Customer Security Questionnaire Support
Questionnaire turnaround < 2 days
Customer security questionnaires are the enterprise-sales tax. Every prospect over $50K sends 100-400 questions covering the same ground as SOC 2 + ISO 27001 + your trust page. Sales pings security; security pings engineering; engineering complains about writing the same 47-word answer for the fourth time this quarter. Deals stall 2-6 weeks waiting for the response. Answers get copy-pasted from stale docs. The evaluator sees a slow, inconsistent security posture.
An hour-by-hour walkthrough.
Step by step.
- 01
Parse the questionnaire into individual questions
Handle CAIQ / SIG / VSA / custom XLSX / PDF / web forms. Extract each question with its section, response-format expectation (yes/no, freeform, N/A allowed). Normalise to a common question record.
Document parsing · Questionnaire format library - 02
Match against the answer library
Every prior questionnaire answer + trust portal contents + SOC 2 + ISO 27001 + internal security docs. Match by semantic similarity + question intent. Confidence score per match.
Answer library · Reasoning · Trust portal · Compliance docs - 03
Draft answers by confidence tier
High confidence: filled with citation. Medium confidence: drafted with edit flag. Low or no confidence: routed to the SME with a draft-if-possible + the specific gap in the source material.
Reasoning · Confidence model · SME routing - 04
Reviewer edits + submits
Security lead reviews the draft. Edits inline. Approves. Submits in the required format (some customers want XLSX back, some their portal, some PDF). Lex delivers.
Web UI · Excel export · Portal submission - 05
Feed accepted answers back to the library
Every submitted answer feeds the library with the question + response + reviewer edits. Trust-portal source materials updated where the library reveals a gap. Library gets sharper over time.
Answer library · Trust portal · Compliance docs
What you connect to make this run.
Answer library · Trust portal
read+writeMaster corpus: every past questionnaire answer, published trust-portal contents, SOC 2 / ISO 27001, DPAs, subprocessor list. Read for matching; write with new answers accepted through this playbook.
Salesforce · HubSpot
read+writeOpportunity context: customer, deal value, timeline. Write questionnaire status back to the opportunity so sales sees blocker state. Deal-level SLA (typically 5 business days) drives urgency.
Slack · Teams · Email
read+writeReviewer + SME notifications. Draft handoff for edits. Final submission notification to sales. SME question-answering happens in Slack thread; answer becomes library material.
Vendor portals · DocuSign · Email
writeSubmit in the format the customer wants — some portals (Whistic, OneTrust) accept API submission, some want XLSX upload, some accept PDF via email. Lex delivers per each.
Before and after, honestly.
Playbooks that pair with this one.
Vendor Security Review
Reverse side — this playbook answers questionnaires; that playbook consumes them.
SOC2 / Vanta Evidence Collection
SOC 2 evidence is the largest source material this playbook draws from.
DPA Handling
DPAs are often attached to the same security review; joint handling saves cycles.
Answers about this playbook.
What if the customer's questionnaire asks about features we don't have?
Lex drafts an honest N/A with brief context ("Feature X is on our 2027 roadmap; compensating control is Y"). SME reviews and adjusts. Never fabricates a yes.
How does it handle contradictory answers we've given historically?
Surfaces the contradiction to the reviewer with both past answers + dates + who approved each. Reviewer resolves and the library update creates a single source of truth for next time.
Can we use it for RFPs and RFIs too?
Yes — same mechanism. RFPs have more freeform business questions; those route more often to SMEs, but the security portion (usually 30-40% of an enterprise RFP) is handled the same way.
How does confidentiality work when answers are reused across customers?
The answer library never quotes another customer's questionnaire or contract. Source materials are internal + public (trust portal, SOC 2, DPAs). Customer-specific claims (e.g., "we integrate with your specific system") stay in that customer's answer only.
What about very early-stage prospects (no NDA yet)?
Lex distinguishes public-safe answers from NDA-required ones. For pre-NDA questionnaires, only trust-portal-level answers auto-fill; NDA-gated answers wait for the NDA to complete before drafting.
See it run on your data.
Free plan, no credit card. Connect the systems this playbook needs and run it against a past event first.