Privacy and preparation
Shipping data on encrypted hard drives: a step-by-step chain of custody
By SourceX Editorial · Updated
Short answer
To ship data on an encrypted hard drive safely, encrypt the whole drive, record a hash of every file, seal it in tamper-evident packaging, log each handover, and send the decryption key by a separate channel only after the recipient confirms the seal is intact. The chain closes when hashes match and the drive is returned or destroyed.
Key takeaways
- The drive and its decryption key should never travel together or through the same channel.
- A hash manifest lets both sides prove that the files that arrived match the files that left.
- Release the key only after the recipient confirms the bag serial number and an unbroken seal.
- Every handover, from the server room to the courier to the recipient, gets a dated log entry and a name.
- The chain of custody ends with a documented return or destruction, not with delivery.
When shipping a drive beats an online transfer#
Shipping an encrypted drive beats an online transfer when a dataset is too large to move over the network in a reasonable time, or when the recipient will only load data inside an isolated environment. Multi-terabyte archives of photos, scanned documents, machine logs or full mailbox exports are the usual cases.
Physical shipment changes the risk rather than removing it. Online transfer risks misdirected links and unverified recipients; a drive risks loss, theft and quiet copying in transit. Encryption, hashing and a custody log answer those risks, and the table compares the main delivery routes.
| Delivery route | Fits when | Main custody risk |
|---|---|---|
| Recipient access to data in your own storage | You can grant scoped, expiring access | Over-broad or long-lived credentials |
| Encrypted network transfer | The package moves within an acceptable window | Misdirected links and unverified recipients |
| Encrypted drive by courier | The package is very large or the recipient works offline | Loss, theft or tampering in transit |
| Encrypted drive carried by a named employee | The stakes justify someone traveling | One person holds both the drive and its context |
The chain of custody in eight steps#
The chain of custody for a shipped drive is a fixed sequence in which every step leaves a record that someone outside the project could check later. Run it the same way every time, so a missing entry stands out instead of blending in.
- Step 1, encrypt: copy only the approved release onto new media and encrypt the whole drive or a container on it.
- Step 2, hash: generate a manifest with a cryptographic hash for every file and store it with the custody record.
- Step 3, seal: place the drive in a numbered tamper-evident bag, with a second person witnessing, and photograph it.
- Step 4, log: open the custody record with the drive serial, bag serial, manifest reference and the names of who prepared and sealed it.
- Step 5, ship: use a tracked, signature-required service addressed to a named recipient, with nothing on the label about the contents.
- Step 6, send the key separately: release it by a different channel only after the recipient confirms the seal.
- Step 7, confirm: the recipient recomputes the hashes, reports any mismatch and signs a receipt.
- Step 8, return or destroy: close the record with a return receipt or a certificate of destruction.
Encrypting and hashing before the drive leaves#
Encryption for a shipped drive should cover the entire volume or a sealed container, never individual files picked by hand. Hardware-encrypted drives with a recognized validation such as FIPS 140, or software such as BitLocker, FileVault, LUKS or VeraCrypt on a new drive, are common choices, and the decision usually follows what the recipient can open on their side.
Use new or freshly sanitized media, and copy the release your approver signed off from the prepared package rather than from source systems. A drive that once held other files can carry recoverable remnants, and a copy pulled from a live system can include records that preparation removed.
Hashing turns a claim that the files arrived into something both sides can prove. Generate a SHA-256 hash for every file, keep the manifest with the custody record and send the recipient a copy by a channel separate from the drive; any file altered in transit will fail the comparison.
Sealing, shipping and the custody log#
The custody log is the document that shows who held the drive at every point, and it should be opened before the drive is sealed. A second person should witness the sealing and initial the entry, because a log written by one person cannot show that nobody else touched the drive.
Address the package to a named individual, require a signature and keep the label plain. Nothing on the box should suggest it holds company records, and the tracking number belongs in the log, not in the email that carries the key.
| Log field | Example entry | Why it matters |
|---|---|---|
| Drive identifier | Manufacturer serial number | Ties the record to one physical device |
| Seal identifier | Tamper-evident bag serial and photo reference | Shows whether the bag was opened or swapped |
| Manifest reference | Manifest file name and its own hash | Links the drive to its exact contents |
| Prepared and sealed by | Two names with date and time | Puts a witness on the sealing |
| Carrier handover | Tracking number, pickup time, driver signature | Covers the transit leg |
| Recipient receipt | Name, time, seal condition, serial match | Proves the drive arrived intact |
| Closure | Return receipt or destruction certificate | Ends the chain |
Releasing the key only after the seal checks out#
The decryption key should reach the recipient only after they confirm in writing that the bag serial matches the log and the seal is unbroken. Sending the key early means a drive opened in transit could be read before anyone notices the damaged bag.
