Is this a hardware write blocker? No — and here's exactly what that means.
DF Sentinel Guard is the write-protection engine running underneath every case. It's software-based: enforced at the driver level, armed by default on every connected device, and verified by actually attempting a write and watching it get refused — not just assumed. We'd rather tell you that precisely than round it up to something it isn't.
A tool that tells you what it couldn't do is more trustworthy than one that claims it can do everything.
Software write-blocking, verified by attempt.
Most forensic and preservation software is built to sound confident. DF Sentinel is built to be accurate, even when that's a less flattering thing to say. Write protection here is enforced in software, at the driver level — every external device is write-blocked automatically the moment it's detected, and writing is a deliberate exception an operator opts into per device, not something you have to remember to switch on.
That's a different, more precise claim than "hardware write blocker" — and a deliberately honest one. We'll never call this "guaranteed," "impossible to write," or dress it up as hardware-grade protection it isn't. If a physical write did somehow reach the device, that would be a failure worth knowing about, not something a marketing claim should paper over.
Protection is the default state, not a setting to remember.
While armed, every external device is write-blocked automatically the instant it appears — new arrivals included, without the operator having to act first. Writing to a device is the exception, opted into per device, not the default you have to think to switch off.
Proof, not trust.
On your command, the software attempts a real write to the device and shows you the operating system refusing it — demonstrating the block actually holds, in that moment, rather than asking you to assume it does. It's the difference between a status label that says "Blocked" and watching a write get rejected in front of you.
A swapped device never inherits another device's permissions.
Windows drive letters get reassigned — unplug one device and plug in another, and it can silently land on the same letter the first device used. Protection state here is bound to the device's own identity, verified by a content fingerprint even when a device reports no serial number, not to a drive letter that can quietly point somewhere else. A different disk of the same make and size doesn't get waved through on the strength of a familiar-looking path.
Software vs hardware write blockers.
Two genuinely different tools, each with a real trade-off. Here's both sides, plainly.
Physical-layer certainty
A dedicated device sits between the drive and your machine, physically preventing write commands at the interface level. The categorically stronger guarantee if your institution has a hard requirement for it — but it means buying, carrying and maintaining separate hardware for every interface type (SATA, IDE, USB), and one more physical step in every acquisition.
Verified, not assumed
Write commands are intercepted at the driver level before they reach the device, armed by default, and provable on demand via Test Block — no separate hardware to buy or carry. The honest trade-off: it doesn't foreclose a low-level bypass the way a physical blocker does, which is exactly why we call it software protection and nothing more.
One exception worth knowing: DF Sentinel's floppy disk imaging path is read-only by physics — it issues no write commands to the disk at all, which is a stronger claim than software write-blocking and one we make precisely because it's true for that specific pathway, not as a blanket claim across every device type.
Your own machine is never at risk.
The machine's own system disk and DF Sentinel's working folder are never blocked and never appear as imaging targets — enforced automatically, not left to the operator to remember to exclude.
Questions about write-blocking, specifically.
Is DF Sentinel a hardware write blocker?
How do I know the write-block is actually working, not just claimed?
What stops a swapped device from inheriting another device's permissions?
Can the system disk accidentally get blocked or imaged?
Does this work for SD cards from a built-in laptop reader, not just USB?
Should we use a hardware write blocker instead?
More from DF Sentinel.
DF Sentinel Overview
The full product — imaging, integrity validation, reporting and how we work with you.
Legacy MediaFloppy Disk Imaging
Flux-level capture, read-only by physics, built for a shelf of disks at once.
Digital PreservationBeyond Capture-Time Hashing
Ongoing fixity monitoring, PRONOM format ID, Dublin Core metadata and BagIt export.
Offline & Air-GappedNo Cloud, No Phone-Home
Runs identically on a permanently isolated workstation, including licensing.
ForensicsFor Labs & Legal Teams
Chain of custody, dual-hash imaging and resumable acquisition, explained honestly.
SpecificationsWhat You Need To Run It
Windows 10/11, file systems, deployment and licensing — plainly stated.
Sample ReportSee The Output
A verdict-first summary, with a full technical appendix underneath.
Talk to us — we'll give you a straight answer.
If physical-layer certainty is a hard requirement for your institution, we'll tell you that honestly too. Tell us what you're working with and we'll help you figure out the right fit.
No newsletters, no mailing lists, no marketing follow-up — whichever way you get in touch.