FillTrust security questionnaire corpus

Guidance for answering vendor security questionnaires.

Community: Submitted by a user or imported; check the owner before granting accessDegradedNo sign-inGlobalFreeRead-only

What it can do

    What data it sees

    Do you need an account

    No: the server works without sign-in

    Guidance for answering vendor security questionnaires. Every result carries the page it came from.

    Server tool list (5)

    Raw names from tools/list. Only developers need these.

    search_questionsFind guidance on how to answer a security questionnaire question. Search by the question text, a control area, or a standard and control identifier such as CEK-03. Returns matching entries with the URL of the page each came from.
    get_questionThe complete published guidance for one questionnaire question: what it is really asking, which of your documents answers it, what evidence to attach, a model answer with the specifics left blank, the ways it usually goes wrong, and the standards that ask it with their verified control references.
    list_standardsWhich questionnaire standards this corpus answers questions from, how many questions each has, and which controls are cited. Standards whose control lists are proprietary are named without reference numbers, on purpose.
    get_filltrust_postureFillTrust's own answers to the questions it exists to answer, for anyone assessing it as a vendor. Includes the answers that are "no".
    get_questionnaire_statisticsMeasured counts from 146 real vendor security questionnaires (17,697 questions) published by universities, purchasing consortia and companies: which topics are asked most, and detailed profiles of the questionnaires that have a name people use, such as HECVAT and CAIQ. Use this when asked what a security questionnaire contains, how long one is, or what a named questionnaire asks about. These are counts from real files rather than an estimate.