
Security Questionnaires, Answered From What You Have Already Said
Selling to anyone who takes security seriously ends the same way: a spreadsheet of two hundred questions, most of which you answered for the last prospect in slightly different words.
The trust module has promised AI-answered questionnaires since launch, but only the outbound direction — questionnaires you send to vendors — actually existed. This release builds the inbound side on the same foundation. Upload the sheet, check the extracted questions, and draft. The drafting order is the point: your own public words come first, because an answer that matches your trust center is one your prospect can verify. Internal policies, evidence, and controls come second and are weighted down, because they were written for insiders. Every answer cites its source, and a quote the model paraphrased is labeled as paraphrased.
When you approve a questionnaire, its answers become the library. The next prospect who asks "Do you encrypt customer data at rest?" as "Is data encrypted when stored?" gets a draft from the answer you already approved.
The trust center itself became something you run rather than something you configure. Visitors subscribe and confirm by email, you send updates by topic, and the visitor questions, access requests, and subscriber list moved out of Settings into the main app, where the work actually happens.
On the compliance side, custom control mapping is for teams who wrote their own controls and need each one tied to the several framework requirements it covers. Map it in the app or in the CSV import, and anything ambiguous is reported back instead of guessed. PCI assessment drafting now reads what is inside your evidence before it writes a response, and writes one per testing procedure.
- Inbound security questionnaires with grounded AI drafting and an answer library
- Trust center subscribers with double opt-in, topic-based updates, and unsubscribe
- Trust inboxes in the main app — questions, access requests, subscribers
- Custom control mapping and per-scope Tests
- Evidence-grounded PCI drafting, per-procedure responses, and a full SAQ report
- Readable findings and a weekly coverage digest
- A security hardening pass across functions, route guards, and notification content
Compare Risk Frameworks
A practical guide to NIST RMF, ISO 27005, FAIR, OCTAVE, and COSO ERM—when each fits mid-sized companies, what the tradeoffs are, and how to pick without checkbox theater.
Agent-first GRC: what changes when AI runs the program
Most GRC tools added AI as a feature. Agent-first GRC treats agents as the operator — drafting policies, answering questionnaires, and running the program with humans approving the work that matters.