Pass your vendor security questionnaire
Stop stalling deals on the security questionnaire. Pentest Today turns an approved-target scan into the pentest report, policies, and diagrams that answer the hard questions for you.
What a Vendor Security Questionnaire review asks for
Enterprise buyers send a security questionnaire before they'll sign — asking how you test, protect, and monitor their data.
What closes each requirement
| Control | What they ask | Evidence | Where it comes from |
|---|---|---|---|
| Application security testing | Behind "do you perform penetration testing?" sits "show me the report, and let me check its date and its scope". | A penetration test report listing the approved targets, with severity on every finding and, wherever the finding supports it, a CVSS v3.1 vector and base score, evidence, reproduction steps, and remediation — plus the retest that closed the findings it raised. | The pentest workflow. The drafted answer names the report as its evidence source, so the reviewer is told which attachment to open rather than asked to guess. |
| Identity and access management | "Do you use MFA?" is a scope question. The reviewer wants to know whether it covers administrators, cloud consoles, and source control, or only the shared marketing inbox. | The Access Control Policy's authentication and privileged-access sections, with the enforcement scope taken from your intake instead of asserted. | The policy pack. Where the intake does not settle it, the drafted answer marks the enforcement scope as unconfirmed rather than claiming full coverage. |
| Encryption and data handling | Everyone answers yes to "is data encrypted at rest and in transit?". The follow-up naming algorithms and asking who holds the keys is the one that separates answers. | The Data Handling Policy's encryption standards and key-management clauses, with the specifics filled from the encryption summary in your intake. | The policy pack. With no encryption summary on file the answer is drafted conditionally and flagged, which is the honest version of not knowing. |
| Incident response | "Do you have incident response procedures?" is really asking what you have committed to notifying this buyer about, and on what clock. | The Incident Response Policy — detection, triage, containment, eradication, recovery, post-incident review — together with the severity tiers and the named owner of the process. | The policy pack. The owner comes from the intake; where none is given, the draft leaves the name out instead of inventing a role. |
| Third parties and subprocessors | "List your subprocessors" is a test of whether you know where the data goes, which is why a careful reviewer compares your list against your own architecture drawing. | The Vendor Management Policy for how a vendor is assessed and reviewed, and the system architecture and data-flow diagram showing which third parties sit outside your trust boundary. | The policy pack and the generated diagram, both from the same intake, so the list and the drawing cannot disagree. |
| AI and model providers | "Is customer data sent to AI services, and do any of them train on it?" now appears on most enterprise questionnaires, and it stalls deals because most vendors have no document that answers it. | The AI Customer Data Handling Statement, the AI Vendor/Subprocessor Summary, and the AI Vendor Review Policy setting out how a model provider is assessed before it is approved. | The AI documents in the security packet, drafted from the intake's answers on AI tooling, product AI features, and whether customer data reaches a model provider at all. |
| Continuity and recovery | "What are your RPO and RTO?" is asking for two numbers you have committed to, not for the name of your backup tool. | The Business Continuity / Disaster Recovery Policy: daily automated backups, encryption at rest, documented retention, and restores tested at least quarterly. Its recovery objectives start from baseline defaults — twenty-four hours to restore, four hours of tolerable data loss — each marked to be confirmed per system. | The policy pack, with the Current implementation section written from your intake's backup process, hosting setup, and cloud provider. Treat the two recovery numbers as a starting position rather than an answer, and settle them before the document reaches a buyer, because that is the row a reviewer reads against your contract. |
What an answered row actually looks like
Illustrative example, written in the format the product generates. Not taken from a customer engagement.
How this review actually runs
A questionnaire arrives attached to a deal that is otherwise done. It is usually a spreadsheet of forty to three hundred rows, and it lands on whoever answered the last one.
The rows split into three unequal groups. A minority are facts about your environment — the authentication method, the encryption summary, the logging stack — and only somebody who knows the system can supply them. Most ask whether a documented process exists, and are answered by naming the document. A handful are commercial and belong to legal, not security.
