[{"data":1,"prerenderedAt":185},["ShallowReactive",2],{"changelog-2026-09-28-questionnaires-trust-center-control-mapping":3,"changelog-2026-09-28-questionnaires-trust-center-control-mapping-surround":174},{"id":4,"title":5,"api":6,"authors":7,"body":13,"category":91,"date":92,"description":93,"extension":94,"faq":6,"features":95,"fixes":119,"highlight":135,"image":144,"improvements":146,"meta":168,"navigation":169,"path":170,"seo":171,"stem":172,"__hash__":173},"posts\u002F3.blog\u002F2026-09-28-questionnaires-trust-center-control-mapping.md","Security Questionnaires, Answered From What You Have Already Said",null,[8],{"name":9,"to":10,"avatar":11},"Justin Leapline","https:\u002F\u002Fwww.linkedin.com\u002Fin\u002Fjustinleapline\u002F",{"src":12},"\u002Fimages\u002Fjustinleapline.png",{"type":14,"value":15,"toc":87},"minimark",[16,20,23,26,29,41],[17,18,19],"p",{},"Selling to anyone who takes security seriously ends the same way: a spreadsheet of two hundred questions, most of which you answered for the last prospect in slightly different words.",[17,21,22],{},"The trust module has promised AI-answered questionnaires since launch, but only the outbound direction — questionnaires you send to vendors — actually existed. This release builds the inbound side on the same foundation. Upload the sheet, check the extracted questions, and draft. The drafting order is the point: your own public words come first, because an answer that matches your trust center is one your prospect can verify. Internal policies, evidence, and controls come second and are weighted down, because they were written for insiders. Every answer cites its source, and a quote the model paraphrased is labeled as paraphrased.",[17,24,25],{},"When you approve a questionnaire, its answers become the library. The next prospect who asks \"Do you encrypt customer data at rest?\" as \"Is data encrypted when stored?\" gets a draft from the answer you already approved.",[17,27,28],{},"The trust center itself became something you run rather than something you configure. Visitors subscribe and confirm by email, you send updates by topic, and the visitor questions, access requests, and subscriber list moved out of Settings into the main app, where the work actually happens.",[17,30,31,32,36,37,40],{},"On the compliance side, ",[33,34,35],"strong",{},"custom control mapping"," is for teams who wrote their own controls and need each one tied to the several framework requirements it covers. Map it in the app or in the CSV import, and anything ambiguous is reported back instead of guessed. ",[33,38,39],{},"PCI assessment drafting"," now reads what is inside your evidence before it writes a response, and writes one per testing procedure.",[42,43,44,51,57,63,69,75,81],"ul",{},[45,46,47,50],"li",{},[33,48,49],{},"Inbound security questionnaires"," with grounded AI drafting and an answer library",[45,52,53,56],{},[33,54,55],{},"Trust center subscribers"," with double opt-in, topic-based updates, and unsubscribe",[45,58,59,62],{},[33,60,61],{},"Trust inboxes in the main app"," — questions, access requests, subscribers",[45,64,65,68],{},[33,66,67],{},"Custom control mapping"," and per-scope Tests",[45,70,71,74],{},[33,72,73],{},"Evidence-grounded PCI drafting",", per-procedure responses, and a full SAQ report",[45,76,77,80],{},[33,78,79],{},"Readable findings"," and a weekly coverage digest",[45,82,83,86],{},[33,84,85],{},"A security hardening pass"," across functions, route guards, and notification content",{"title":88,"searchDepth":89,"depth":89,"links":90},"",2,[],"changelog","2026-09-28","Inbound security questionnaires land as work items and draft their answers from your trust center and an answer library of everything you have approved before. Plus trust center subscribers and updates, custom control mapping, per-scope tests, evidence-grounded PCI assessment drafting, and findings that read like findings.","md",[96,99,102,105,107,110,113,116],{"label":97,"text":98},"Questionnaires","Inbound security questionnaires are a new work item under a Trust section in the sidebar — received, in review, approved, sent — with answers grouped by the sheet's own sections, accept and flag per answer, and CSV export.",{"label":100,"text":101},"AI","Draft unanswered, redraft everything not yet accepted, or regenerate a single answer. Confidence blends retrieval similarity with the model's own estimate and is discounted when a quote cannot be found verbatim in its source.",{"label":103,"text":104},"Trust Center","Visitors can subscribe from any page of your trust portal, pick the topics they care about — frameworks, subprocessors, policies, general — and confirm by email. Admins send updates to verified subscribers by topic, and every message carries a working unsubscribe link.",{"label":103,"text":106},"Visitor questions, access requests, and subscribers moved out of Settings into the Trust section of the main app, because they are daily work, not configuration. Visitors are emailed when an access request is decided or a question is answered.",{"label":108,"text":109},"Controls","Map a custom control to every framework requirement it covers — pick several at once, filtered by framework, visible from both ends. CSV import accepts a maps_to column and a procedures column, and reports refs that match nothing or match more than one rather