Who owns a penetration test report, and can the testing firm license it?
Client-specific penetration test findings are usually the client's confidential information, so a pentest firm generally cannot license its reports without consent. The firm may own its methodology, test plans, internal tooling documentation and anonymized taxonomies, subject to contract review with the company.
Can a penetration testing firm license its reports?
Not the client-specific ones, in most cases. A pentest report describes a named client's systems and weaknesses, and engagement letters typically treat it as the client's confidential information. What the firm may own is a separate layer: its methodology, test plans, internal tooling documentation and anonymized finding taxonomies.
So the honest answer to an owner who asks "do we own our reports?" is "probably not the reports, possibly the know-how behind them". Whether a given firm can license anything depends on its contracts, which SourceX reviews with the company. This is general information, not legal, tax or financial advice.
Two columns to use with the owner
Draw this on a call. It turns a vague worry about confidentiality into a sorting exercise.
| Likely the client's or confidential | Possibly the firm's, subject to contract review |
|---|---|
| Findings naming a client's hosts, applications or credentials | Internal methodology guides and testing playbooks |
| Executive summaries and risk ratings for a specific engagement | Reusable test plan templates and scoping questionnaires |
| Screenshots, proof-of-concept output and evidence files | Documentation for tools the firm built itself |
| Retest results and remediation correspondence | Anonymized finding taxonomies and severity rubrics |
| Scope documents and rules of engagement | Training material for junior testers |
The pentest contract's intellectual property and confidentiality clauses decide where an item falls. If the firm's reusable material is mixed with client data, the rights review decides what, if anything, can be separated.
What the contract clauses usually decide
Ask the owner for the master services agreement and a typical statement of work, then check four things:
- Deliverable ownership: does the client own the report on delivery, or only receive a license to use it?
- Confidentiality term: does it expire, and does it cover findings after anonymization?
- Residual knowledge: does the contract let the firm reuse general skills and techniques learned during the work?
- Firm-owned tooling: are scripts, payloads and methods carved out as the firm's background material?
A firm with a lawyer-reviewed template and consistent terms across clients is a far easier conversation than one with different informal terms for each account.
How to respond when an owner says the reports are all confidential
Acknowledge it first; the owner is right about client findings.
Then ask three questions: how long has the firm kept methodology and quality records, which systems hold them (wiki, ticketing, document repository), and who could export them. The company fit checker gives a preliminary, non-binding screen without contact details.
What if the concern is valid
Sometimes it is. Park the firm when any of these is true:
- The firm has under 50 full-time employees at peak, which is common for boutiques. The baseline on who qualifies is 50+ full-time employees at peak (contractors excluded).
- Its only substantial archive is client reports with no carve-outs.
- Government or regulated clients restrict all engagement material.
- Nobody can export the internal wiki or ticketing history.
- The owner will not consider an exclusive license.
Larger security and IT services groups are a different case. A managed security provider with several hundred staff and years of ticketing, runbooks and incident records may qualify, and the same client-versus-firm split applies. For comparison, see how the software agency code ownership question separates client deliverables from agency tooling, and the Phase I environmental report question for a consultant whose reports go to named users.
How the introduction works without touching findings
You make the introduction and give basic fit information only. You never receive, describe or upload any report.
- Register and share your referral link, or submit the firm through the referral form.
- SourceX qualifies size, history, data breadth and rights.
- The firm completes a data inventory by system, with years of history.
- Price and terms are agreed before buyers review anything.
- After a signed agreement and the firm's authorization, only agreed material is prepared and delivered.
How partner rewards work
Partners earn 25% of the eligible platform fees SourceX actually collects from the referred company's licensing deals, capped at $100,000 per referred company. The reward is paid only after the buyer pays and SourceX receives its fee; an introduction, meeting or signed agreement alone does not trigger payment, and no reward is guaranteed. Roll-up sponsors can screen several security add-ons using the buy-and-build sectors guide.
Next step
If you know a security firm with real scale and a clear split between client work and its own know-how, register as a partner and make the introduction. Confirm with your own counsel before advising any firm on contract rights.
- Step 1Share your linkSend your personal link to a company you know.
- Step 2Company appliesThe company applies itself at /apply.
- Step 3Buyer selects and paysThe buyer selects and pays for the data and SourceX receives its fee.
- Step 4You get your rewardYour share of SourceX fees becomes payable.
Common questions
Who owns a penetration test report by default?
There is no universal default. Most engagement letters make the report the client's confidential information, and many assign ownership to the client on delivery. The firm's rights depend on the intellectual property and confidentiality clauses in its own contract, so read those rather than assume.
Can a pentest firm reuse findings in anonymized form?
Only if its contracts allow it. Some agreements permit anonymized, aggregated insights while others forbid any use of engagement material. Even where allowed, anonymization has to be effective, so the firm should have counsel review before any use or license.
Is a pentest methodology protectable by the firm?
Often the firm's own playbooks, templates and tooling documentation belong to it, unless a contract assigns them to a client. These internal records are typically the stronger licensing candidates compared with client-specific reports.
Why would AI buyers care about security testing records?
Security work is a structured, multi-step process: scoping, reconnaissance, testing, rating, reporting and retesting. Records of that process with outcomes are scarce publicly, which makes a firm's own process documentation of interest, subject to rights review.
Does the partner need to see any reports?
No. Partners give basic fit information only. They never receive, describe or upload client findings, and SourceX handles inventory, rights review and redaction rules directly with the firm.
Related pages
Free resources
- Portfolio data opportunity scanner — Screen several companies in one session.
- Working capital calculator — Net working capital, current ratio and quick ratio.
- Due diligence checklist generator — A tailored document request list by deal type.
- All free tools · MCP resource center
By SourceX Partnerships Team · Published 2026-10-09 · Updated 2026-10-09
Know a US company with valuable proprietary data?
Become a referral partner from anywhere we support, get your link and introduce an owner or authorized decision-maker.
Refer a company →I own a business
Explore licensing your company's data to AI developers worldwide. Start a short assessment; no uploads needed.
Start an assessment