Pentest Today's answer generator takes the row list, pasted one per line or drawn from a preset set, and matches each question to a topic. The draft is grounded in your intake and the documents in your security packet, and answers nothing outside them. Every row comes back with three things attached: a named evidence source, a confidence of high, medium, or low, and a review flag. A row grounded in something you answered comes back high with the flag clear. A row the intake does not cover comes back medium or low with the flag set, and the text says what is unconfirmed instead of filling the gap.
That second group decides whether the questionnaire survives contact. A reviewer who catches one answer you cannot evidence re-reads every other answer, and the conversation stops being about your security and becomes about your accuracy. Spend the afternoon on the flagged rows; attach a document to the rest and move on.
What gets this sent back
Scan
Authenticated and external scans across web, API, and cloud surface the issues before an assessor does — de-duped, triaged, and mapped to CVE/CVSS.
Pentest
Approved-target scans become a client-ready pentest report: validated findings, evidence, reproduction steps, remediation, and the retest letter auditors accept.
Policy Generator
Generate the policies and system architecture diagrams the review expects — access control, cryptography, incident response — pre-mapped to controls.
Start your Pentest
Our agent swarm and human experts test your endpoints and deliver an audit, fast.
SOC 2
SOC 2 is an AICPA report on how your controls meet the Trust Services Criteria — security, availability, processing integrity, confidentiality, and privacy.
SOC 2 Type II
A SOC 2 Type II report tests whether your controls operated effectively across an observation window, not just on paper.
ISO 27001
ISO/IEC 27001 certifies that you run an Information Security Management System (ISMS) with the Annex A controls in place.
HIPAA
The HIPAA Security Rule requires administrative, physical, and technical safeguards for electronic protected health information (ePHI).
GDPR
GDPR Article 32 requires appropriate technical and organizational measures to secure personal data, including regular testing of their effectiveness.
PCI DSS
PCI DSS protects cardholder data and explicitly requires both internal and external penetration testing at least annually.
Vendor Security Questionnaire, answered
How do I answer a vendor security questionnaire faster?
Answer it once and reuse it. Most rows repeat from buyer to buyer, so the leverage is a maintained answer library in which every entry names the document behind it. Pentest Today drafts that library from a single intake, attaches an evidence source to each answer, and flags the rows a person still has to finish.
What documents should I attach to a security questionnaire?
A current penetration test report, the policies the questions cite — access control, data handling, incident response, vendor management — and a system architecture or data-flow diagram. The diagram is the unusual attachment, and it is the one that stops a reviewer asking three follow-up questions about where their data ends up.
Do I need a penetration test to pass a vendor security review?
Most enterprise reviews ask for one, and a growing number will not sign without it. What gets accepted is a report with a scope statement naming the tested targets, per-finding severity and evidence, and a remediation trail. A scanner export with no scope and no reproduction steps usually comes back.
What if the honest answer to a question is no?
Say no, then say what compensates for it and when that changes. Reviewers score an unbacked yes far more harshly than a no with a dated plan, because the yes has to be verified and the no does not. Every questionnaire has rows nobody passes; the ones that end deals are the ones later found untrue.
How often does a security questionnaire have to be redone?
Annually for most enterprise buyers, and again after a material change — a new subprocessor, a new data location, an acquisition. Because the answers are drafted from an intake, updating the intake and regenerating is what keeps the library current, rather than editing last year's spreadsheet in place.
Is a SOC 2 report a substitute for the questionnaire?
A SOC 2 report shortens the questionnaire and rarely replaces it. Buyers holding a SOC 2 still ask the questions their own obligations force them to ask — data location, subprocessors, AI use, breach notification — because those are commitments made to them specifically, and an attestation about your controls does not make them.
Is the pentest a real test or just a scanner dump?
Both scanning and AI triage are scoped to your approved targets, and every finding is reviewed and signed off by a human before delivery — so the report reflects verified findings, not raw scanner noise.
How fast can I get a report?
Most reports turn around in hours, not weeks. You connect an approved target, we scan and verify, and you export a client-ready report and policy pack.
Get the evidence for your Vendor Security Questionnaire review this week.
Start a scan on an approved target and walk in with the report, policies, and diagrams already done.