What it's for
Letting someone who has never heard of Veriflow find out, in three minutes, whether they'd survive an enterprise security review — and giving them something useful whether or not they sign up.
When you use it
It's public and needs no account. Share the link in a founder community, a sales conversation, or with a colleague who owns security.
What's on the screen
Ten questions, each mapped to real control IDs, answered yes / no / (sometimes) N/A. Then a results screen with a percentage score, a verdict ranging from "You'd fail today" to "You'd likely pass initial review", a gap list with concrete fixes, a red SOC 2 warning if applicable, and a Download report button.
Below the quiz is an early-warning tool: paste real questionnaire questions and see which map to structured controls. It runs entirely in the browser — nothing is transmitted.
How it works
Scoring is a simple percentage of applicable questions answered yes; the SOC 2 question is captured but excluded from the score, since it isn't an AIUC-1 control. The downloadable report is generated client-side as markdown, framed as "what the next enterprise buyer will ask" so it's shareable internally.
Nothing is stored and no email is required — by design. Gating it would cut the traffic that makes it useful.
Gotchas
- It doesn't create an account or carry answers into the app. Signing up still means running the full wizard.
- The quiz is deliberately harsher than your in-app score — it assumes no evidence and no policies.