Questionnaire Workspace
35 questions across 7customer questionnaires. Each answer's confidence, status, and reviewer is computed from the mapped evidence — search, filter, and open any row to see why.
Northwind Capital
Financial Services · Renewal
5 questions$480K
1 awaiting a reviewerOpen
Meridian Health
Healthcare · New Logo
5 questions$1.2M
2 awaiting a reviewerOpen
Sterling Government Solutions
Public Sector · New Logo
6 questions$2.1M
2 awaiting a reviewerOpen
Bluepeak Retail
Retail & E-commerce · Expansion
5 questions$150K
2 awaiting a reviewerOpen
Helios Energy
Energy & Utilities · New Logo
5 questions$640K
All answers automatedOpen
Lumen Analytics
Data & Analytics · New Logo
5 questions$320K
4 awaiting a reviewerOpen
Orbit Media
Media & SaaS · Renewal
4 questions$90K
All answers automatedOpen
| Question | Evidence | Reviewer | |||
|---|---|---|---|---|---|
Are AI vendors and subprocessors disclosed? q-030 · 1 mapped control | Lumen Analytics | Privacy & Data Retention | Escalate47 | Expired | Privacy / Data Protection |
Are subprocessors disclosed and bound by data protection agreements? q-009 · 1 mapped control | Meridian Health | Privacy & Data Retention | Escalate56 | Expired | Privacy / Data Protection |
What human oversight exists for AI-generated outputs? q-028 · 1 mapped control | Lumen Analytics | AI & Model Governance | Needs Review64 | Expiring Soon | Legal |
What are your patch remediation SLAs and how are they tracked? q-012 · 1 mapped control | Sterling Government Solutions | Vulnerability Management | Needs Review70 | Expired | Security SME |
How quickly are critical patches applied to internet-facing systems? q-020 · 1 mapped control | Bluepeak Retail | Vulnerability Management | Needs Review72 | Expired | Security SME |
What is your patch management SLA for critical vulnerabilities? q-004 · 1 mapped control | Northwind Capital | Vulnerability Management | Needs Review75 | Expired | Security SME |
What are your contractual breach notification timelines? q-016 · 1 mapped control | Sterling Government Solutions | Incident Response | Suggested75 | Expiring Soon | Security Enablement |
How does your AI functionality use customer data, and is it used for model training? q-014 · 1 mapped control | Sterling Government Solutions | AI & Model Governance | Needs Review78 | Expiring Soon | Legal |
What is your vendor and third-party risk management process? q-019 · 1 mapped control | Bluepeak Retail | Vendor & Third-Party Risk | Suggested81 | Current | Security Enablement |
Describe data retention for AI training datasets. q-029 · 1 mapped control | Lumen Analytics | Privacy & Data Retention | Needs Review81 | Current | Privacy / Data Protection |
How are encryption keys managed and rotated? q-002 · 1 mapped control | Northwind Capital | Encryption & Data Protection | Suggested83 | Expiring Soon | Security Enablement |
Describe your incident response and breach notification process. q-007 · 2 mapped controls | Meridian Health | Incident Response | Suggested83 | Expiring Soon | Security Enablement |
How does your platform use AI, and is customer data used to train models? q-027 · 1 mapped control | Lumen Analytics | AI & Model Governance | Needs Review83 | Expiring Soon | Legal |
Do you support customer-managed data deletion requests? q-021 · 1 mapped control | Bluepeak Retail | Privacy & Data Retention | Needs Review84 | Current | Privacy / Data Protection |
How are encryption keys rotated and who has access to them? q-025 · 1 mapped control | Helios Energy | Encryption & Data Protection | Suggested84 | Expiring Soon | Security Enablement |
Describe vendor risk management for your subprocessors. q-035 · 1 mapped control | Orbit Media | Vendor & Third-Party Risk | Suggested84 | Current | Security Enablement |
Is business continuity and disaster recovery tested regularly? q-010 · 1 mapped control | Meridian Health | Business Continuity & Resilience | Auto-Approved91 | Current | Auto-Approved |
Describe your incident response plan and testing cadence. q-024 · 1 mapped control | Helios Energy | Incident Response | Auto-Approved91 | Current | Auto-Approved |
Provide details on your vulnerability management and penetration testing cadence. q-011 · 1 mapped control | Sterling Government Solutions | Vulnerability Management | Auto-Approved95 | Current | Auto-Approved |
Describe your cloud hosting architecture and tenant isolation. q-018 · 1 mapped control | Bluepeak Retail | Cloud & Infrastructure Security | Auto-Approved95 | Current | Auto-Approved |
What identity federation and MFA standards do you enforce? q-023 · 1 mapped control | Helios Energy | Access Control & Identity | Auto-Approved95 | Current | Auto-Approved |
How is PHI encrypted at rest and how is access to it controlled? q-006 · 2 mapped controls | Meridian Health | Encryption & Data Protection | Auto-Approved97 | Current | Auto-Approved |
Do you hold current SOC 2 and ISO 27001 certifications? q-034 · 1 mapped control | Orbit Media | Compliance & Certifications | Auto-Approved97 | Current | Auto-Approved |
Describe how customer data is encrypted at rest and in transit. q-001 · 2 mapped controls | Northwind Capital | Encryption & Data Protection | Auto-Approved100 | Current | Auto-Approved |
Is multi-factor authentication enforced for administrative access? q-003 · 1 mapped control | Northwind Capital | Access Control & Identity | Auto-Approved100 | Current | Auto-Approved |
Do you maintain a SOC 2 Type II report and ISO 27001 certification? q-005 · 1 mapped control | Northwind Capital | Compliance & Certifications | Auto-Approved100 | Current | Auto-Approved |
What is your data retention and deletion policy upon contract termination? q-008 · 1 mapped control | Meridian Health | Privacy & Data Retention | Needs Review100 | Current | Privacy / Data Protection |
Describe access provisioning, review, and deprovisioning controls. q-013 · 1 mapped control | Sterling Government Solutions | Access Control & Identity | Auto-Approved100 | Current | Auto-Approved |
Confirm SOC 2 Type II and ISO 27001 certifications and availability of reports. q-015 · 1 mapped control | Sterling Government Solutions | Compliance & Certifications | Auto-Approved100 | Current | Auto-Approved |
How is cardholder data encrypted and segmented per PCI DSS? q-017 · 2 mapped controls | Bluepeak Retail | Encryption & Data Protection | Auto-Approved100 | Current | Auto-Approved |
Describe encryption in transit for all external integrations. q-022 · 1 mapped control | Helios Energy | Encryption & Data Protection | Auto-Approved100 | Current | Auto-Approved |
Is there a documented business continuity plan with RTO/RPO targets? q-026 · 1 mapped control | Helios Energy | Business Continuity & Resilience | Auto-Approved100 | Current | Auto-Approved |
What encryption protects data processed by AI features? q-031 · 1 mapped control | Lumen Analytics | Encryption & Data Protection | Auto-Approved100 | Current | Auto-Approved |
Confirm the TLS standards used for data in transit. q-032 · 1 mapped control | Orbit Media | Encryption & Data Protection | Auto-Approved100 | Current | Auto-Approved |
Is access reviewed periodically and revoked on offboarding? q-033 · 1 mapped control | Orbit Media | Access Control & Identity | Auto-Approved100 | Current | Auto-Approved |
Showing 35 of 35 questions. Click any row to open the drafted answer, mapped evidence, and routing reasons.