Secure Password Sharing for Hosting Companies
Hosting companies share login credentials with clients continuously. Learn how to do this securely at scale.
See PassTransfer ProNo business shares credentials more frequently than a hosting company. Every new hosting account provisioned is a credential handover event. Every server setup triggers a password delivery. Every support interaction that involves resetting access means sharing a new credential with a client. At any reasonable scale, this happens dozens or hundreds of times per day.
Most hosting companies are still handling this via plain-text email. The provisioning system generates a welcome email, the credentials go in the email body, the client receives them, and the email persists — in the client's inbox, in your sent folder, in your email infrastructure — indefinitely.
This page examines why that model creates real risk at hosting company scale, what a better approach looks like, and how branded secure credential delivery improves client trust without adding operational complexity.
The Scale Problem: Why Hosting Companies Face Elevated Risk
For most organisations, insecure credential sharing is an occasional problem. For hosting companies, it is a structural one.
Volume Amplifies Every Risk
If you provision 50 new hosting accounts per month, you are generating 50 or more credential emails per month. Over five years, that is 3,000+ emails with credentials in them, distributed across your client inbox infrastructure and your own email systems.
A single breach of your outbound email system — or a breach of a client's email account — can expose not one credential but potentially hundreds, depending on what the attacker chooses to search for. The attack surface grows linearly with your business volume.
Client Email Accounts Are Not Your Security Control
When you email a credential to a client, it lands in infrastructure you have no visibility into or control over. Your clients' email providers, their security practices, their password hygiene, their vulnerability to phishing — none of these are under your management. And yet your credential is now sitting in that environment indefinitely.
A client whose email account is compromised is also, effectively, a credential breach — even if your systems were never touched.
Automated Welcome Emails Are a Systemic Weakness
Most hosting platforms automate credential delivery via welcome emails. This is operationally sensible but creates a predictable pattern that attackers know and exploit. Welcome emails from hosting providers are a standard target for attackers who compromise a hosting company's email infrastructure precisely because they reliably contain credentials in predictable formats.
If your provisioning system emails credentials in plain text, you have a known, predictable security weakness at the heart of your onboarding flow.
Password Reset Workflows Are Recurring Exposure Events
Support teams at hosting companies handle password resets constantly. A client locked out of their control panel. A forgotten FTP password. An expired certificate causing an authentication failure. Each reset is another credential in an email — another record in an archive, another exposure point.
Over the lifetime of a client relationship, there may be dozens of reset events. Each one leaves a trail.
What Hosting-Specific Credential Sharing Should Look Like
The ideal credential delivery flow for a hosting company has these properties:
- Credentials are not in the email — the email contains a link, not the credential itself
- The link expires — ideally within 24–48 hours; long enough for a client to act, short enough to limit exposure
- The link works once — after the client retrieves the credential, the link is worthless
- The interface is branded — the client sees your company's identity, not a generic third-party tool
- No new account required — the client does not need to sign up for anything to access their credentials
PassTransfer Pro provides all five of these properties via a branded subdomain.
Support Workflows: Where Credential Sharing Gets Messy
Provisioning is the predictable part of credential delivery. Support is where discipline tends to break down.
A support engineer under time pressure, dealing with an urgent client issue, defaults to the fastest available method. If the fastest method is email or chat, that is what they use. Policies help, but they do not override urgency in practice unless the secure method is as fast as the insecure one.
PassTransfer is designed to be that fast. From a bookmarked browser tab:
- Type the new credential
- Set a 24-hour expiry
- Copy the link
- Paste the link into the support response
The entire flow takes under 30 seconds. That is close enough to plain-text email that it does not create meaningful resistance under pressure.
For teams handling high volumes, the Pro tier's branded subdomain means the support engineer is sending the client to a URL they recognise as yours — reducing any client hesitation about accessing the link.
Client Trust and the Credential Delivery Moment
Hosting clients evaluate their provider's trustworthiness continuously, but credential delivery is a particularly visible moment. It is often the first substantive interaction in a new hosting relationship. It sets the tone.
A welcome email with credentials in the body says nothing about your security posture — it is the standard, expected, unremarkable approach. A welcome email with a secure link to yourcompany.passtransfer.com says something different. It says you have thought about how to protect their access, you use proper tools, and you handle credentials professionally.
