How Long Should a Testing Firm Keep Client Findings?
Evidence, screenshots, credentials and reports accumulate for years by default. What the obligations actually say, what clients are starting to require, and how to set a retention position you can defend.
Ask a testing firm how long they keep client findings and the honest answer is usually "we have never deleted any". Not from negligence, but because nothing forces the decision. Storage is cheap, deletion is irreversible, and there is always a reason it might be needed later.
That default is becoming difficult to defend. Clients ask about retention in supplier assessments, insurers ask in questionnaires, and the aggregate over several years is a remarkable concentration of other organisations’ weaknesses sitting in one place with no expiry.
What You Are Actually Holding
Worth enumerating, because "reports" undersells it considerably.
- Findings, including ones the client never remediated.
- Screenshots showing live systems, sometimes with real data visible.
- Reproduction steps that work, or worked recently.
- Access credentials the client issued for testing, which are occasionally still valid years later.
- Network diagrams, asset inventories and scoping documents.
- Correspondence naming individuals on both sides.
A five-year archive across forty clients is a genuinely attractive target, and it is one you assembled by not making a decision.
Testing credentials. They were meant to be revoked on the end date, they frequently were not, and they are sitting in your archive attached to a document that says exactly what they open.
What the Obligations Actually Say
Less than people assume, and in different directions depending on the material.
| Material | What drives the period | Typical defensible answer |
|---|---|---|
| Financial records of the engagement | Tax law, which is specific | Six years in the UK, and not negotiable |
| The report and attestation | Client need and contractual terms | Two to three years, often longer by agreement |
| Evidence and screenshots | Data minimisation, and your own risk | Twelve to twenty-four months, unless a retest is expected |
| Testing credentials | Nothing justifies keeping these | Destroyed at the end of the engagement |
| Personal data within evidence | Data protection law, which requires a purpose | Redacted at capture, so the question does not arise |
The pattern is that the deliverable and the evidence behind it have different half-lives. Most firms keep them together and apply the longest period to everything, which is the expensive choice in both storage and risk.
Setting a Position You Can Defend
- Split the categories. Financial, deliverable, evidence, credentials. Four periods, not one.
- Write the periods down with the reason attached. A period without a rationale gets argued with; a period with one rarely does.
- Put it in the engagement letter. Retention agreed up front is a selling point. Retention raised later is a negotiation.
- Redact at capture. The cheapest way to answer a question about personal data in evidence is not to have captured it.
- Handle credentials on the end date. Confirm revocation with the client, in writing, as part of closing the engagement.
- Diarise the deletions. A policy nobody executes is worse than no policy, because you have now documented what you failed to do.
A retention policy you do not execute is a written record of a control you do not operate.
The Question That Follows Immediately
Clients who ask about retention almost always ask a second question: can you delete our data if we ask? It is worth knowing your own answer before it is put to you.
The answer depends less on policy than on where the data physically is. If findings live in a platform somebody else administers, deletion means asking a vendor and trusting the confirmation. If they live in a database in your own cloud account, deletion is something you perform and can evidence.
Your engagement data lives in a Postgres project in your own cloud account, so retention is a decision you take and execute rather than a request you submit. Nothing is held on Pental’s side to be forgotten: the inventory there is your account email, your subscription state and your domain routing. Ending your subscription ends your licence to the software and does not touch the database, because it was never in our custody in the first place.
A Position Worth Publishing
- Four categories with four periods, each with a stated reason.
- Testing credentials destroyed at the end of the engagement, confirmed with the client.
- Evidence redacted at capture rather than reviewed later.
- Deletion scheduled and actually performed, with a record.
- A one-paragraph answer to "can you delete our data" that describes a mechanism.
Firms that get here find the same thing: it stops being a compliance chore and becomes something to say in a pitch. Being able to tell a prospect exactly how long you will hold their weaknesses, and what happens at the end, is a better answer than most of their existing suppliers can give.
Pental Is Built by the People Writing This
Engagement management for testing firms, on a database you own, under your brand, with the AI running on your key.