Skip to content
Back to blog
case-study

Case study: secure password sharing at a hosting company

P
PassTransfer
Published January 17, 20264 min read

A hosting company operates in a unique position: it holds credentials not just for its own systems, but for hundreds of client environments. Servers, control panels, databases, DNS records, SSL management interfaces — the credential surface area is enormous. And every time a client needs access to their own infrastructure, credentials change hands.

This case study describes a composite scenario based on common challenges faced by hosting providers in the Netherlands and Belgium, and how PassTransfer addresses them.

The situation

A Dutch hosting company with approximately 400 active clients and a support team of 12 had been sharing credentials the way most companies do: via email. When a new client was onboarded, their initial FTP credentials and control panel login were sent in a welcome email. When a client called support and needed credentials reset, the new credentials were sent via a reply to their support ticket — in plain text.

The problems were predictable:

  • Credential exposure in email archives: Both the hosting company's and the client's email servers retained copies of credentials indefinitely. Years after a project ended, login details were still searchable in ticket history.
  • No confirmation of receipt: When credentials were emailed, the support agent had no way of knowing whether the client had read and understood them, or whether the email had been intercepted.
  • Security audit findings: The company participated in an ISO 27001 preparation audit and was flagged for inadequate credential delivery practices.
  • Client complaints: Several clients had called to report that they could not find their credentials — because the email had landed in spam, or they had simply lost it.

The change

The hosting company implemented PassTransfer as their standard credential delivery mechanism, integrated into their support workflow. The process was straightforward:

  1. When credentials need to be shared with a client, the support agent creates a PassTransfer link with a 48-hour expiry
  2. The link is pasted into the support ticket reply or client-facing email
  3. The client receives the link and retrieves their credentials
  4. The credential is deleted from PassTransfer's servers immediately after retrieval
  5. After 48 hours, any unclaimed link expires automatically

For Pro accounts, the company branded the credential links under their own subdomain — so clients received a link like secure.hostingcompany.nl rather than an unfamiliar third-party URL.

What changed

After three months of using this approach:

  • No more credentials in email archives: The support history now contains links, not credentials. Even if the ticket archive were compromised, there are no recoverable passwords.
  • Reduced support tickets for lost credentials: Because links are clearly labeled with an expiry, clients knew to act within 48 hours. Lost credential complaints dropped significantly.
  • ISO 27001 preparation: The audit trail improved. The company could point to a defined, documented process for credential delivery rather than ad hoc email.
  • Improved client confidence: Several enterprise clients specifically mentioned the professional credential delivery process as a positive signal during onboarding.

Lessons learned

Expiry times need calibration. An initial 24-hour expiry caused some client complaints — clients who received a link late on a Friday and did not open email until Monday found it had expired. Moving to 72 hours for client-facing links reduced friction while maintaining security. For guidance on picking these windows, see what expiry time to choose for a secret link.

Communicate the change to clients. Some clients were initially confused by receiving a link instead of the credentials themselves. A brief explanation in the email — "For security, credentials are delivered via a one-time secure link. Click the link below to retrieve your login details." — resolved this entirely.

Internal use follows client use. Once the team was comfortable using PassTransfer for client-facing credential delivery, they began using it for internal credential transfers as well — sharing server root credentials between senior engineers, for example.

The bottom line

For hosting companies, credential delivery is a core operational process. Replacing email-based credential sharing with one-time links requires almost no technical implementation — but the security and compliance benefits are significant. The transition is measured in days, not months.

Share this article
P
PassTransfer

The team behind PassTransfer writes about secure sharing, compliance and practical security for teams and agencies.

Ready to get started?

Sharing securely takes 10 seconds

Paste your password, pick an expiry time and share the link. Free and without an account.

Share a password