Use cases

Match security questionnaire questions to approved answers

Matches each question to the fitting approved answer in your library and flags ones asking for documents or commitments. A person reviews every match.

Try it on this example

Example · A three-part encryption question, where one approved answer covers two parts

Section heading: 4. Data Protection

Questionnaire question, one row

4.3 Please confirm whether customer data is encrypted when stored, state the algorithm and key length used, and state whether the encryption keys are managed by the customer or by the vendor.
  1. Does the row ask a question clear enough to answer?Yes95%
  2. Which approved answer in the library answers this questionnaire question?ENC-01 Encryption at rest58%
  3. Does one approved answer in the library answer everything the question asks?No61%
  4. Does the question ask more than one thing?Yes98%
  5. Does the question ask for a document, report, certificate or policy to be attached or sent?No90%
  6. Does the question ask Quillstack to agree to a contractual term rather than describe a practice?No92%
  7. Which security area does the question belong to, for routing to the right expert?Encryption100%

These are real answers stored from one run on this example.

The prism behind it

Match security questionnaire questions to approved answers7 questions

Fields

  • Questionnaire question, one row
  • Section heading

Context

Security questionnaires sent to Quillstack, a business software company, by customers and prospects. Each row of a questionnaire is read here on its own, with its section heading. The options of the approved answer question are the entries of our answer library. Each entry was written and approved by the security and legal teams, is named by its library id, and is described by what it says. When an entry is chosen, code copies its approved text into the questionnaire. Nothing here writes or changes answer text. A person reviews every questionnaire before it goes back. Rows no single entry fully answers go to the security expert for the row's topic. Rows that ask Quillstack to agree to a contractual term go to legal, because contract terms are agreed only in the contract. Rows that ask for a document are answered from the trust centre.

Questions

  1. Does the row ask a question clear enough to answer? Yes / No

    Some rows are headings, instructions to the vendor, or fragments such as "See above" or "Other (please specify)". Yes: The row asks something Quillstack could answer, however it is worded. No: The row is a heading, an instruction, a fragment or otherwise asks nothing that can be answered.

  2. Which approved answer in the library answers this questionnaire question? Choice

    Read the question and its section heading, and compare them with what each library entry says. Choose the entry that answers the question. When the question asks several things, choose the entry that answers the most of it; other questions record what is left. Do not choose an entry only because it shares words with the question. When no entry answers any part of the question, none of the listed options fits.

    • ENC-01 Encryption at rest Customer data is encrypted at rest with AES-256, using 256-bit keys, in every data store, including backups and replicas.
    • ENC-02 Encryption in transit All external traffic uses TLS 1.2 or higher; traffic between internal services is encrypted with mutual TLS.
    • ENC-03 Key management Encryption keys are held in the cloud provider's key management service, managed by Quillstack and rotated every year. Customers on the Enterprise plan can supply their own keys.
    • IAM-01 Customer sign-in, SSO and MFA Customers can sign in through SAML 2.0 or OpenID Connect single sign-on on all paid plans, and can require multi-factor authentication for every user.
    • IAM-02 Staff access to production Quillstack staff reach production only through single sign-on with hardware security keys, on least privilege, reviewed every quarter. Access to customer data needs an approved ticket and is logged.
    • OPS-01 Logging and monitoring Security events are logged centrally, kept for 12 months and monitored around the clock by the security operations team.
    • OPS-02 Vulnerability management Systems and dependencies are scanned for vulnerabilities every week. Critical findings are fixed within 7 days and high findings within 30.
    • ASM-01 Penetration testing An independent firm tests the product and infrastructure every year. A summary of the latest report is available under NDA.
    • ASM-02 Secure development Every code change is peer reviewed and scanned before release, and developers take secure coding training every year.
    • CRT-01 SOC 2 Type II Quillstack has a SOC 2 Type II report covering security and availability, renewed every year, available under NDA.
    • CRT-02 ISO/IEC 27001 Quillstack is certified to ISO/IEC 27001; the certificate is published on the trust centre.
    • IR-01 Incident response plan A written incident response plan with named roles and a 24-hour on-call rota, tested twice a year.
    • IR-02 Breach notification Customers are told of a confirmed security breach affecting their data without undue delay, and within 72 hours of confirmation.
    • BCM-01 Backup and recovery Data is backed up every day to a second region. Recovery point objective 24 hours, recovery time objective 8 hours; restores are tested every quarter.
    • BCM-02 Business continuity A business continuity plan covers the loss of an office, a hosting region or a key supplier, and is tested every year.
    • PRV-01 Data residency Customers choose EU or US hosting when they sign up, and data at rest stays in the chosen region.
    • PRV-02 Subprocessors Subprocessors are listed on the website, and customers are told 30 days before a new one is added.
    • PRV-03 Data deletion at contract end Customer data is deleted within 30 days of the end of the contract, and from backups within a further 35 days.
    • PRV-04 Data processing agreement Quillstack acts as a processor of customer personal data under its standard data processing agreement, which includes the EU standard contractual clauses for transfers.
    • HR-01 Staff screening and training Employees pass background checks where the law allows, sign confidentiality terms, and take security awareness training when they join and every year.
    • VEN-01 Supplier security reviews Suppliers with access to customer data are assessed before contract and reviewed every year.
    • INF-01 Physical security Quillstack runs no data centres of its own. Physical security is provided by the cloud provider's certified facilities.
    • AI-01 Use of AI and customer data Customer data is not used to train AI models. AI features are optional, off by default, and use providers bound not to keep or train on customer data.
  3. Does one approved answer in the library answer everything the question asks? Yes / No

