Remote wipe: erasing a lost or stolen device
Wipe a device from the portal when it's gone — cryptographic erase in seconds on encrypted disks.
- 1Available on Growth plans and above, to the workspace owner and EPP admins, from the individual device page — never the device table.
- 2Open Endpoint Protection → Devices → the device → Remote wipe (lost or stolen device). Type the device's exact hostname to confirm; the button stays disabled until it matches.
- 3Cybermatic isolates the device first (cutting off any live session and guaranteeing the result reaches you), then erases it. On an encrypted disk (BitLocker, LUKS, FileVault) it destroys the keys — the data is unrecoverable in seconds. On an unencrypted disk it runs a best-effort wipe and warns you that fragments could be recovered from a removed drive.
- 4Servers are detected automatically and require a second confirmation plus a 60-second cancel window shown on the page, because wiping a server can destroy the only copy of business-critical data.
- 5macOS: user data is destroyed and FileVault is disabled (encrypted data becomes unreadable). A full factory erase on macOS requires MDM and is not performed.
- 6Every wipe is recorded in the immutable response audit — who requested it, when, and the result — like every other response action. A wipe cannot be undone.
Tip: Remote wipe is for lost or stolen hardware. To retire a device you still hold, un-protect it and wipe it locally.