Pentest Today.
security questionnaire

Pass your vendor security questionnaire

Stop stalling deals on the security questionnaire. Pentest Today turns an approved-target scan into the pentest report, policies, and diagrams that answer the hard questions for you.

What a Vendor Security Questionnaire review asks for

Enterprise buyers send a security questionnaire before they'll sign — asking how you test, protect, and monitor their data.

✓A recent penetration test report
✓Vulnerability scanning and remediation evidence
✓Security policies (access, encryption, incident response)
✓Architecture and data-flow diagrams
✓Proof your findings are tracked and closed

What closes each requirement

ControlWhat they askEvidenceWhere it comes from
Application security testingBehind "do you perform penetration testing?" sits "show me the report, and let me check its date and its scope".A penetration test report listing the approved targets, with severity on every finding and, wherever the finding supports it, a CVSS v3.1 vector and base score, evidence, reproduction steps, and remediation — plus the retest that closed the findings it raised.The pentest workflow. The drafted answer names the report as its evidence source, so the reviewer is told which attachment to open rather than asked to guess.
Identity and access management"Do you use MFA?" is a scope question. The reviewer wants to know whether it covers administrators, cloud consoles, and source control, or only the shared marketing inbox.The Access Control Policy's authentication and privileged-access sections, with the enforcement scope taken from your intake instead of asserted.The policy pack. Where the intake does not settle it, the drafted answer marks the enforcement scope as unconfirmed rather than claiming full coverage.
Encryption and data handlingEveryone answers yes to "is data encrypted at rest and in transit?". The follow-up naming algorithms and asking who holds the keys is the one that separates answers.The Data Handling Policy's encryption standards and key-management clauses, with the specifics filled from the encryption summary in your intake.The policy pack. With no encryption summary on file the answer is drafted conditionally and flagged, which is the honest version of not knowing.
Incident response"Do you have incident response procedures?" is really asking what you have committed to notifying this buyer about, and on what clock.The Incident Response Policy — detection, triage, containment, eradication, recovery, post-incident review — together with the severity tiers and the named owner of the process.The policy pack. The owner comes from the intake; where none is given, the draft leaves the name out instead of inventing a role.
Third parties and subprocessors"List your subprocessors" is a test of whether you know where the data goes, which is why a careful reviewer compares your list against your own architecture drawing.The Vendor Management Policy for how a vendor is assessed and reviewed, and the system architecture and data-flow diagram showing which third parties sit outside your trust boundary.The policy pack and the generated diagram, both from the same intake, so the list and the drawing cannot disagree.
AI and model providers"Is customer data sent to AI services, and do any of them train on it?" now appears on most enterprise questionnaires, and it stalls deals because most vendors have no document that answers it.The AI Customer Data Handling Statement, the AI Vendor/Subprocessor Summary, and the AI Vendor Review Policy setting out how a model provider is assessed before it is approved.The AI documents in the security packet, drafted from the intake's answers on AI tooling, product AI features, and whether customer data reaches a model provider at all.
Continuity and recovery"What are your RPO and RTO?" is asking for two numbers you have committed to, not for the name of your backup tool.The Business Continuity / Disaster Recovery Policy: daily automated backups, encryption at rest, documented retention, and restores tested at least quarterly. Its recovery objectives start from baseline defaults — twenty-four hours to restore, four hours of tolerable data loss — each marked to be confirmed per system.The policy pack, with the Current implementation section written from your intake's backup process, hosting setup, and cloud provider. Treat the two recovery numbers as a starting position rather than an answer, and settle them before the document reaches a buyer, because that is the row a reviewer reads against your contract.

What an answered row actually looks like

Two rows, as the answer generator's baseline drafts them, before review
AI and model providers Question: "Is any customer data sent to third-party AI or machine-learning subprocessors?" Draft answer: Support transcripts and in-product prompts are sent to one approved model provider for summarization; no other customer data leaves our environment for AI processing. Approved AI vendors are listed in our AI Vendor/Subprocessor Summary. Evidence source: AI Customer Data Handling Statement; AI Vendor/Subprocessor Summary Confidence: high Needs review: no Encryption and data handling Question: "Describe how customer data is encrypted at rest and in transit, including algorithms and key management." Draft answer: Yes. Data is encrypted in transit and at rest. Specific algorithms and key management details are to be confirmed. Evidence source: Data Handling Policy Confidence: medium Needs review: yes

Illustrative example, written in the format the product generates. Not taken from a customer engagement.

