Security

How Long Should a Testing Firm Keep Client Findings?

Evidence, screenshots, credentials and reports accumulate for years by default. What the obligations actually say, what clients are starting to require, and how to set a retention position you can defend.

Pental11 min read

Ask a testing firm how long they keep client findings and the honest answer is usually "we have never deleted any". Not from negligence, but because nothing forces the decision. Storage is cheap, deletion is irreversible, and there is always a reason it might be needed later.

That default is becoming difficult to defend. Clients ask about retention in supplier assessments, insurers ask in questionnaires, and the aggregate over several years is a remarkable concentration of other organisations’ weaknesses sitting in one place with no expiry.

What You Are Actually Holding

Worth enumerating, because "reports" undersells it considerably.

  • Findings, including ones the client never remediated.
  • Screenshots showing live systems, sometimes with real data visible.
  • Reproduction steps that work, or worked recently.
  • Access credentials the client issued for testing, which are occasionally still valid years later.
  • Network diagrams, asset inventories and scoping documents.
  • Correspondence naming individuals on both sides.

A five-year archive across forty clients is a genuinely attractive target, and it is one you assembled by not making a decision.

Testing credentials. They were meant to be revoked on the end date, they frequently were not, and they are sitting in your archive attached to a document that says exactly what they open.

What the Obligations Actually Say

Less than people assume, and in different directions depending on the material.

MaterialWhat drives the periodTypical defensible answer
Financial records of the engagementTax law, which is specificSix years in the UK, and not negotiable
The report and attestationClient need and contractual termsTwo to three years, often longer by agreement
Evidence and screenshotsData minimisation, and your own riskTwelve to twenty-four months, unless a retest is expected
Testing credentialsNothing justifies keeping theseDestroyed at the end of the engagement
Personal data within evidenceData protection law, which requires a purposeRedacted at capture, so the question does not arise

The pattern is that the deliverable and the evidence behind it have different half-lives. Most firms keep them together and apply the longest period to everything, which is the expensive choice in both storage and risk.

Setting a Position You Can Defend

  1. Split the categories. Financial, deliverable, evidence, credentials. Four periods, not one.
  2. Write the periods down with the reason attached. A period without a rationale gets argued with; a period with one rarely does.
  3. Put it in the engagement letter. Retention agreed up front is a selling point. Retention raised later is a negotiation.
  4. Redact at capture. The cheapest way to answer a question about personal data in evidence is not to have captured it.
  5. Handle credentials on the end date. Confirm revocation with the client, in writing, as part of closing the engagement.
  6. Diarise the deletions. A policy nobody executes is worse than no policy, because you have now documented what you failed to do.

A retention policy you do not execute is a written record of a control you do not operate.

The Question That Follows Immediately

Clients who ask about retention almost always ask a second question: can you delete our data if we ask? It is worth knowing your own answer before it is put to you.

The answer depends less on policy than on where the data physically is. If findings live in a platform somebody else administers, deletion means asking a vendor and trusting the confirmation. If they live in a database in your own cloud account, deletion is something you perform and can evidence.

Your engagement data lives in a Postgres project in your own cloud account, so retention is a decision you take and execute rather than a request you submit. Nothing is held on Pental’s side to be forgotten: the inventory there is your account email, your subscription state and your domain routing. Ending your subscription ends your licence to the software and does not touch the database, because it was never in our custody in the first place.

A Position Worth Publishing

  • Four categories with four periods, each with a stated reason.
  • Testing credentials destroyed at the end of the engagement, confirmed with the client.
  • Evidence redacted at capture rather than reviewed later.
  • Deletion scheduled and actually performed, with a record.
  • A one-paragraph answer to "can you delete our data" that describes a mechanism.

Firms that get here find the same thing: it stops being a compliance chore and becomes something to say in a pitch. Being able to tell a prospect exactly how long you will hold their weaknesses, and what happens at the end, is a better answer than most of their existing suppliers can give.


Pental Is Built by the People Writing This

Engagement management for testing firms, on a database you own, under your brand, with the AI running on your key.