Answer the questionnaire with evidence, not adjectives.
A customer's security team sends 200 questions and a deadline. Most answers get written from memory and hope. Ours are answered by the scan where a scan can see, by a named person where it can't, and the document never blurs which is which.
36 questions a scan answers. 16 only a person can.
Every other tool renders a typed "Yes" identically to an observed one. We keep them apart because a buyer's reviewer will ask "how do you know?" on the first row they doubt, and the honest answer is different for each.
A question earns this slot only when a detector in the product actually produces the signal. A "Yes" requires the evidence source to be connected; nothing connected reads "Not assessed", never "Yes". A typed answer is refused here — it would replace an observation with an opinion.
- Access control6
- Vulnerability management6
- Infrastructure4
- Cryptography3
- Endpoint security3
- External exposure2
- Incident response2
- Logging & monitoring2
- Secure development2
- Vendor / third-party2
- Data protection1
- Email security1
- SaaS security1
- Personnel1
Background checks, DR rehearsals, insurance, policy sign-off: no scan can see these, and a tool that pretends otherwise is lying on your behalf. A named person answers, both Yes and No are real options, and the row renders "stated by <name> on <date>". A finding is never allowed to infer one of these.
- Data protection4
- Business continuity3
- Governance3
- Personnel2
- Change management1
- Incident response1
- Physical security1
- Vendor / third-party1
Why 52 and not the 261 in CAIQ v4: most of those ask about things no scanner can see, so importing them wholesale turns ten unanswered rows into two hundred and thirty. The proportion answered does not improve; the reader just wades through more admissions. We map to CAIQ / SIG-Lite control ids so a reviewer can cross-reference, and we grow the observed set only as fast as the detectors do.
No single score — a percentage would rise as you connected less and asserted more.
A scanner looked at the connected system and found the control in place. Only an observed question can say this, and only when its evidence source is connected.
A real finding is open against a control this question maps to. The answer changes when the finding closes — not when someone edits the document.
The check ran and the control is absent. A questionnaire that cannot say no is a form with one answer, and a buyer knows it.
Nothing that could answer this is connected yet. Fixed by connecting a system, not by typing.
No scan can see this — background checks, DR rehearsals, insurance. A named person answers, and the document says who and when.
The rendered document carries two separate notes above the table — what needs a system connected, and what needs a person to sit down — because merged, the reader is told to fix the wrong thing. The same answers feed the buyer-facing Trust Center (your own page at /trust/<workspace> once you sign up), so the next questionnaire is a link, not a fortnight.
See which of the 35 you can already answer.
Connect one system on the free tier and the observed rows fill in from real evidence. Prefer to start outside-in? The free domain scan covers the email-auth and web-posture rows without an account.