
A penetration test report is a working set of instructions for compromising your business, complete with screenshots and the requests that proved each finding. It deserves the same handling as your most sensitive commercial documents, and buyers rarely ask where it will be stored or how long the supplier keeps it. Those questions belong in the procurement conversation, not the post-incident one.
What the evidence actually contains
More than the report. During an engagement a tester accumulates screenshots, captured requests and responses, extracted configuration files, password hashes and sometimes sample records proving that data was reachable. Where an application holds customer information, that evidence may contain personal data, which makes the supplier a processor under UK GDPR with the obligations the Information Commissioner’s Office expects of one. Ask what is collected, how it is stored during the engagement, and whether anything is retained afterwards beyond the report itself. Ask too whether evidence is encrypted at rest on the consultant’s own machine, since that is where it lives while the work is running.
Delivery and storage
Reports should arrive through a portal with authentication, not as an email attachment, and certainly not through a general file sharing link that anyone with the address can open. Ask where the supplier stores the report and evidence, in which country, and who inside their business can read it. Check whether subcontractors or offshore staff are involved, since that changes both your data protection analysis and your risk. A supplier who has thought about this will answer immediately, and one who has not will offer reassurance instead of detail.
“Ask any supplier how long they keep your report and evidence, and what happens at the end of that period. The good answer is a defined retention with secure destruction and confirmation on request. I have seen reports from six years ago sitting in a shared drive at a supplier the client stopped using in 2020, still perfectly accurate about a network that had barely changed.”
William Fieldhouse, Director, Aardwolf Security Ltd

Your own handling once it arrives
The report usually gets less careful treatment inside the client than at the supplier. It is forwarded to developers, attached to a ticket, pasted into a chat channel and stored on a shared drive where the whole IT department can read it. Decide who needs the full technical detail and give everyone else the summary. Store it somewhere with access control and a review date, and remember that an attacker inside your network who finds it has just been handed a map with the exploitation steps written out. Old reports should be archived rather than left on a drive people browse.
Sharing it with customers
Customers increasingly ask for evidence of testing, and sending the full report is rarely the right answer. An attestation letter confirming scope, dates and that findings were remediated satisfies most requests. Where a customer insists on detail, a redacted summary under a non-disclosure agreement is the sensible middle. Askpenetration testing supplierswhether they produce these formats as part of the engagement, and when youtalk to us about a penetration testing quote, mention any customer assurance requirements so the deliverables are agreed at the start.
Frequently asked questions about report handling
These questions come up when procurement reviews a testing agreement.
Should the supplier delete everything afterwards?
Not immediately. They need the report for the retest and often for professional indemnity reasons. Agree a period, usually twelve to twenty-four months, then secure destruction with written confirmation.
Can you require UK-only storage?
Yes, and many suppliers offer it as standard. Put it in the contract rather than assuming, particularly where the tested systems hold personal data or the work falls under a public sector framework.




