GRC Oversight

Live demoFictional sample data. Nothing is saved.

Sign up

11GRC

Questionnaires

Upload a security questionnaire (Excel or CSV). We parse the questions, draft answers from Northwind Robotics's policies, evidence, and past approved Q&A, score each by confidence, and let you approve every answer before export.

Excel (.xlsx) or CSV.

Your questionnaires

Acme Corp (RFP Security Questionnaire).xlsx

5 questions · 2 approved · PROCESSING

  1. 1. Do you encrypt data at rest and in transit?

    91% confidence
    Suggested answer

    Yes. All data at rest is encrypted with AES-256; data in transit uses TLS 1.2+. Encryption key management is handled via our cloud provider's KMS with annual key rotation.

    ✓ Approved
  2. 2. Do you have a documented incident response plan? How often is it tested?

    84% confidence
    Suggested answer

    Yes, our Incident Response Policy defines severity tiers, escalation paths, and communication SLAs. The plan is tabletop-tested annually; the most recent exercise was completed 3 months ago.

    ✓ Approved
  3. 3. Describe your vendor / sub-processor risk management process.

    77% confidence
    Suggested answer

    We maintain a vendor inventory rated by criticality, collect and parse SOC 2 reports on onboarding, and re-assess annually or on material change. High/critical vendors are continuously monitored for security posture drift.

  4. 4. Do you support single sign-on (SSO) and SCIM provisioning?

    32% confidence
  5. 5. What is your data retention and deletion policy for customer data after contract termination?

    68% confidence
    Suggested answer

    Customer data is retained for 30 days post-termination to support export requests, then permanently deleted, with deletion confirmed within 60 days per our Data Retention Policy.