moment of capture, and a correction is added as a new entry rather than overwriting the old one. A hash-chained record and a signed certificate you can check yourself are on our roadmap; we will not claim them until they ship.
Can Nabel forge a record?
We would rather answer this plainly than let you wonder. We operate the database, so today the honest answer is that you are relying on us. Cryptographic proof — a hash-chained record and a signed certificate, so that any alteration by us would be provable — is on our roadmap, and customer-held keys after that.
Can our auditor verify a certificate without involving you?
Not yet. A public verification page, checked against a published key with no account needed, is on our roadmap. Today your auditor checks the certificate against the per-device record behind it.
Who witnesses a destruction, and how is that recorded?
The operator is a signed-in user in your organization. The witness gets a read-only link, opens the live manifest on their own device and watches it fill. Both have their own block on the certificate. It is not yet a cryptographic signature or a key your own people hold; that is on the roadmap and we will not describe it as more than it is.
What does the equipment do with our clients' data?
It depends on the deployment. The offline deployments — secure tablet, fixed mount and on-shredder — have no connectivity. Nothing reaches us, and records leave only when your operator exports them. The mobile app is a connected product: scanning works offline, but it is backed by a cloud service we operate, and sessions, captured images, serials and record entries are held there. If your client's policy will not allow that, the offline deployments exist for exactly that reason. Our privacy notice sets out what the app's service holds. Get in touch to find out more.
Where is the app's data held?
In the United States. Our platform provider runs it on AWS in US-East-2, on infrastructure certified to ISO/IEC 27001 and covered by SOC 2 reporting. To be exact about whose certification that is: it is our provider's, not ours. Nabel Solutions does not yet hold ISO 27001 certification or a SOC 2 report of its own — what we can tell you is that the ground it runs on is independently audited. Our privacy notice names every company that touches your data.
Who designed how our data is handled?
On competence rather than certification: the product's data handling was designed by an ISO/IEC 27001:2022 Lead Implementer who also holds CISSP, CISM and CRISC. Those are individual credentials, held by people rather than by the company — but they are why the design looks the way it does.
Is the app's data backed up?
Yes, frequently, on our infrastructure provider's certified infrastructure.
Can we keep everything on site instead?
Yes. The secure tablet, the fixed mount and the on-shredder unit have no connectivity at all — nothing reaches us, and records leave only when your operator exports them. If a client's policy will not allow asset images and serials on a third party's infrastructure, those deployments exist for exactly that reason. Need a connected on-prem solution, or need it on independent infrastructure, reach out to discuss.
Can it write into the ITAD ERP we already use?
It can but it doesn't, yet. We are looking for integration partners now. Today the record is exported by your operator; the API puts the serial into your system of record as the scan happens instead. If you run an ERP, or built one, get in touch.
We have procurement or security requirements. Who do we talk to?
Us, directly. Get in touch.
How is this different from the barcode scanner we already have?
A barcode scanner gives you every code on the label or a single code but leaves your technician to work out which is the serial. Xtractor identifies the serial itself in a single capture in less than 1 second. That one step is the difference between ~10 seconds an asset and under 1.
What if a device has no barcode at all?
It reads printed text as well, and identifies the serial from that.
Does it need an internet connection?
The offline deployments never do — they ship with no connectivity at all. The mobile app scans without a connection, but needs one to export a manifest and to reach the service behind it. If you need capture and export to work with no network whatsoever, choose an offline deployment.
Can it save a serial without anyone checking it?
Yes, and that is the point — but you control it. You set how many seconds your operator gets to stop a serial before it saves. Set that to zero for hands-off running, or longer if you want eyes on every asset.
What happens when it cannot read a label?
It holds the asset for a person rather than guessing.
Whose name is on the certificate?
Yours. It is your document, issued by your organization to your client.
Will it work on the devices we actually handle?
Only one way to know, give it a try for free on the mobile app.
What does it cost?
It depends on how many stations you need and how you would rather pay for them. Get in touch and we will give you a straight number.
Try it on your own labels
A demo on our devices tells you little about yours. That's the test worth running.
We're on a mission to bring automation to ITAD
Interested in hearing more, or got something you'd like to talk through? Get in touch.