Think Build Implement Repeat
London, UK +44 7367 067226
WhatsApp FOLLOW f in X
  1. Home
  2. Blog
  3. How Does a Penetration Testing Firm Deliver Reports to Clients Without Password-Protected Zips and Passwords by Text Message?
Problems We Solve

How Does a Penetration Testing Firm Deliver Reports to Clients Without Password-Protected Zips and Passwords by Text Message?

Pen test reports go out as zip files with passwords sent separately, then forwarded anywhere. We build a report delivery portal with access control and logs.

Updated 3 min readBy SpiderHunts Technologies

Free estimateNo obligation

Get a free estimate

Tell us what you need. A senior engineer reads every enquiry.

Takes under a minute. We never share your details.

  • Free consultation
  • No commitment
  • NDA on request

Prefer to talk? Book a free 30-minute call →

Quick answer — TL;DR

Report delivery is awkward because the report is sensitive, the client wants it quickly, and the usual method (an encrypted file by email and a password by another channel) is clumsy and leaves you with no idea who has it. We build a delivery portal where named client contacts sign in to download reports, access expires when you choose, every download is recorded, and the same place holds retest reports and remediation status.

Release day

The report has passed QA. It is time to send it. Your operations coordinator exports the PDF, puts it in an encrypted archive, emails it to the client's contact and texts them the password. The client contact is on leave, so their colleague asks for it to be resent. The coordinator resends it, and texts the password to a new number they have been given by email.

A month later the client's managing director asks for a copy. Then their developer does. Then an external auditor. Each time, someone at your firm has to decide whether the person asking should have it, find the file, and go through the process again. Some clients simply forward the original email and password around their business.

Nobody at your firm could say, if asked, who has a copy of any given report.

Report delivery is the moment your client gets what they paid for. It is odd that it is also the least organised step in the whole engagement.

Why delivery is clumsy

  • Email is the only channel everyone has, but it is not where you want a sensitive report to live.
  • Password-by-another-channel depends on having a verified phone number for the right person.
  • Requests for copies come from people you have not dealt with, and deciding who is entitled is left to whoever answers.
  • Once a file is sent, it can be forwarded without any record.
  • Reports, retest reports and certificates for the same client are sent separately, over time, and scattered.

What the current method costs

ProblemEffect
Resending reports and passwordsCoordinator time on every engagement
No list of authorised recipientsJudgement calls about who gets a copy
No record of accessCannot say who has the report
Clients forward the emailReport travels further than intended
Documents scattered over timeClient asks for 'everything from last year'

Handling client reports carefully is part of what clients pay a security firm for. A delivery method that relies on text messages and forwarding does not reflect the care that went into the testing.

The delivery portal we build

  1. Each client has a list of named contacts who may receive reports, confirmed by the client's lead contact, who can add or remove people.
  2. Released reports are placed in the portal, and authorised contacts receive a notification that a document is ready. The report itself never travels by email.
  3. Contacts sign in with multi-factor authentication to view or download. You can choose whether a report can be downloaded or only viewed, and whether downloaded copies carry the recipient's name as a watermark.
  4. Access expires after a period you set, and can be extended by your team on request.
  5. Every view and download is recorded with the person and the time.
  6. The same portal holds retest reports, certificates, and, if you use one, the remediation tracker for that engagement, so the client has one place for everything.

We build it on your domain and your branding, using a secure file storage service such as Azure Blob Storage or Amazon S3 behind it, with access and retention designed with you.

What delivery looks like afterwards

Releasing a report is one step. Requests for copies are handled by pointing people to the portal, where the client's own lead decides who is on the list. Your firm can say exactly who has accessed a report and when. And the client finds last year's report, retest and certificate in one place when their auditor asks.

Consider the auditor request again. Instead of a new round of zip files and text messages, the client's lead adds the auditor as a contact with view-only access that expires in a month. The auditor signs in, reads the reports, and the record shows they did. Nobody at your firm had to be involved at all.

Is this how you deliver reports?

  • Reports go out as encrypted zips with passwords sent separately.
  • Your team resends reports and passwords regularly.
  • Nobody decides consistently who may receive a copy.
  • You cannot say who has accessed a report.
  • Clients ask you to resend old reports for auditors.

FAQ

Frequently asked questions

The questions readers ask us after this guide.

Still have a question?

Ask us directly — a senior engineer will get back to you.

Ask about your project

Will clients find a portal harder than email?

Most find it easier, because they get a notification and sign in once, rather than handling files and passwords.

Can clients still download reports?

Yes, if you allow it. You can also choose view-only, or watermarked downloads.

Where are reports stored?

In storage within an environment you control, with access and retention policies agreed with you.

Can it link to our reporting platform?

Yes. Released reports can be published to the portal automatically from your reporting platform where it has an API.

Keep reading

More on Problems We Solve

Start here

Tell us where the admin slows your security practice down

Describe how engagements run today, from scoping call to final report and retest: the reporting tool, the calendars, the trackers and the email threads. We will tell you what we would build and what we would leave alone, and if your existing tools can already do it, we will say so.

  1. You tell us what you needTwo minutes on the form, or a message on WhatsApp.
  2. A senior engineer reviews itAnd comes back with questions, a realistic range and an honest view on fit.
  3. Free 30-minute scoping callWe talk through scope, options and a realistic estimate — with no obligation.
Free estimateNo obligation

Talk to someone who builds this

Send a short brief and we will come back with an honest view and a realistic range.

Takes under a minute. We never share your details.

  • Free consultation
  • No commitment
  • NDA on request

Prefer to talk? Book a free 30-minute call →