Part of Pro · 36 questions · export to PDF

A customer sent a security questionnaire.The deal is waiting on it.

It has a deadline somebody else set, it asks questions you have answered before, and every answer has to be defensible. Answer it from your own scan history instead of from memory.

In short

A security questionnaire is the list of security questions a prospect sends before they will sign. XploitScan answers 36 of the questions procurement most often asks, drawing 6 of them directly from your own scan history and labelling every answer with what backs it — "Verified by scan" with a date, or "Self-attested" when it came from you. You review, edit anything, and export to PDF. It is part of the Pro plan; the separate Trust Page is free and needs no account.

Every answer says what backs it

This is the part a generic questionnaire filler cannot do. An unsourced “Yes” is what a procurement reviewer pushes back on — so we never write one.

Verified by scan

Sourced from a scan we ran, with the date attached and the age shown. Past 90 days we say so and suggest a re-scan rather than letting an old result read like this morning’s.

Self-attested

Came from you — your trust page, your security checklist. Useful and honest, and deliberately not dressed up as something we measured.

If your account has nothing behind a question, it stays blank for you to answer. We would rather hand you an empty field than agree to something on your behalf in a document you are about to sign and send.

How it works

  1. 1

    Scan your code

    Whatever we can source from a scan gets filled in — currently 6 of the 36 questions, covering the application-security section procurement leans on hardest.

  2. 2

    Review and fill the rest

    Questions about your own processes come to you blank. Edit anything we produced; your wording always wins, and the answer is relabelled as yours when you change it.

  3. 3

    Export and send

    Print or save to PDF. The evidence labels travel with the document, so whoever reads it can see which answers are measured and which are self-reported.

  4. 4

    Reuse it for the next deal

    Keep one master template and a per-prospect library, so answers can differ by customer without you rebuilding the whole thing each time.

What it covers

36 questions across 10 categories, written in our own words to cover the ground procurement teams ask about.

Company & ContactsSecurity ProgramApplication SecurityData HandlingAccess ControlIncident ResponseCompliance & AuditsSubprocessorsBusiness ContinuityPrivacy

Not SIG Lite or CAIQ — those are trademarked and we can’t ship the actual files. Answer here once, then copy across into whichever form the customer sent.

Questions about the questionnaire

What is a vendor security questionnaire?

It's the list of security questions a prospective customer sends before they'll sign — covering how you build software, who can access customer data, what happens during an incident, and which frameworks you align with. It usually arrives from procurement or legal, it has a deadline attached to a deal, and for most small teams it's the single most disruptive piece of unbilled work in the sales cycle.

Do you support SIG Lite or CAIQ?

Not as those formats. SIG Lite and CAIQ are trademarked and contain copyrighted question text, so we can't ship the actual files. Our question bank is written in our own words and covers the same ground procurement teams are asking about. In practice you answer here once and copy the answers across into whichever form a customer sent you.

How do you know the answers are true?

We don't assume them. Answers we can source from your scan history are marked "Verified by scan" and carry the scan date; answers that came from your trust page or your security checklist are marked "Self-attested", because those are your own entries rather than something we measured. If your account has no scan behind a question, we leave it blank for you to fill in rather than agreeing on your behalf.

Does it fill in everything automatically?

No, and that's deliberate. Questions about your own processes and infrastructure — how you triage findings, whether your traffic is encrypted, how often you review your program — can't be answered from anything we can see, so they come to you blank. Roughly 6 of the 36 questions can be sourced from a scan; the rest are yours to write, and you can edit any answer we do produce.

Is this a compliance certification?

No. We map findings to SOC 2, ISO 27001, OWASP Top 10 and CWE controls for reference, which is informational mapping and not an audit. Nothing here makes you certified, and the tool never claims you are. If a customer needs an actual SOC 2 report, you need an auditor.

What does it cost?

The questionnaire tools are part of the Pro plan, alongside the live Trust Page and the full rule set. If you're not ready for that, the Free Trust Page is genuinely free and needs no account — it answers the subset of questions that are really about publishing your policies and security contact.

Can I keep separate answers for different customers?

Yes. There's a default template you maintain once, and a library where each prospect's questionnaire is tracked as its own response with its own answers and status. Answers can drift per deal without losing the master template.

Answer it once

The questionnaire tools are part of Pro, alongside the live Trust Page and the full rule set. If you just need somewhere to publish your policies and security contact, the Trust Page is free and needs no account.

Security Questionnaire Answers, Backed by Real Scans | XploitScan