FillTrust

For teams with no compliance department

Security questionnaires, answered automatically in minutes.

Drop in a vendor questionnaire. Every answer is drafted from your own SOC 2 report and policies, with the passage it came from — so the afternoon becomes a review. Where your documents do not support an answer, the box is left blank rather than filled with a control you would have to defend.

Every answer links back to a source line you can verify.

It reads

  • SOC 2 Type II
  • ISO 27001
  • Policies
  • DPAs
  • Pen test reports
  • Your answer library

One finished questionnaire, in figures

241
questions in the worked example
99%
drafted from the company’s own documents
2
that needed a person
5
ways an answer can be graded

One 241-question assessment. Sample data: the company and its documents are invented.

How it works

From a blank questionnaire to a cited draft, in one pass.

  1. STEP 01

    Give it your evidence

    Your SOC 2 report, ISO certificate, policies, pen test summaries. It reads these and nothing else.

  2. STEP 02

    Upload the questionnaire

    Excel, Word or PDF. Merged headers, several sheets, one column or five. It finds the questions in it.

  3. STEP 03

    Read the ones that need you

    Sorted by how solid the evidence is. Confirmed answers are ready; only the handful marked “needs you” want a look.

See it step by stepAnd what it does around the drafting

Receipts, not guesses

Every answer shows the passage it came from.

Pick any question below. The answer, its grade, and the document and page behind it are all there, so a reviewer approves in seconds instead of going to look for the evidence themselves.

CAIQ_v4_Vendor_Assessment.xlsx

239 answered · 2 need you

Pick a question · 4

Drafted answer

Yes. Application vulnerability assessments are performed at least annually, and an independent penetration test is carried out each year by an external firm.

Your documents confirm annual assessments but never mention an external penetration test. That second sentence is an inference. Cut it or confirm it before sending.

Drawn from

SOC2_Type_II_2026.pdfpp. 52–53

How answers are graded

Five ways an answer gets made.

Not a confidence score. A percentage tells you nothing about what to do next; these tell you exactly, and the same colour means the same thing everywhere in the product.

most solid

Confirmed in your documents
168 / 241

explicit

Answered “no” from your documents
21 / 241

reused

Reused from your library
39 / 241

inferred

Implied, not stated
11 / 241

needs you

Not in your documents
2 / 241

How accurate is it?

Refusals

Three things it will not do.

On purpose. They are the reason the answers are worth reading.

  • Invent a control you do not have

    If your documents do not cover something, it says so and leaves the answer blank. A plausible sentence in that gap is a false security representation to your customer.

  • Send anything on your behalf

    Every answer is yours to approve, and the file only leaves when you download it. We never send it to the company that asked.

  • Make you the reviewer of its own homework

    Answers that are inferred are labelled as inferred, and answers drawn straight from your documents say which passage they came from. A quick review stays quick.

Answer two. Not two hundred.

From $19 a month. Put your documents in once, and it is the last questionnaire you answer by hand.

Not ready? Publish a Trust Center instead. It is free, and some questionnaires stop at the page.