Playbook, SaaS company
A procurement reviewer working through a vendor assessment at speed
Somewhere in the middle of a deal that your sales team thinks is going well, a security reviewer the seller has never spoken to opens the marketing site and starts pasting rows from a vendor assessment into the chat box. They will never open the product. They have a spreadsheet, a deadline, and a list of controls, and the speed of the answer decides whether the deal moves this week or next month.
Why this is not the general answer
The handling pattern for security questionnaires holds across every trade. What follows is the part that does not.
- The person asking is not a user and never will be, they are an assessor working through a template on behalf of somebody who has already chosen you.
- The questions are commercial security controls: subprocessors, residency, audit scope, breach notification windows, provisioning standards, contract terms.
- Failure here is silent, because a reviewer who cannot get an answer marks the row unanswered and the deal stalls without anybody telling you why.
- The endpoint is always a document rather than a conversation, and the document carries an attestation that only a person can put their name to.
How it arrives
- do you have an audit report we can review
- who are your subprocessors and where do they operate
- can we see a summary of your last penetration test
- do you support scim provisioning and enforced single sign on
- what is your breach notification window
- will you sign our data processing agreement or only your own
What has to be indexed for this to work
| The trust page and the subprocessor list | Every third party that touches customer data, what they do, and where they operate. Reviewers ask this first and it is entirely publishable. Keep it dated, because a list without a date reads as a list nobody maintains. |
|---|---|
| How an audit report is requested | Not the report, the route to it: who to contact, whether a confidentiality agreement is required first, and how long that usually takes. The assistant can hand somebody that route in one reply, and the route is the actual bottleneck in most deals. |
| Your data processing agreement and its standard position | Whether you offer your own agreement, whether you will review theirs, and which annexes are already prepared. Reviewers ask this because their legal team asked them, and a clear published position saves a fortnight. |
| The answers you already reuse across assessments | Most companies past a certain size have a document of standard responses, written once and pasted repeatedly. It is the highest value material for this cell and it usually lives in one person's drive rather than anywhere indexable. |
The reply
The subprocessor list with processing locations is published on the trust page, and enforced single sign on with automated provisioning is available on the plans listed there. The audit report is shared under a confidentiality agreement rather than published, and the security team sends it out on request. I cannot complete or return an assessment document, so leave your name, your work email and the deal or account it relates to and the team will send the report and the standard response set together.
It answers the rows it can from published material and gives the route for the row it cannot, which is what an assessor actually needs to keep moving. It never characterises whether an answer satisfies the control, because that judgement belongs to the reviewer and offering it is how a vendor ends up quoted in a report. Asking which deal it relates to means the response lands with the sales thread rather than as an anonymous request.
Where it stops
The trigger. Any request that ends in a document being returned, a term being agreed, or a signature.
Completed assessments and signed agreements come from the security team rather than from here, and I cannot commit to a contractual position. If you leave your name, your work email and the company you are assessing on behalf of, they will send the report request form and the standard responses in one go.
It stops answering before it guesses, says who will pick it up, and asks for the one thing that makes a reply possible. Nothing about it reads as a dead end.
Never say this here
Out of bounds
- That you hold a certification, audit report or assessment status that your own published material does not state.
- An availability commitment or recovery target that is not in a published service agreement.
- That a given answer will satisfy the reviewer's control or their internal policy.
- That a contractual term, annex or amendment is acceptable.
Questions
- Our reviewers want the answers back in their own template. Can it do that?
- No, and it should not appear to. It answers in chat with references back to the source page, which lets a reviewer verify a claim against your own document rather than trusting a chat message. Transcribing that into their template, and attesting to it, is a person's job with a person's liability attached.
- Is it risky to let a security team query us through a public widget?
- It answers only from what you index, so the exposure is exactly the material you chose to publish. The genuine risk is the opposite of leakage: a confident sounding summary of a carefully worded trust page, which is why quoting with a reference beats paraphrasing here.
- What is the fastest thing we can do to improve these answers?
- Publish the subprocessor list and the report request route, and date them both. Those two rows appear in nearly every assessment, they block the rest of the sheet, and neither of them requires a legal review to put on a page.
Keep reading
- Everything for a SaaS companyOne widget serves prospects, trialists and paying customers. What it can answer about plans and limits, and what has to reach a person.
- Handling security questionnaires in generalA buyer-side question arriving in the wrong place. Answer only what you publish, and never let an assistant improvise a claim you then own.
- The moment a subscription question turns into an account nobody can seeOn a subscription site the handover line is account visibility. What to collect in the message field, and why a second vague reply costs you.
- The card expired, and the notice went to somebody who has leftDunning, grace periods and the annual renewal that declines. What can be explained from policy when nobody in chat can see the payment.
- Reset my password is often the wrong question on a team accountIf sign in is federated there is no password to reset. What the assistant can explain, and why it can never send a link itself.
Try it on your own material
Upload a document or point it at your site, paste one line of HTML, then ask it something only your business could answer.