GetPentest

What to send when a customer asks to see your pentest

Almost nobody who asks to see your penetration test needs the report. They need proof that a test happened, that it was independent, and that the serious findings are closed. Those are three different documents and only one of them is dangerous to send.

Last reviewed 2026-08-31Written by Jacob Masse, TrazTech Inc.

Send the attestation letter. In almost every case where a customer, a prospect or an insurer asks to see your penetration test, a one-page letter from the testing firm naming the date, the scope, the methodology and the remediation status is the correct answer, and the full report is not. The report describes how to attack your product, including anything you have not fixed yet. It should leave your company only under a signed agreement, and only when somebody has read the request closely enough to know why nothing else will do.

1 page Attestation letter, what most requests actually need

30 to 80 pages Full report, including reproduction steps

$0 to $750 CAD, typical charge for a letter if not included

The four documents, and what each one gives away

Attestation letter, sometimes called a summary letter
One page on the testing firm's letterhead. Names the client, the dates, the scope in general terms, the methodology followed, the count of findings by severity, and whether they have been remediated and retested. Contains no reproduction steps and no system detail. Safe to send to a prospect, an insurer or a procurement team without negotiation.
Executive summary
The first two to four pages of the report, usually including the severity chart and the narrative of what the tester concluded. Safe enough for most enterprise reviewers, though it names systems and sometimes describes the class of issue found, which a determined reader can work with.
Redacted report
The full report with reproduction steps, payloads, hostnames and screenshots removed. Real work to produce, and the redaction has to be done by somebody who understands what a screenshot reveals. Reasonable where a large customer's security team genuinely reviews findings rather than filing them.
Full report
Everything, including how to reproduce each finding. This is an internal document. Share it under a non-disclosure agreement, with a named recipient, and only where the recipient's own obligations require it, which in practice means a regulator, an auditor, or a customer whose contract says so in words.

Work out which one to send

  1. Read what they actually wrote. "Do you perform annual penetration testing" is a questionnaire line and is answered by a letter. "Please provide your most recent penetration test report" is a request from a template and is usually still answered by a letter plus an offer.
  2. Ask who is going to read it. A procurement analyst working through a checklist needs a date and a firm name. A security engineer at an enterprise customer may genuinely read findings, and for them a redacted report under an agreement is a better relationship than a fight.
  3. Check whether anything is still open. If high findings are unfixed, send the letter and say when the retest is booked. Sending a document listing your open holes to a company you have not signed with is the failure mode.
  4. Check the contract you already signed. Some enterprise agreements commit you to providing test results on request, and a few name the report specifically. If yours does, the negotiation happened at signature and the answer is to comply in the narrowest form the clause allows.
  5. If they insist on the full report, offer three things in order: the letter, then the executive summary, then a redacted report under a mutual agreement with a named recipient. Most requests stop at the first or second offer, because the person asking has a box to tick.
  6. Where a report keeps being demanded by many customers, that is the signal to buy the framework report instead. A SOC 2 report exists precisely so a company can answer this question once.
What to send, by who is asking
Who is askingSendWhy
A prospect in a sales cycle Attestation letter They have a checklist. Nothing is signed. No detail should leave
A signed enterprise customer's security team Executive summary, redacted report if pressed They review findings, and there is a contract behind them
A cyber insurance broker or underwriter Attestation letter They are confirming testing happens, not reading findings
Your SOC 2 or ISO 27001 auditor Full report, plus the remediation trail They are bound by professional obligations and need the detail
A QSA assessing a card environment Full report, plus segmentation test results PCI DSS is prescriptive about what has to be evidenced
An acquirer doing technical diligence Redacted report under the diligence agreement They are pricing risk and will ask harder questions if refused
A public sector buyer Whatever the solicitation names The terms are set in the bid documents, not by you

Comparing firms for this? Tell us what you need and it goes to the ones in the directory that do this work. No charge, and no phone number required.

What a usable attestation letter contains

Letters vary in quality, and a thin one causes the second round of questions you were trying to avoid. Ask the firm for these seven things by name, at scoping rather than after the report. A letter written months later costs money.

  • The legal name of the tested company and the legal name of the testing firm, on letterhead, signed by a named person with a role.
  • The testing dates, start and end, not just a month.
  • The scope described in general terms: the production web application and its API, the external perimeter, the corporate network. Not hostnames.
  • The methodology by name, such as the OWASP testing guide, PTES, or NIST SP 800-115.
  • The count of findings by severity, and nothing about what they were.
  • The remediation status as at the letter date, ideally referencing a retest and its date.
  • A statement that the letter is a summary and that no findings detail is included, which pre-empts the follow-up question.

Ask for it in the original quote

Some firms include an attestation letter as standard, some charge $250 to $750 CAD for it, and a few do not offer one at all, which tells you something about who their clients are. Add it to the list of things you ask for before signing, alongside the retest window and the tester day count. The full list of what to ask a firm is on choosing a Canadian testing firm.

The Canadian angle nobody raises

A penetration test report often contains personal information. Screenshots proving an authorisation flaw usually show a real record, and the record usually belongs to a real person. Once that is true, the report is not merely commercially sensitive. It holds personal information you are accountable for under PIPEDA, or under Law 25 in Quebec and PIPA in British Columbia and Alberta.

Two consequences. Ask the testing firm to mask personal information in evidence before the report is issued, which good firms do unasked. And do not forward the report casually: sending it to a prospect discloses that information to a third party with no reason to receive it. The transfer rules are covered on PIPEDA compliance.

How old is too old

A report is treated as current for twelve months by most buyers, which is where the annual testing convention comes from rather than from any standard. Two things age it faster. A significant change to the tested system, since the report describes software that no longer exists, and PCI DSS says so explicitly. And an open high finding, because a report showing unremediated high severity issues is worse than no report from the day it is written.

If a customer asks for a test newer than yours and the scope has not changed materially, offer the letter with the retest date on it and say when the next test is booked. That answer is accepted far more often than buying a test out of cycle. What one costs out of cycle is on penetration testing cost in Canada.

Get a firm that issues a letter you can actually send

Tell us the scope and that you need an attestation letter and a retest, and the request goes to Canadian firms that provide both.

Get matched

Common questions

Can I refuse to send my penetration test report?

Yes, unless a contract you signed says otherwise. Refusing outright reads badly, so refuse by substitution rather than by silence: offer the attestation letter immediately, explain in one sentence that the full report contains reproduction detail, and offer a redacted version under an agreement if their review requires findings. That sequence almost never escalates.

What is an attestation letter for a penetration test?

A one-page statement from the testing firm confirming that a test was performed, when, over what scope, using which methodology, and what the remediation status is. It is the document designed to be shared outside the company. It is not an audit opinion and it carries no assurance about controls, which is the difference between it and a SOC 2 report.

A customer says the letter is not enough. What now?

Ask what specifically they need to see and why, because the answer is often a single questionnaire field their tooling requires. If they genuinely review findings, offer the executive summary first and a redacted report under a mutual non-disclosure agreement second, with a named recipient and no onward sharing. Put the offer in writing so the file shows you cooperated.

Should the letter say we passed?

No, and a firm offering to write that is a firm to walk away from. There is no pass or fail in penetration testing. Every test finds something, and a letter claiming a clean result invites a reader to ask why your test found nothing when everyone else's found eleven things. What the letter should say is the count by severity and the remediation status.

Do we need a separate letter for each customer?

No. One letter, addressed to whom it may concern, dated, covering the engagement, is the normal form and can be sent to everyone who asks during the year. Request a fresh one after a retest closes the high findings, because that version answers the follow-up question before it is asked.