Evidence-backed security questionnaires
Import customer questions, draft answers from approved reports, review citations and attestations, and export approved responses.
Open Security questionnaires in Compliance programs. Each questionnaire retains its questions, source references, answer revisions, and approval history.
Import the questions
Choose Import a questionnaire and provide a title. Upload a UTF-8 CSV or TSV file, or enter one question per line. Files may use comma, semicolon, or tab separators and must have a Question column; Reference or ID is optional. The import supports up to 500 questions and a 2 MB file. Quoted CSV fields preserve line breaks inside a question.
Reference,Question
SEC-01,How are cloud permissions reviewed?
SEC-02,Is multi-factor authentication required for all staff?References and question order remain available for the final export. If validation fails, correct the named row or header and import again.
Select approved evidence
Choose the approved report revisions that may support the answers, then draft responses. Open each cited source and check its version, freshness, scope, and relevant excerpt.
A report about repository permissions cannot establish an unrelated company-wide policy. When the selected sources do not support an answer, the response remains unsupported. It should not be filled with an invented assurance.
Review each response
For a supported answer, confirm that its text follows from the cited evidence before approving it. If you edit the answer, review its provenance again; approval does not carry forward automatically.
When evidence does not establish the answer, an authorized reviewer can provide a statement and explicitly attest to it. An attested answer remains labeled as a reviewer statement. It is not converted into an evidence-backed fact.
Answer history shows the recorded changes and decisions. Changing evidence sources or drafting new content requires another review of the affected answers.
Export for the requester
Approve the responses required for export, then download the questionnaire CSV. The export preserves question order and references and identifies each answer's basis. Review the resulting file before returning it to the requester, especially any attested statements or coverage limitations.
Try the interactive demo to see a supported permissions answer and an unsupported MFA question. The demo requires a sample report approval before drafting, and explicit attestation for the unsupported answer.
Was this guide useful?
Your response stays in this browser unless you open a GitHub issue.