FillTrust

How it works

From a blank questionnaire to a cited draft, in one pass.

From a folder of security documents to the spreadsheet you were sent, filled in, with every answer showing where it came from.

  1. STEP 01

    Upload the questionnaire

    Drag in the .xlsx, .csv, PDF or Word file you were sent. Any format, any length, however the columns are laid out.

  2. STEP 02

    It reads your evidence

    Your SOC 2 report, policies, DPA and past approved answers become the source for every draft. Nothing is invented.

  3. STEP 03

    Review just the gaps

    Sorted by how solid the evidence is. Confirmed answers are ready; only the handful marked “needs you” want a look.

What we read

Your evidence. Nothing else.

There is no model memory of security best practice behind this. If a claim is not in a document you gave us, it does not get written.

SOC 2 Type II reports
The control descriptions and the auditor’s testing, section by section.
ISO 27001 certificates and Statements of Applicability
Scope, controls in place, and the ones you have justified out.
Internal policies and standards
Access control, encryption, incident response, business continuity.
Legal documents and DPAs
Retention, sub-processors, data location, breach notification windows.
Your answer library
Every answer you have already approved, reused instead of regenerated.

The mechanism

Eight steps, and you are in two of them.

  1. 01

    Add your documents once

    Your SOC 2 report, ISO certificate, internal policies, whitepapers, previous questionnaires. They stay in your knowledge base, so every questionnaire after the first starts from everything you have already written down.

  2. 02

    We index them, per account

    Each document is split into passages and stored as embeddings scoped to your account alone. Retrieval works on meaning rather than keyword overlap, so a question phrased nothing like your policy still finds the paragraph that answers it.

  3. 03

    Upload whatever you were sent

    Excel, PDF or Word. There is no list of supported questionnaires to check yours against. The parser reads the layout of the file in front of it, including merged headers, several sheets, and question text spread across more than one column.

  4. 04

    Extraction, including the fiddly parts

    Questions, the context columns around them, and the data validation rules, so where a cell only accepts “Yes / No / N/A”, the answer written there is one of those exact options. You can see and correct the detected layout before anything is answered.

  5. 05

    Answers, with their sources attached

    Each answer is drafted from the passages retrieved for that specific question, and the quotes behind it are checked against those passages. An answer claiming certainty on sources we cannot find is demoted rather than published.

  6. 06

    You review what actually needs it

    Answers are labelled by what your documents support: confirmed, implied but not stated, a documented no, or not covered at all. The confirmed ones need a glance. The rest are the reason you are here, and there are usually a handful.

  7. 07

    Ask a colleague, without giving them a seat

    For a question nobody can answer from a document, send that single question to whoever does know. They reply by email, no account required, and their answer is saved to your library for the next questionnaire that asks it.

  8. 08

    Send back the file they sent you

    The same workbook, with styling, dropdowns and macros intact and answers in the cells they were meant for, plus a sheet recording which document each answer came from. PDF and Word get an answers appendix instead, because rewriting someone else's document in place is how documents get corrupted.

Confidence grading

What each grade actually claims.

Confirmed in your documents
A passage in your documents says it. The citation names the file and the page or section it sits on, and opens it.
Answered “no” from your documents
Your documents say you do not do this. A finished answer, not a gap.
Reused from your library
You approved this wording before. Reused verbatim rather than written again.
Implied, not stated
Supported by inference, not by a sentence. Somebody has to look before it goes out.
Not in your documents
Nothing covers it. Left blank on purpose, never filled with something plausible.

How accurate is it, and how would you know?

Or skip ahead and look at a finished one. No account needed.

Create your account