than guessing.",{"label":111,"text":112},"Testing","Testing procedures are now simply Tests, attachable per scope, and findable from the control itself rather than buried in a tab nobody opened.",{"label":114,"text":115},"PCI","Assessment drafting is grounded in the contents of your evidence, not just its filenames, and writes a response for every testing procedure — the column a Report on Compliance exists to carry. The SAQ report is now the full five-part document, including eligibility and an action plan built from real issues and tasks.",{"label":117,"text":118},"Evidence","Excel files are read. Firewall exports, sampling worksheets, and asset inventories uploaded as xlsx now align to controls and appear in search instead of being skipped silently.",[120,123,126,129,132],{"label":121,"text":122},"Security","A hardening pass across the data layer — execute revoked on SECURITY DEFINER functions, evidence writers now authorize themselves, API route guards match the RLS they bypass, invite links and agent reply tokens moved off rows other members can read, and credential-shaped values are redacted from notification templates. Slack messages are escaped and email subjects sanitized.",{"label":124,"text":125},"Auth","Three defects that made a successful sign-in look like it failed, and entering a workspace now counts as accepting its invite.",{"label":127,"text":128},"Integrations","Deactivated admins are refused at the OAuth install gate, the AWS IAM credential report is regenerated when none exists, and transient Azure errors are retried.",{"label":130,"text":131},"Agent","A dry run no longer executes the handler it was previewing.",{"label":133,"text":134},"Notifications","A channel's switch only appears where that channel can actually deliver, and unaccepted admin invites are skipped in workspace notices.",{"title":136,"description":137,"icon":138,"items":139},"Every questionnaire makes the next one faster","Every prospect's security review ends in a spreadsheet. Upload it — xlsx, csv, docx, or pdf — and episki extracts the questions into a preview you can edit before creating the questionnaire. Draft with AI grounds each answer on your own public words first — trust center FAQs, answered visitor questions, published resources, and previously approved answers — then on internal policies, evidence, and controls. Every answer cites its sources, quotes are checked against the source text, and approving the questionnaire writes its answers back to the library so the next one asking the same thing in different words drafts from it.","i-lucide-message-square-text",[140,141,142,143],"Import a questionnaire from a spreadsheet, document, or PDF, and edit the extracted questions before creating it","Answers grounded on your trust center and answer library first, internal GRC content second","Citations on every draft, with paraphrased quotes flagged rather than presented as verbatim","Approved answers feed the library, so repeat questions draft themselves",{"src":145},"\u002Fimages\u002Fchangelog\u002Fquestionnaires-trust-center-control-mapping.webp",[147,150,153,156,159,162,165],{"label":148,"text":149},"Findings","Findings raised by a failing check get a readable title and a body that explains which fields decided the match, the relevant record values, and the controls and collection behind them — with no model call, so a finding raised at 3am reads the same on every run. Existing open findings are rewritten the next time their check runs.",{"label":151,"text":152},"Coverage","A weekly digest tells admins how many suggested control links are waiting for review. Coverage analysis no longer re-runs on unchanged evidence every sync, and suggestions retire when the evidence they point at is deleted.",{"label":154,"text":155},"Lists","A shared labels filter on every list view.",{"label":157,"text":158},"Settings","AI settings are consolidated into one group.",{"label":160,"text":161},"Third-Party Risk","A vendor review is now a real review, and the gaps a walkthrough of the module surfaced are closed.",{"label":163,"text":164},"Frameworks","Catalog references moved to SCF 2026.3, with workspace control refs remapped automatically.",{"label":166,"text":167},"Performance","AWS sync stops re-reading its estate and scope graph on every call, and bootstrap hydration is scoped to synced tables.",{},true,"\u002Fblog\u002F2026-09-28-questionnaires-trust-center-control-mapping",{"title":5,"description":93},"3.blog\u002F2026-09-28-questionnaires-trust-center-control-mapping","m2o-O584uVVqQZrXYq6QCpOihrpX0O_Ft_SPm1njauE",[175,180],{"title":176,"path":177,"stem":178,"description":179,"children":-1},"Compare Risk Frameworks","\u002Fblog\u002F2026-09-16-compare-risk-frameworks","3.blog\u002F2026-09-16-compare-risk-frameworks","A practical guide to NIST RMF, ISO 27005, FAIR, OCTAVE, and COSO ERM—when each fits mid-sized companies, what the tradeoffs are, and how to pick without checkbox theater.",{"title":181,"path":182,"stem":183,"description":184,"children":-1},"Agent-first GRC: what changes when AI runs the program","\u002Fblog\u002Fagent-first-grc","3.blog\u002Fagent-first-grc","Most GRC tools added AI as a feature. Agent-first GRC treats agents as the operator — drafting policies, answering questionnaires, and running the program with humans approving the work that matters.",1790735151680]