Security questionnaires

Answer the questionnaire with evidence, not adjectives.

A customer's security team sends 200 questions and a deadline. Most answers get written from memory and hope. Ours are answered by the scan where a scan can see, by a named person where it can't, and the document never blurs which is which.

Two kinds of answer, never mixed

36 questions a scan answers. 16 only a person can.

Every other tool renders a typed "Yes" identically to an observed one. We keep them apart because a buyer's reviewer will ask "how do you know?" on the first row they doubt, and the honest answer is different for each.

Observed — answered by the scan

A question earns this slot only when a detector in the product actually produces the signal. A "Yes" requires the evidence source to be connected; nothing connected reads "Not assessed", never "Yes". A typed answer is refused here — it would replace an observation with an opinion.

  • Access control6
  • Vulnerability management6
  • Infrastructure4
  • Cryptography3
  • Endpoint security3
  • External exposure2
  • Incident response2
  • Logging & monitoring2
  • Secure development2
  • Vendor / third-party2
  • Data protection1
  • Email security1
  • SaaS security1
  • Personnel1
Attested — answered by a named human

Background checks, DR rehearsals, insurance, policy sign-off: no scan can see these, and a tool that pretends otherwise is lying on your behalf. A named person answers, both Yes and No are real options, and the row renders "stated by <name> on <date>". A finding is never allowed to infer one of these.

  • Data protection4
  • Business continuity3
  • Governance3
  • Personnel2
  • Change management1
  • Incident response1
  • Physical security1
  • Vendor / third-party1

Why 52 and not the 261 in CAIQ v4: most of those ask about things no scanner can see, so importing them wholesale turns ten unanswered rows into two hundred and thirty. The proportion answered does not improve; the reader just wades through more admissions. We map to CAIQ / SIG-Lite control ids so a reviewer can cross-reference, and we grow the observed set only as fast as the detectors do.

Five answers, each with a meaning

No single score — a percentage would rise as you connected less and asserted more.

Yes

A scanner looked at the connected system and found the control in place. Only an observed question can say this, and only when its evidence source is connected.

In Progress

A real finding is open against a control this question maps to. The answer changes when the finding closes — not when someone edits the document.

No

The check ran and the control is absent. A questionnaire that cannot say no is a form with one answer, and a buyer knows it.

Not assessed

Nothing that could answer this is connected yet. Fixed by connecting a system, not by typing.

Needs your answer

No scan can see this — background checks, DR rehearsals, insurance. A named person answers, and the document says who and when.

The rendered document carries two separate notes above the table — what needs a system connected, and what needs a person to sit down — because merged, the reader is told to fix the wrong thing. The same answers feed the buyer-facing Trust Center (your own page at /trust/<workspace> once you sign up), so the next questionnaire is a link, not a fortnight.

See which of the 35 you can already answer.

Connect one system on the free tier and the observed rows fill in from real evidence. Prefer to start outside-in? The free domain scan covers the email-auth and web-posture rows without an account.