Use a channel unrelated to the shipment: a password manager share, an encrypted message to a verified contact, or a call to a phone number you already hold rather than one printed in an email. Never put the key in the same message as the tracking details.
Limit who holds the key on each side. One named custodian at the supplier and one at the recipient is easier to account for than a shared mailbox, and the log should record when and to whom the key was released.
When something goes wrong in transit#
A broken seal, a hash mismatch or a missing package is handled by pausing the chain, holding the key back and recording what happened. Encryption is what keeps an incident small, which is the whole reason the key and the drive travel apart.
Bring counsel in quickly if a drive is lost and there is any doubt about the encryption or the key handling. Whether an incident triggers breach notification depends on the data and the laws that apply, and encrypted data whose key stayed secure is often treated differently from readable data.
| Event | Immediate action | What to record |
|---|---|---|
| Package delayed or lost | Hold the key and open a carrier trace | Tracking history and last confirmed handover |
| Seal broken or serial mismatch | Do not release the key; quarantine the drive | Photos, recipient statement, carrier notes |
| Hash mismatch on arrival | Identify the affected files and resend them | Which files failed and the corrected manifest |
| Key sent to the wrong person | Re-encrypt with a new key and reship | Who received the key and when it was revoked |
Illustrative: a 3PL ships its warehouse history#
Illustrative: a fictional third-party logistics provider is licensing years of warehouse management system scan events, transportation management load records and proof-of-delivery photos. The photos alone make the package too large for a practical network transfer, so the parties agree on an encrypted drive.
The IT lead copies the approved release from the prepared package onto a new hardware-encrypted drive, generates a hash manifest and seals the drive in a numbered bag with the operations manager as witness. A tracked, signature-required courier carries it to a named recipient.
The recipient photographs the unopened bag and confirms the serial in writing, and only then does the IT lead release the key through a password manager share. Every hash matches, the receipt is signed and, under the license, the drive is destroyed at the end of the project against a certificate that closes the log.
How SourceX handles drive deliveries#
SourceX never hosts multi-terabyte datasets. Large packages either remain in storage the supplier controls or travel on encrypted drives like the one described here, and the handover is recorded as part of Delivery, the last stage of the SourceX five-step transaction, after the supplier's Approval.
The custody record is filed with the SourceX Evidence Packet for the same package. Because the packet already holds the release authorization, along with provenance, licensing rights, permitted use and the privacy record, the sign-off and the physical handover can be traced to each other.
Frequently asked questions
Should we use hardware or software encryption?
Either can work. Hardware-encrypted drives keep the key off the host computer and are simple for recipients to use, while software encryption on a standard drive is flexible and easy to inspect. Choose what the recipient can open in their environment, and record the method and drive model in the custody log.
Is a regular parcel service acceptable?
A tracked service with signature on delivery is commonly used for encrypted drives, because the encryption protects the contents if the package goes astray. For higher-risk packages, some companies use a courier offering chain-of-custody handling or send a named employee. Match the method to the harm a loss would cause.
Do we still need encryption if the data is de-identified?
Yes. De-identification lowers privacy risk, but the package can still hold confidential business information, such as pricing patterns, vendor terms or process detail, licensed to one recipient only. An unencrypted drive also cannot show that nobody read it in transit, which weakens the whole custody record.
What changes when the drive goes to another country?
International shipment adds customs inspection, possible cross-border data transfer rules and, in some countries, rules on importing encryption products. Check with counsel before shipping abroad, keep the key out of the package as always, and confirm the license allows the destination.
Who should destroy the drive at the end?
The license should say. Some suppliers prefer the drive back so they can sanitize it themselves; others accept destruction by the recipient against a signed certificate naming the drive serial, method and date. Media sanitization guidelines such as NIST SP 800-88 are a common reference for the method.
Related resources
See if your company qualifies
A short company assessment. No data uploads are needed.