How it works
From a blank questionnaire to a cited draft, in one pass.
From a folder of security documents to the spreadsheet you were sent, filled in, with every answer showing where it came from.
STEP 01
Upload the questionnaire
Drag in the .xlsx, .csv, PDF or Word file you were sent. Any format, any length, however the columns are laid out.
STEP 02
It reads your evidence
Your SOC 2 report, policies, DPA and past approved answers become the source for every draft. Nothing is invented.
STEP 03
Review just the gaps
Sorted by how solid the evidence is. Confirmed answers are ready; only the handful marked “needs you” want a look.
What we read
Your evidence. Nothing else.
There is no model memory of security best practice behind this. If a claim is not in a document you gave us, it does not get written.
- SOC 2 Type II reports
- The control descriptions and the auditor’s testing, section by section.
- ISO 27001 certificates and Statements of Applicability
- Scope, controls in place, and the ones you have justified out.
- Internal policies and standards
- Access control, encryption, incident response, business continuity.
- Legal documents and DPAs
- Retention, sub-processors, data location, breach notification windows.
- Your answer library
- Every answer you have already approved, reused instead of regenerated.
The mechanism
Eight steps, and you are in two of them.
- 01
Add your documents once
Your SOC 2 report, ISO certificate, internal policies, whitepapers, previous questionnaires. They stay in your knowledge base, so every questionnaire after the first starts from everything you have already written down.
- 02
We index them, per account
Each document is split into passages and stored as embeddings scoped to your account alone. Retrieval works on meaning rather than keyword overlap, so a question phrased nothing like your policy still finds the paragraph that answers it.
- 03
Upload whatever you were sent
Excel, PDF or Word. There is no list of supported questionnaires to check yours against. The parser reads the layout of the file in front of it, including merged headers, several sheets, and question text spread across more than one column.
- 04
Extraction, including the fiddly parts
Questions, the context columns around them, and the data validation rules, so where a cell only accepts “Yes / No / N/A”, the answer written there is one of those exact options. You can see and correct the detected layout before anything is answered.
- 05
Answers, with their sources attached
Each answer is drafted from the passages retrieved for that specific question, and the quotes behind it are checked against those passages. An answer claiming certainty on sources we cannot find is demoted rather than published.
- 06
You review what actually needs it
Answers are labelled by what your documents support: confirmed, implied but not stated, a documented no, or not covered at all. The confirmed ones need a glance. The rest are the reason you are here, and there are usually a handful.
- 07
Ask a colleague, without giving them a seat
For a question nobody can answer from a document, send that single question to whoever does know. They reply by email, no account required, and their answer is saved to your library for the next questionnaire that asks it.
- 08
Send back the file they sent you
The same workbook, with styling, dropdowns and macros intact and answers in the cells they were meant for, plus a sheet recording which document each answer came from. PDF and Word get an answers appendix instead, because rewriting someone else's document in place is how documents get corrupted.
Confidence grading
What each grade actually claims.
- Confirmed in your documents
- A passage in your documents says it. The citation names the file and the page or section it sits on, and opens it.
- Answered “no” from your documents
- Your documents say you do not do this. A finished answer, not a gap.
- Reused from your library
- You approved this wording before. Reused verbatim rather than written again.
- Implied, not stated
- Supported by inference, not by a sentence. Somebody has to look before it goes out.
- Not in your documents
- Nothing covers it. Left blank on purpose, never filled with something plausible.
Or skip ahead and look at a finished one. No account needed.
Create your account