You hold the most sensitive thing your client owns
During an engagement a testing firm holds working credentials, live customer data and a written list of the fastest ways in. Practical handling rules for all of it, including the laptop.
During an engagement a testing firm holds working credentials, network diagrams, screenshots of live customer data, and a written list of the fastest ways into the business. Very few of a client's suppliers hold a comparable concentration of risk, and clients have started noticing.
None of what follows is novel. It is the discipline you are paid to assess, applied to yourself, which is a harder sell internally than it should be.
Credentials with an expiry from the moment they are issued
Ask for accounts created for the engagement rather than existing accounts shared with you, and ask for them to be disabled on the end date rather than at some later tidy-up that never happens.
Where a client insists on sharing an existing account, note it in the report. It is a finding about their process even when it never becomes one about their systems, and writing it down protects both of you if that account is later implicated in something.
Chat threads, spreadsheets on a shared drive, the body of an email, and a tester's local notes file. All four survive the engagement by default. Keep engagement credentials in one place that expires them, and if your tooling cannot do that, a shared vault scoped to the engagement is the minimum.
Do not let evidence live in two places
The common failure is not dramatic. It is a screenshot folder on a tester's desktop, a copy pasted into a channel so a colleague could look at it, and a third in a report draft, one of which never gets cleaned up.
Attach evidence to the engagement record once, and remove the local copy when the finding is written. The rule is easy to state and it only works if the primary location is genuinely convenient, which is worth spending money on.
Redact at capture time
Redacting later means holding the unredacted version in the meantime, and the unredacted version is the one that ends up in the archive. Capture the smallest region that proves the point. Where a demonstration genuinely needs real customer data, capture one record rather than a page of them, and say in the finding that you did so deliberately.
Redaction that is actually redaction
Black boxes drawn in an image editor and flattened are fine. Black boxes drawn over live text in a document that keeps the text underneath are not, and neither is blurring, which has been reversed often enough to be a bad idea. Flatten the image, then check the flattened file.
Tool output is evidence, not scratch
Scanner output, proxy history and traffic captures are frequently more sensitive than the report, because they are complete rather than curated. A proxy log from an authenticated session routinely contains session tokens, personal data and internal hostnames in one file that nobody has read end to end.
It deserves the same storage, the same access control and the same disposal date as everything else, and it should never be attached to an email.
Have a disposal rule that actually runs
- Decide the period. How long you hold evidence after delivery, written into the engagement contract rather than assumed.
- Attach deletion to closing. Make it a step in closing an engagement, not an annual cleanup that gets deferred every year.
- Separate report retention from evidence retention. Professional obligations usually require the report for longer than the evidence needs to exist.
- Know what a client can demand. And be able to do it without a week of archaeology across three storage systems.
The laptop is in scope
Full disk encryption, a screen lock measured in minutes, no shared local accounts, no personal machines, and a plan for a stolen device that does not begin with "we would tell the client and hope".
A supplier assessment will ask about all of this. Being able to answer without qualification is worth more in procurement than most certification logos, and it costs a weekend to get right.
Assume you will be assessed
The firms winning larger accounts are the ones that can describe their own handling as precisely as they describe their clients' weaknesses.
Write it down once, keep it true, and the questionnaire stops being a week of work every time one lands. Keeping it true is the hard part, and it is the part that makes the document worth anything.
Where the evidence actually lives
Most of the discipline above is about handling. The question underneath it is custody: whose infrastructure holds the material, and who could read it if they wanted to.
For a testing firm this is not an abstract question, because it is the one your clients are increasingly asking you. Three answers exist and they are not equivalent.
| Arrangement | Who could read a finding |
|---|---|
| A shared platform holding every customer in one database | Your staff, plus the vendor's staff, plus anyone who gets a tenant filter wrong. |
| Files on your own drives and a folder structure | Your staff, subject to whatever your file permissions actually are rather than what you think they are. |
| A database in your own account, with access decided by the database | Your staff, under rules enforced on every query rather than by the application remembering to ask. |
Whichever you run, be able to describe it precisely. The firms that answer supplier assessments quickly are the ones whose answer is a mechanism rather than an intention.
Every firm runs on its own Postgres project, in its own account, in a region it picks, with access decided by row-level security policies evaluated by Postgres on every query. Evidence and files sit inside that database with no storage tier to outgrow, and Pental holds no copy of any of it.
Pental Is Built by the People Writing This
Engagement management for testing firms, on a database you own, under your brand, with the AI running on your key.
Related reading
Setup guide
See the product set up, end to end
The whole setup in 8:15, with chapters you can jump to: registering, your own domain, your own database, your own mail server, branding, the first sign-in, and keeping the database updated.
- 0:00 · Registering, signing in, and the free trial
- 0:51 · Your name and your firm’s name
- 0:57 · Custom domain
- +5 more