What it's for
Answering the security questionnaire a buyer sent you — in their format, with citations, in an hour rather than three weeks.
When you use it
Every time a buyer sends one. Also useful proactively: run a past questionnaire through it to find your gaps.
What's on the screen
Two input modes. Upload their document takes a drag-and-drop file (.xlsx, .xls, .csv, .tsv, .pdf, .txt; 10 MB and 100 questions max). Paste questions takes one per line, with a sample loader.
Result cards per questionnaire, showing name, question count, source type, date, and a "N need review" flag. Each answer displays the question, the drafted answer, a confidence chip, citation chips, and a status badge (from bank, needs review, owned by you). Per-answer actions: Edit, Save to bank, Ask an expert. Export buttons for .xlsx and .csv.
How it works
- Questions are extracted — every cell for spreadsheets, line-by-line for PDF and text, filtered by question marks and interrogative openings.
- Each question checks the answer bank first; a close match is reused verbatim at high confidence.
- Remaining questions go to the LLM with your controls, statuses, evidence, approved policies, and SOC 2 status as context — restricted to control IDs in your scope. Without an API key, a keyword matcher handles this.
- Citations are attached deterministically from your database, not by the model.
- Anything that maps to no control is flagged
needs reviewrather than dressed up.
Gotchas
- Answers reflect actual control status. In-progress controls produce "we're implementing this," not a claim of completion. That's the feature.
- Edit before sending. You're signing your name to these.
- Save the good ones to the bank or you'll regenerate them next time.