How this review actually runs

A questionnaire arrives attached to a deal that is otherwise done. It is usually a spreadsheet of forty to three hundred rows, and it lands on whoever answered the last one.

The rows split into three unequal groups. A minority are facts about your environment — the authentication method, the encryption summary, the logging stack — and only somebody who knows the system can supply them. Most ask whether a documented process exists, and are answered by naming the document. A handful are commercial and belong to legal, not security.

Pentest Today's answer generator takes the row list, pasted one per line or drawn from a preset set, and matches each question to a topic. The draft is grounded in your intake and the documents in your security packet, and answers nothing outside them. Every row comes back with three things attached: a named evidence source, a confidence of high, medium, or low, and a review flag. A row grounded in something you answered comes back high with the flag clear. A row the intake does not cover comes back medium or low with the flag set, and the text says what is unconfirmed instead of filling the gap.

That second group decides whether the questionnaire survives contact. A reviewer who catches one answer you cannot evidence re-reads every other answer, and the conversation stops being about your security and becomes about your accuracy. Spend the afternoon on the flagged rows; attach a document to the rest and move on.

What gets this sent back

A yes with nothing attached. The reviewer's next message asks for the document, and that round trip costs more than the answer saved. Every affirmative that names no artifact is an invitation to a follow-up you will answer later anyway.
A penetration test report older than a year. Most enterprise reviewers apply a twelve-month recency rule, and a stale report is treated as no report at all — the row fails and the deal waits on a new test rather than on your answer.
Answers that contradict the architecture diagram. A subprocessor list that omits a service the diagram draws outside your boundary tells a reviewer the two documents were written by different people who never compared them, and both get read again more slowly.
Overclaiming on encryption. Answering "AES-256 everywhere" without knowing what the managed database actually does is the claim most likely to be checked, and being wrong on it reopens every other row you answered confidently.
One person answering from memory. An answer nobody can trace back to a document is unverifiable by definition, and when that person changes role the next questionnaire starts from an empty page.
Free · no account

Start your Pentest

Our agent swarm and human experts test your endpoints and deliver an audit, fast.

Vendor Security Questionnaire, answered

How do I answer a vendor security questionnaire faster?

Answer it once and reuse it. Most rows repeat from buyer to buyer, so the leverage is a maintained answer library in which every entry names the document behind it. Pentest Today drafts that library from a single intake, attaches an evidence source to each answer, and flags the rows a person still has to finish.

What documents should I attach to a security questionnaire?

A current penetration test report, the policies the questions cite — access control, data handling, incident response, vendor management — and a system architecture or data-flow diagram. The diagram is the unusual attachment, and it is the one that stops a reviewer asking three follow-up questions about where their data ends up.

Do I need a penetration test to pass a vendor security review?

Most enterprise reviews ask for one, and a growing number will not sign without it. What gets accepted is a report with a scope statement naming the tested targets, per-finding severity and evidence, and a remediation trail. A scanner export with no scope and no reproduction steps usually comes back.

What if the honest answer to a question is no?

Say no, then say what compensates for it and when that changes. Reviewers score an unbacked yes far more harshly than a no with a dated plan, because the yes has to be verified and the no does not. Every questionnaire has rows nobody passes; the ones that end deals are the ones later found untrue.

How often does a security questionnaire have to be redone?

Annually for most enterprise buyers, and again after a material change — a new subprocessor, a new data location, an acquisition. Because the answers are drafted from an intake, updating the intake and regenerating is what keeps the library current, rather than editing last year's spreadsheet in place.

Is a SOC 2 report a substitute for the questionnaire?

A SOC 2 report shortens the questionnaire and rarely replaces it. Buyers holding a SOC 2 still ask the questions their own obligations force them to ask — data location, subprocessors, AI use, breach notification — because those are commitments made to them specifically, and an attestation about your controls does not make them.

Is the pentest a real test or just a scanner dump?

Both scanning and AI triage are scoped to your approved targets, and every finding is reviewed and signed off by a human before delivery — so the report reflects verified findings, not raw scanner noise.

How fast can I get a report?

Most reports turn around in hours, not weeks. You connect an approved target, we scan and verify, and you export a client-ready report and policy pack.

Get the evidence for your Vendor Security Questionnaire review this week.

Start a scan on an approved target and walk in with the report, policies, and diagrams already done.