Security

Real offensive depth

Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Security & Compliance Glossary

Security Questionnaire

A security questionnaire is a structured set of questions an enterprise buyer sends a vendor to assess the vendor's security and compliance posture before purchasing. It covers areas like access control, encryption, incident response, and certifications. Completing it is a standard gate in the B2B sales and procurement process.

In practice

Common formats include the SIG (Standardized Information Gathering) questionnaire and CAIQ. They arrive late in the deal and can stall it for weeks if a vendor scrambles to answer from scratch.

A current SOC 2 report or ISO 27001 certificate short-circuits much of the questionnaire, since buyers accept the attestation in place of many individual answers. A maintained answer library and a named security owner turn a multi-week fire drill into a same-week turnaround.

// how traztech helps

traztech delivers security questionnaire response and vendor reviews for startups and growth-stage companies, led by a published security researcher.

Book a call

For a broader look at getting audit-ready, see our SOC 2 readiness work, or talk to a fractional CISO about building a program around it.

Where it comes up

Questionnaires arrive at the worst point in a sales cycle: after the buyer is interested and before they will sign. Answering one badly costs weeks; answering forty of them badly costs a quarter.

The efficient pattern is to answer once, properly, and reuse it. A public trust page removes a large share of the questions before anybody sends the form, and a current SOC 2 or ISO 27001 report answers many more with independent evidence.

Security Questionnaire: common questions

How do we reduce how many questionnaires we receive?

Publish the answers. A trust page covering certifications, data handling, subprocessors and a security contact answers most of what a reviewer needs and narrows what they ask for.

Can we refuse to complete a questionnaire?

You can offer your SOC 2 report or ISO certificate instead, and many buyers accept that. Regulated buyers usually still send their own form.

Track record

Who is actually doing the work

5
Published CVEs, including a CVSS 9.1
76
Controls taken from nothing to a passed SOC 2 Type II
Zero
Exceptions on that Type II report
20+
Penetration testing engagements delivered

Published vulnerability research

Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.

Before you go

Want the practical version by email?

Definitions only get you so far. I send a few short notes on how this plays out in practice. Unsubscribe in one click, and replies reach me directly.

From Jacob Masse, principal of traztech. No spam, unsubscribe in one click.