Security Questionnaires
Answer the security questionnaires your customers send you. Upload, review and export them, while every approved answer grows a reusable answer library so the next questionnaire is faster.
Overview
The Security Questionnaires module is where you answer the security and vendor-assessment questionnaires that your customers send you. Upload the file you received, and devguard reads it into individual questions, pre-fills what it can from your Answer Library, and lets you review, edit, approve and export each answer.
Every answer you approve is promoted into the Answer Library, so the next questionnaire that asks the same thing is pre-filled automatically. The library compounds: the more questionnaires you complete, the less work each new one takes.
This is the reverse of Vendor Questionnaires, which are the ones you send to your own vendors. The two are kept deliberately separate.
How it works
- Upload a questionnaire you received (XLSX, CSV or PDF).
- devguard parses it into questions and shows which columns it read.
- Each question is matched against your Answer Library and pre-filled where a confident match exists.
- Optionally, AI auto-fill drafts answers for the remaining questions from your organisation's own data.
- You review, edit and approve each answer.
- Export the completed questionnaire as XLSX or CSV to send back.
It works fully without AI: upload, match, review and export never require generation. AI auto-fill is an explicit, optional accelerator.
Uploading
Choose Upload questionnaire and select an XLSX, CSV or PDF file.
| Field | Description |
|---|---|
Name | How the questionnaire appears in your list (defaults to the file name) |
File | The questionnaire you received (XLSX/CSV up to 25 MB, PDF up to 4 MB) |
This questionnaire is already answered | Turn on to import the file's existing answers straight into your Answer Library |
After parsing, the result shows how many questions were found and which columns the questions and answers were read from. If the wrong columns were picked, choose them manually and scan the file again. There is no need to re-upload.
Turn on "This questionnaire is already answered" when you upload a questionnaire you have completed before: its answers seed the Answer Library so your very first live questionnaire already has something to match against.
Reviewing answers
The review surface has a rail of questions on the left and one answer editor on the right. You work through the questions in sequence.
Each question in the rail carries up to three signals, kept strictly separate:
- Approval is shown in colour: a green check once an answer is approved.
- Provenance is shown by an icon for where the answer came from: your library, AI, or written by hand.
- Attention is an amber triangle for a match that is not confident, or an AI answer with no supporting evidence, that you should read carefully before approving.
Filter the rail to Needs review, Needs attention, Approved or All questions. Editing an answer automatically withdraws its approval until you approve it again, so the exported answer is always one you have vetted.
Press ⌘↵ (or Ctrl+↵ on Windows) to approve the current answer and jump to the next one.
Provenance
| Icon meaning | Where the answer came from |
|---|---|
| From your answer library | A previously approved answer matched this question |
| AI generated | Drafted by AI auto-fill from your organisation's data |
| Written manually | Typed or edited by a person |
| Not answered yet | No answer has been provided |
AI auto-fill
Auto-fill drafts answers for the still-unanswered questions using your organisation's own data (policies, controls and previously approved answers) as context. It is optional and streams its progress; you can stop it at any time, and everything generated so far is kept.
Auto-fill never overwrites a matched, hand-written or approved answer, and when it finds no supporting evidence for a question it says so rather than inventing one. AI auto-fill draws on your monthly AI request quota.
Exporting
Export produces an XLSX or CSV of the questions and answers to send back to your customer.
By default the export includes only approved answers, so an unreviewed draft never reaches a customer's security team. Turn on Include unapproved answers only when you deliberately want drafts in the file.
Answer Library
The Answer Library holds every answer you have approved, matched against future questionnaires so the same question is never answered twice.
- Vetted answers: the number of approved answers available for reuse.
- Reuses: how many times a library answer has pre-filled a later questionnaire.
- Questionnaires answered: questionnaires completed so far.
Edit a library answer to keep it accurate — editing rewrites how it is matched, so future questionnaires get the corrected version. Archive an answer to stop it pre-filling questionnaires; it can be restored later. Archiving is the library's retirement mechanism: there is no delete, so a vetted answer is never lost by accident.
How is this guide?
Vendors
Vendors track the third-party suppliers and service providers your organization depends on, so you can score their risk, capture evidence, run questionnaires, and keep assessments on a recurring schedule.
Incidents
Record and manage security and data incidents from detection through to closure — track severity, build a timeline, link the assets, risks and vendors involved, and manage GDPR breach-notification deadlines.