Security · Vendor Reviews

What customers ask in security questionnaires, how to build an accurate answer bank and how to handle gaps honestly.

Last updated: October 2026. Written by Athar Ahmad, Certified Bubble.io Developer and Tech Architect, Simple Automation Solutions.

Quick answer

A security questionnaire is a list of questions a customer sends a supplier to assess how it protects information, covering governance, access control, data protection, application security, hosting, logging, backups, incident response, suppliers, privacy, people and certifications. A small vendor should document what it actually does, write short accurate answers, note gaps honestly, keep supporting documents and assign an owner to maintain the answer bank. Never overclaim or present a platform’s certifications as your own.

Key takeaways

  • Document what you actually do, area by area, before answering.
  • Write short, accurate answers, note gaps honestly and offer plans where realistic.
  • Keep policies, a supplier list and an architecture summary ready.
  • Distinguish platform attestations from your own controls.
  • Never claim certifications or practices you do not have.

What is a security questionnaire?

A security questionnaire is a list of questions that a prospective customer sends to a supplier to assess whether it handles information safely. Larger organisations, regulated firms and anyone sharing sensitive data with a vendor often require one before signing. For a small SaaS or studio, these questionnaires can arrive suddenly and block a deal, so being prepared is a real commercial advantage.

What do they usually ask about?

AreaTypical questions
Company and governanceWho is responsible for security? Are there written policies?
Access controlHow are users authenticated? Is multi-factor authentication used? How is access granted and removed?
Data protectionWhat data is stored, where, and how is it separated between customers? Is it encrypted in transit and at rest?
Application securityHow is the application developed and tested? How are vulnerabilities handled?
InfrastructureWhere is it hosted? Which providers are used?
Logging and monitoringAre actions logged? Who reviews logs?
Backups and continuityHow often are backups taken, and are restores tested? What is the recovery plan?
Incident responseWhat happens if there is a breach, and how are customers told?
SuppliersWhich sub-processors are used, and how are they assessed?
PrivacyHow are access, correction and deletion requests handled? Where is data processed?
PeopleIs staff background-checked and trained? Is access limited to those who need it?
CertificationsDo you hold SOC 2, ISO 27001 or similar?

How to prepare an answer bank

  1. Document your real practices. Walk through each area above and write down what you actually do.
  2. Write short, accurate answers in plain language, with a yes or no where possible and a sentence of detail.
  3. Note gaps honestly. If you do not do something, say so, and where possible say what you plan.
  4. Keep supporting documents ready: policies, a supplier list, an architecture summary, a backup description.
  5. Assign an owner who updates the answers regularly.
  6. Reuse the bank for each questionnaire, adapting where needed.

Example answer framing (illustrative)

QuestionHonest, specific framing
Do you use multi-factor authentication?“Yes for staff and administrator accounts. For customer users, it is [available / required / planned].” Say what is true.
How is customer data separated?“Each record is linked to a customer account and access is enforced by rules on the data layer. We test by trying to access one account’s data from another.”
Do you encrypt data?State what the platform and your configuration provide, in transit and at rest, and name your sources.
Do you have SOC 2 or ISO 27001?“No, not currently” if so, with a summary of the controls you do have and the platform’s own attestations clearly distinguished from yours.
What is your incident response process?Describe who decides, how customers are notified and how quickly, in line with contract and law.

The examples show the style, not what to say. Answers must reflect your reality, and overclaiming creates legal and commercial risk.

What should you do when a gap appears?

  • Be honest. Customers value candour more than a polished false answer.
  • Explain compensating controls.
  • Offer a plan and a date, if realistic.
  • Ask whether the requirement is mandatory or a preference.
  • Fix gaps that appear repeatedly, since they will keep costing deals.

What mistakes should you avoid?

  • Copying answers from a competitor or a template without checking.
  • Claiming certifications or practices you do not have.
  • Giving the platform’s attestations as if they were yours.
  • Different answers to different customers.
  • Leaving the questionnaire to whoever is free.
  • Never updating answers after changes.

How do we help?

Simple Automation Solutions builds apps with access control, key handling, logging and testing designed in, which makes honest answers easier, and we can help you assemble an accurate security summary for your product. We do not provide certification. Builds start at $3,500, and a $345 Discovery Sprint, credited toward the build, includes security requirements in the PRD. See our security guide, how multi-tenant architecture works and what maintenance involves.

Frequently asked questions

What is a security questionnaire?

A list of questions a customer sends a supplier to assess how it protects information, covering access control, data protection, application security, backups, incident response, suppliers and certifications.

How do I answer a security questionnaire if I am a small company?

Document what you actually do, write short accurate answers, note gaps honestly and keep supporting documents ready.

Do I need SOC 2 to answer yes to everything?

No. Many questionnaires can be answered well without certification. Be honest about what you hold and what you do.

Can I reuse answers between customers?

Yes, with an answer bank that you keep accurate and adapt where needed.

Should I mention my platform’s certifications?

Yes, but clearly distinguish what the platform provides from what you do in your own app and processes.

Facing a customer security review?

Email us what your product does and what the customer asked. We will help you prepare accurate answers and close real gaps.

Email info@sasolutionspk.com

Athar Ahmad, Certified Bubble.io Developer and Tech Architect, Simple Automation Solutions

About Simple Automation Solutions (SA Solutions)

Simple Automation Solutions is a Bubble.io development studio led by Athar Ahmad, a Certified Bubble.io Developer and Tech Architect. It builds web and mobile apps, client portals and SaaS products for founder-led businesses such as law firms, accounting firms, boutique agencies and consultants. Services include a free 30-minute Idea Audit, a $345 Discovery Sprint (a Product Requirements Document delivered within 24 hours, credited toward the build) and builds starting at $3,500. Website: sasolutionspk.com.

Simple Automation Solutions

Business Process Automation, Technology Consulting for Businesses, IT Solutions for Digital Transformation and Enterprise System Modernization, Web Applications Development, Mobile Applications Development, MVP Development