Free Tool

Penetration Testing Credential Handover Form Template
open the credential lifecycle on the engagement record, not in chat

A free, copy-ready penetration testing credential handover form template. Ten structured sections covering header and engagement references, parties and signing authority, authentication models in scope (cookie, bearer, basic auth, form login, mTLS, API key, OAuth, SSH, VPN, AD/IAM), per-credential role tier and environment, named recipients on the testing party, storage method and access controls, the rotation plan at engagement close, the rotation log reference, framework and regulatory references (ISO 27001, SOC 2, PCI DSS, DORA, GDPR, HIPAA), and signature blocks. Pairs with the executed rules of engagement, engagement letter, and (at close) the closure letter and evidence destruction certificate so the credential lifecycle inherits the authorisation chain rather than restating it. Aligned with PTES, NIST SP 800-115, OWASP WSTG, and the CREST Defensible Penetration Test specification.

No credit card required. Free plan available forever.

Loading tool...

Run credential handover on the same record the engagement opened on

SecPortal stores the credential handover form alongside the engagement letter, SOW, ROE, findings, evidence pack, final report, debrief deck, attestation letter, closure letter, and rotation log. Credentials live in the encrypted vault with AES-256-GCM at rest. Free plan available.

No credit card required. Free plan available forever.