A standardised set of questions a customer uses to assess a provider's information security.
With a security questionnaire (also vendor security assessment) a customer wants to understand, before signing, whether a provider processes their data securely. The questions range from access control through encryption and incident management to certificates and subcontractors. Many customers use established standards such as VSA, CAIQ or SIG, others send their own Excel lists with hundreds of rows. For regulated industries like finance or healthcare the questionnaire is often especially extensive.
For many providers the security questionnaire is the most tedious part of a tender, and at the same time the decisive one. Because the answers rarely sit in one place: IT knows one part, the data protection officer another, some of it lives in certificates. The same questions come up with every customer, just phrased differently, and are still answered by hand each time. Whoever delivers fast and consistently gains a real edge; whoever spends weeks gathering blocks the entire deal.
With Tendry you answer security questionnaires automatically from your verified knowledge base, source-based and auditable. So you deliver in hours instead of weeks and never answer the same question twice.