macOS: honest erase paths
HexaSeal does not claim third-party NAND sanitize of Apple silicon internal SSDs. Certificates state the real scope.
What we support
- Inventory via
diskutil/ agentmacos-inventory - External / removable volumes:
diskutil secureEraseoreraseDiskwhen--allow-destructiveis set - Internal boot disk: operator uses Apple Erase All Content and Settings or Recovery; HexaSeal can record the job + certificate metadata after operator attestation
Agent
hexaseal-agent macos-inventory hexaseal-agent --simulate=false --allow-destructive simulate --method nist_clear