SIG Lite, answered.
The 41 questions from SIG Lite we have written up so far. Each one covers what it is really asking, which of your documents answers it, what to attach alongside, and the specific ways it gets answered badly.
Are background checks performed on employees with access to customer data?
Confirmed in your documentsOne of the few questions answered from an HR document rather than a security one, which is exactly why it is often answered from memory.
People
Are backups tested by performing restores?
Implied, not statedEverybody takes backups. This question is about the last time one was proved to work.
Resilience
Are user access rights reviewed periodically?
Implied, not statedPolicies say quarterly. The reviewer is asking about the person who left in March, and periodic review is the wrong instrument for finding them.
Access control
Can customers access audit logs of activity in their account?
Answered “no” from your documentsThis one is a product question, not a security question, and the honest answer for most young products is no with an offer attached.
Logging and monitoring
Do employees complete security awareness training?
Confirmed in your documentsAn easy yes for most teams, and one of the few questions where the follow-up is a date rather than a document.
People
Do you allow customers to audit your security controls?
Answered “no” from your documentsAnswering yes to be agreeable grants a contractual right to send an assessor. Answering no with nothing offered instead leaves a gap in the reviewer's file. The useful answer is no, and here is what you get.
Certifications and audits
Do you assess the security of your vendors and sub-processors?
Implied, not statedThe question your customer is really asking is whether their data can reach somewhere they have not been told about.
Third-party risk
Do you carry cyber liability insurance, and what is the coverage limit?
Not in your documentsThe question FillTrust most often leaves deliberately blank. No security document contains the answer, and guessing a coverage limit is a representation you cannot support.
Governance
Do you classify data by sensitivity?
Not in your documentsOne of the few questions where most small companies genuinely have nothing, and where inventing a scheme is worse than saying so.
Data governance
Do you have a documented change management process?
Confirmed in your documentsAt fifteen people this is not a change advisory board. It is whether your pipeline records who changed what.
Engineering practice
Do you have a documented incident response plan, and what is your breach notification window?
Confirmed in your documentsTwo questions in one, and the second half, the notification window, is the one with contractual teeth. It comes from your DPA, not from GDPR.
Incident response
Do you have a secure software development lifecycle?
Confirmed in your documentsReviewers are testing one thing: what prevents an unreviewed change from reaching your customers' data.
Engineering practice
Do you have a vulnerability disclosure policy or bug bounty programme?
Not in your documentsVery few small companies run a bounty. Almost all of them should have the one-page policy, and it takes an afternoon.
Vulnerability management
Do you hold ISO 27001 certification?
Answered “no” from your documentsOne of the few questions where the answer is usually no, and where no is a perfectly good answer.
Certifications and audits
Do you log and monitor access to production systems?
Confirmed in your documentsTwo questions in one: what you record, and what happens when something in the record is worth waking up for.
Logging and monitoring
Do you maintain a business continuity and disaster recovery plan, and is it tested?
Reused from your libraryTwo numbers carry this answer, RTO and RPO, and they are the two a reviewer can hold you to during a real outage. Do not publish ones you have not measured.
Resilience
Do you maintain a current SOC 2 Type II report?
Confirmed in your documentsIf you have one, the cover page answers this question. The mistakes are all in the details it also contains: the type, the criteria, and the dates.
Certifications and audits
Do you maintain an inventory of systems and assets?
Implied, not statedYou probably have three inventories already and have never called them that.
Infrastructure
Do you perform annual penetration testing by an independent third party?
Implied, not statedThis is the question FillTrust most often grades as inferred rather than confirmed, because policies state a cadence and cadences are not evidence that a test happened.
Vulnerability management
Do you perform regular security risk assessments?
Not in your documentsThe most enterprise-shaped question on the questionnaire, and the one small teams most often answer with an aspiration.
Governance
Do you support single sign-on (SAML or OIDC)?
Answered “no” from your documentsA product question wearing a security costume, and the best example of a documented "no" being a better answer than a hedged yes.
Access control
Do you use customer data to train AI models?
Answered “no” from your documentsThe fastest-growing question on vendor questionnaires, and the one where a careless yes is hardest to walk back.
Data governance
Do you use sub-processors, and can you provide a current list?
Confirmed in your documentsThe list is easy. What reviewers actually check is whether the unglamorous ones are on it: the error tracker, the support desk, the AI provider.
Third-party risk
How are credentials, API keys and other secrets managed?
Confirmed in your documentsThe question is about the credentials your software runs on, not the password manager the team uses. Rotation is the part most likely to be aspirational, and the follow-up is always the date of the last one.
Encryption and key management
How are employee laptops secured?
Implied, not statedThe question moved on from antivirus. It is now about encryption, updates, and whether you can take a device away.
Devices
How do you handle international transfers of personal data?
Confirmed in your documentsWhere the servers are is only half of it. Who can reach the data, from which country, is the other half.
Data governance
How is one customer's data kept separate from another's?
Implied, not statedLogical separation is the true answer for nearly every SaaS, and also what somebody says when they have not thought about it. The difference is whether you can say how the boundary is enforced and tested.
Data governance
How quickly do you patch known vulnerabilities?
Implied, not statedThe question is not whether you patch. It is whether you can name the window and show that you meet it.
Vulnerability management
How quickly is access revoked when someone leaves?
Confirmed in your documentsThe strongest version of this answer is not a time. It is a single action that covers everything, plus a list of what it does not.
Access control
How quickly will you notify us of a data breach?
Confirmed in your documentsThe one answer that must match your contract word for word, because the contract is what a court reads.
Incident response
Is access granted on a least-privilege basis?
Implied, not statedThe honest small-company answer is rarely a clean yes, and the answer that names its exceptions is stronger than the one that does not.
Access control
Is customer data encrypted at rest?
Confirmed in your documentsOne of the most common questions on any questionnaire, and one of the most commonly over-answered: most teams encrypt the database and forget the backups.
Encryption and key management
Is customer data encrypted in transit?
Confirmed in your documentsEasy to answer yes to and easy to check from the outside, which makes it one of the few questions where a wrong answer is found rather than believed.
Encryption and key management
Is multi-factor authentication enforced for administrative access?
Confirmed in your documentsThe gap here is almost always between "enabled" and "enforced", and between staff logins and the two or three accounts that could not take a second factor.
Access control
What are your recovery time and recovery point objectives?
Not in your documentsTwo numbers with no scenario attached mean nothing, and a reviewer who has to guess will assume the flattering reading and hold you to it.
Resilience
What availability do you commit to, and how is it measured?
Implied, not statedA number with no measurement behind it is trivially checkable, against a status page and against the reviewer's memory of your last outage.
Resilience
What is your data retention period, and how is customer data deleted after termination?
Reused from your libraryThe number is easy. What separates a good answer from one that unravels is whether it accounts for backups, logs and every other place a copy came to rest.
Data governance
What is your password policy?
Confirmed in your documentsOne of the few questions where the modern answer looks weaker than the old one and is in fact much stronger.
Access control
What physical security controls protect your data centres?
Confirmed in your documentsYou do not run a data centre. Saying so, and naming who does, is the complete answer.
Infrastructure
Where is customer data hosted, and can it be kept in a specific region?
Reused from your libraryThe database is the easy half. A reviewer at an EU company is asking about every sub-processor and about who can read a record from where.
Data governance
Will you notify us before adding or changing a sub-processor?
Confirmed in your documents"We will notify you" and "we will notify you thirty days before" are different commitments, and this question is asking for the second.
Third-party risk
Answer the whole SIG Lite at once.
Upload the file you were sent. FillTrust drafts each answer from your own documents and shows the passage it came from.