← DF Sentinel/Write-Blocking
DF Sentinel · DF Sentinel Guard — Write-Blocking, Honestly Explained

Is this a hardware write blocker? No — and here's exactly what that means.

DF Sentinel Guard is the write-protection engine running underneath every case. It's software-based: enforced at the driver level, armed by default on every connected device, and verified by actually attempting a write and watching it get refused — not just assumed. We'd rather tell you that precisely than round it up to something it isn't.

A tool that tells you what it couldn't do is more trustworthy than one that claims it can do everything.

Blocked by default, per device Verified by a real write attempt Device-identity bound, not drive-letter bound
DF Sentinel Device Safety screen showing every connected device write-blocked automatically the moment it appears
Device Safety — every connected device, its protection state, and a Test Block button for each.
Lead With The Answer, Not A Sales Pitch

Software write-blocking, verified by attempt.

Most forensic and preservation software is built to sound confident. DF Sentinel is built to be accurate, even when that's a less flattering thing to say. Write protection here is enforced in software, at the driver level — every external device is write-blocked automatically the moment it's detected, and writing is a deliberate exception an operator opts into per device, not something you have to remember to switch on.

That's a different, more precise claim than "hardware write blocker" — and a deliberately honest one. We'll never call this "guaranteed," "impossible to write," or dress it up as hardware-grade protection it isn't. If a physical write did somehow reach the device, that would be a failure worth knowing about, not something a marketing claim should paper over.

Block By Default

Protection is the default state, not a setting to remember.

While armed, every external device is write-blocked automatically the instant it appears — new arrivals included, without the operator having to act first. Writing to a device is the exception, opted into per device, not the default you have to think to switch off.

Hot-plug aware — devices are rescanned continuously, and new arrivals auto-block on connection
Covers card readers too — including built-in laptop SD/MMC readers, not just USB drives
In-use protection — a device being imaged or browsed can't be unblocked or interfered with, even from elsewhere in the app
Test Block

Proof, not trust.

On your command, the software attempts a real write to the device and shows you the operating system refusing it — demonstrating the block actually holds, in that moment, rather than asking you to assume it does. It's the difference between a status label that says "Blocked" and watching a write get rejected in front of you.

The Failure Mode Most Tools Don't Think About

A swapped device never inherits another device's permissions.

Windows drive letters get reassigned — unplug one device and plug in another, and it can silently land on the same letter the first device used. Protection state here is bound to the device's own identity, verified by a content fingerprint even when a device reports no serial number, not to a drive letter that can quietly point somewhere else. A different disk of the same make and size doesn't get waved through on the strength of a familiar-looking path.

An Honest Comparison

Software vs hardware write blockers.

Two genuinely different tools, each with a real trade-off. Here's both sides, plainly.

Hardware write blockers

Physical-layer certainty

A dedicated device sits between the drive and your machine, physically preventing write commands at the interface level. The categorically stronger guarantee if your institution has a hard requirement for it — but it means buying, carrying and maintaining separate hardware for every interface type (SATA, IDE, USB), and one more physical step in every acquisition.

DF Sentinel's software write-blocking

Verified, not assumed

Write commands are intercepted at the driver level before they reach the device, armed by default, and provable on demand via Test Block — no separate hardware to buy or carry. The honest trade-off: it doesn't foreclose a low-level bypass the way a physical blocker does, which is exactly why we call it software protection and nothing more.

One exception worth knowing: DF Sentinel's floppy disk imaging path is read-only by physics — it issues no write commands to the disk at all, which is a stronger claim than software write-blocking and one we make precisely because it's true for that specific pathway, not as a blanket claim across every device type.

Self-Protecting

Your own machine is never at risk.

The machine's own system disk and DF Sentinel's working folder are never blocked and never appear as imaging targets — enforced automatically, not left to the operator to remember to exclude.

Frequently Asked Questions

Questions about write-blocking, specifically.

Is DF Sentinel a hardware write blocker?
No. Write protection is software-based — enforced at the driver level and verified by attempt, not by a physical device sitting between the drive and your machine. We say this plainly because a tool that tells you what it couldn't do is more trustworthy than one that claims it can do everything.
How do I know the write-block is actually working, not just claimed?
Test Block. On your command, the software attempts a real write to the device and shows you the operating system refusing it — proof captured in the moment, not a claim to take on faith.
What stops a swapped device from inheriting another device's permissions?
Device-identity binding. Protection state is tied to the device's own identity, verified by a content fingerprint even when a device reports no serial number — not to a drive letter, which Windows can and does reassign.
Can the system disk accidentally get blocked or imaged?
No — the machine's own system disk and DF Sentinel's working folder are never imaging targets and never appear in the block list. This is enforced automatically, not left to the operator to remember.
Does this work for SD cards from a built-in laptop reader, not just USB?
Yes. Built-in card readers are recognised as removable media and protected the same way as any external USB device.
Should we use a hardware write blocker instead?
If your institution has a hard requirement for physical-layer certainty, a hardware write blocker is the categorically stronger guarantee, full stop — and we'd rather tell you that than pretend otherwise. DF Sentinel's software approach is built for institutions where a verified software block, backed by live proof rather than a claim, is the right trade-off against not needing to buy, carry and maintain separate hardware for every interface type.
Part Of DF Sentinel

More from DF Sentinel.

Questions about how this applies to your collection?

Talk to us — we'll give you a straight answer.

If physical-layer certainty is a hard requirement for your institution, we'll tell you that honestly too. Tell us what you're working with and we'll help you figure out the right fit.

No newsletters, no mailing lists, no marketing follow-up — whichever way you get in touch.