    Compare every part of the question with what the library entries say. Yes: A single entry, as described, answers every part of the question. No: Answering the whole question needs more than one entry, or some part is answered by no entry.

  4. Does the question ask more than one thing? Yes / No

    Count separate requests for facts, such as whether something is done, how, and by whom. A question with a follow-up such as "if yes, describe" asks two things. Yes: The question asks two or more separate things. No: The question asks one thing, however long it is.

  5. Does the question ask for a document, report, certificate or policy to be attached or sent? Yes / No

    Yes: The question asks for a copy of a document, a report, a certificate, a policy or evidence such as a screenshot. No: The question asks only for a description or an answer.

  6. Does the question ask Quillstack to agree to a contractual term rather than describe a practice? Yes / No

    Count questions that ask Quillstack to agree, accept, commit or warrant: an audit right, a notice period, a liability, an indemnity, insurance cover or a service level. A question about what Quillstack does today is a practice, not a commitment. Yes: The question asks Quillstack to agree to a term of this kind. No: The question asks only what Quillstack does or has.

  7. Which security area does the question belong to, for routing to the right expert? Choice

    Choose by what the question asks about, not by the section heading alone.

    • Access control Sign-in, single sign-on, multi-factor authentication, staff access and access reviews.
    • Encryption Encryption at rest and in transit, algorithms, keys and key management.
    • Security operations Logging, monitoring, vulnerability scanning and patching.
    • Application security Secure development, code review, penetration testing and bug bounties.
    • Incident response Incident plans, breach notification and forensic support.
    • Continuity and recovery Backups, disaster recovery, business continuity and uptime.
    • Privacy and data handling Personal data, data residency, subprocessors, retention and deletion.
    • Certifications and audits SOC 2, ISO/IEC 27001, other certifications and third-party audit reports.
    • People security Background checks, confidentiality terms and security training for staff.
    • Supplier management Assessing and monitoring Quillstack's own suppliers.
    • Infrastructure Hosting, networks, physical security and cloud configuration.
    • AI use AI features, model providers and whether customer data trains models.
    • Contract terms Audit rights, liability, insurance, notice periods and other terms to be agreed.

Lens columns

enough_information, enough_information_probability, approved_answer, approved_answer_probability, fully_answered, fully_answered_probability, compound, compound_probability, asks_for_document, asks_for_document_probability, asks_commitment, asks_commitment_probability, topic, topic_probability

Run it on your own text

Add this prism in the app, change any question, and test it on a file of your own.

Ask for an invite