This is especially valuable for hosting companies targeting SME clients who are increasingly security-aware. A client who has just heard about GDPR fines, who has been in a webinar about cybersecurity, or who has a technical stakeholder reviewing your onboarding process will notice and appreciate a secure credential delivery flow.
Integrating Secure Credential Delivery into Hosting Workflows
Option 1: Manual Link Creation (Immediate, No Integration Required)
For smaller hosting operations or teams handling credential delivery manually, the flow is straightforward:
- Support or provisioning team bookmarks the branded PassTransfer URL
- On account creation or password reset, they create a secure link and paste it into the delivery email
- No technical integration required
This approach works immediately and requires no development work. It can be introduced alongside an updated email template that explains to clients that "for security, your credentials are delivered via a secure one-time link rather than in this email."
Option 2: Integration with Provisioning Workflows
For larger hosting companies with automated provisioning systems, the PassTransfer API allows programmatic creation of secure credential links. Instead of inserting credentials into welcome email templates, your provisioning system:
- Makes an API call to PassTransfer to create a secure link for the credentials
- Inserts the link URL into the welcome email template
- Sends the email with a link rather than credentials in the body
This change can be made to your provisioning system in a few hours and immediately applies secure credential delivery to every new account. The client experience is essentially identical — they receive a welcome email and click a link — but the security properties are fundamentally different.
Option 3: Hybrid Approach
Many hosting companies have a mix of automated provisioning for standard accounts and manual handling for custom or enterprise accounts. A hybrid approach applies API integration to automated flows and manual link creation to custom handling, covering both scenarios with appropriate effort.
GDPR Compliance for Hosting Companies
Hosting companies occupy a specific position under GDPR. You are typically a data processor for your clients, who are controllers. The personal data being processed is often your clients' end-user data — email addresses, contact details, transaction records — stored on infrastructure you manage.
Article 28 of GDPR requires data processors to implement "appropriate technical and organisational measures" to ensure the security of processing. Article 32 specifies what those measures include: encryption, access control, and ongoing assessment.
Credentials to client systems are access control mechanisms. If those credentials are compromised — including by interception during transmission — you have a security incident that may trigger breach notification obligations for both you and your affected clients. Under GDPR's 72-hour notification requirement, demonstrating that you handle credentials securely is both a compliance requirement and an operational necessity.
Using encrypted, one-time credential links means:
- Credentials are never stored in your email infrastructure in plaintext
- Credentials are deleted after the client accesses them
- If your email system is breached, the attacker finds links that no longer work, not valid credentials
- You can demonstrate to clients and to data protection authorities that your credential delivery meets the standard of care required
For a full walkthrough of what the regulation expects, see the guide to GDPR and password sharing.
Building a Credential Delivery Policy for Your Team
A hosting company credential delivery policy does not need to be complex. The following four rules cover the essential requirements:
Rule 1: No credentials in email bodies or chat messages. All credentials are delivered via secure one-time links. This applies to automated provisioning and manual support.
Rule 2: All links have expiry set to 48 hours or less. For account provisioning, 48 hours is sufficient for a client to access their welcome link. For support resets, 24 hours is typically adequate.
Rule 3: Links are never reused. Each credential delivery event gets a fresh link. Do not create a link, fail to send it, and then send it later — create a new one.
Rule 4: Credentials shared externally are rotated when access is no longer needed. When a project ends, a client leaves, or an account is transferred, credentials that were shared externally should be changed.
The Competitive Angle
Security-conscious clients choose their hosting provider partly on trust. As data breaches in the hosting industry receive more press coverage and as GDPR enforcement becomes more active, clients are increasingly asking their hosting providers: "What do you do to protect our data and our access credentials?"
A hosting company that can point to a concrete, documented credential delivery practice — encrypted one-time links, automatic expiry, branded delivery, no persistent plaintext storage — is in a stronger position than one that falls back on "we use HTTPS and have a firewall."
PassTransfer Pro is the infrastructure for that practice. It provides the tool, the branded experience, and the API integration path that lets you turn "we take credential security seriously" from a marketing claim into a demonstrable operational reality.
For hosting companies competing on trust, professionalism, and the ability to tell clients they are in safe hands, secure credential delivery is one of the clearest and most practical places to start.
Further reading
Start sharing passwords securely
Create an encrypted, one-time link. Free and without an account.