Security questionnaires, answered from your evidence

Every answer carries the exact words from your own documents.

Upload the buyer's form alongside your policies and standards. We complete it in their required format, quote exactly what we found, and advise where your documents could be stronger in the areas the questionnaire covers.

Citations you can check

Not a claim. A quote.

Where others merely "cite" a source, we show the exact word-for-word text found in your document, alongside the specific file name. If the reference is missing, the question is flagged directly to you rather than guessed or improvised.

See the whole process
Q14 · Access control

Do you enforce multi-factor authentication on administrative access?

Yes. MFA is enforced for all administrative accounts through our identity provider, with no exception path.

Administrative access to production systems requires multi-factor authentication in all cases.

Information Security Policy, s4.2 Quote verified
Q115 · Key management

Do you operate a documented key management lifecycle?

Yes. Keys are generated, stored, rotated and retired under a documented lifecycle, managed in our KMS.

Cryptographic keys are generated, stored, rotated and destroyed under the Key Management Standard.

Key Management Standard, s2.4 Quote verified
Q277 · Application security

Is application security testing performed before release?

Yes. Static analysis and dependency scanning run on every build, with an independent penetration test annually.

All releases undergo static analysis and dependency scanning; an independent penetration test is performed at least annually.

Secure Development Policy, s6.3 Quote verified
01

Proof before payment

See the results before you decide. Our free pre-scan reads your documents, prices the project, and instantly shows five finished answers from your own questionnaire on screen.

02

Their format, returned

Excel, Word, PDF, portal exports, SIG or CAIQ. Whatever the buyer sent, that is what they get back.

03

Our own EU environment

Your documents are stored and processed end to end within Europe (Ireland) and do not leave it, governed by strict European data protection law.

Included with every questionnaire

The answers win this questionnaire. The gap report strengthens every one after it.

Alongside the completed questionnaire you receive a private gap report. It is scoped to the questionnaire in front of you: for the control areas the buyer's questions cover, we assess the documents you provided against ISO 27002 and set out where they could be stronger.

It is precise about why an answer fell short. If a policy states a practice without the specifics buyers look for, the report names those specifics so you can confirm them and strengthen the answer truthfully. If a policy points to a document you did not upload, the report says so, rather than recording a gap in a control you may well operate.

The report is yours alone. Nothing from it appears in the questionnaire the buyer receives. Improvements you make in those areas carry into every future questionnaire that touches them, whichever buyer sends it and whatever the format.

Plain speech

What we do, and what we do not claim.

We do

Answer from your documents, quote the exact text, and name the source for every answer.

We do

Deliver a private gap report with every questionnaire: for the control areas it covers, where your documents could be stronger and what to confirm.

We do

Tell you before payment how much of your questionnaire your evidence supports, with a fixed price.

We do not

Fabricate answers, inflate thin evidence, or assume how your controls operate. This process is a definitive documentary check.

One due this week?

The pre-scan is free and takes minutes. You will know exactly where you stand.

Start free