Questionnaire answer bank
~40 common vendor-security questions with DRAFT answers and fill-in blanks. Copy, edit, delete anything that isn’t true.
SKU TS-SEC-01 · Instant digital ZIP
A Pre-SOC Vendor Security Deal Packet for SaaS and AI builders: ~40 draft answers, a public trust-page skeleton, subprocessor stub, and light SOPs. Templates you edit — not a certification. Calm docs. No sales call.
Digital ZIP · all sales final · educational templates only
Mid-pipeline. Buyer sends a CAIQ-style questionnaire. You don’t have an answer bank, a trust page, or a clear list of what you can (and can’t) claim yet. The founder becomes the bottleneck. This packet is a starting draft so you can organize responses and keep the conversation moving — then edit everything to match your real stack and have counsel/auditor review before you submit.
~40 common vendor-security questions with DRAFT answers and fill-in blanks. Copy, edit, delete anything that isn’t true.
A public trust / security page outline you can adapt and publish — no audit theater.
Subprocessor CSV, light access/offboarding SOP, incident-response one-pager (outline only), and an evidence index of what buyers often ask vs what this pack is / isn’t.
Not included: SOC 2 / ISO / HIPAA / PCI audit or attestation; penetration test; legal review; counsel; fake certifications; ongoing GRC monitoring.
SAMPLE — fictional company (“Northline Analytics”). Illustrative only. Not a certification claim. Edit every answer to match your real controls before sending.
Q: Describe how customer data is encrypted at rest and in transit.
A: [empty — deal waiting on founder]
Q: Describe how customer data is encrypted at rest and in transit.
A: DRAFT — edit Customer data at rest is encrypted using {{encryption_at_rest, e.g. AES-256 via our cloud provider’s managed disk encryption}}. Data in transit uses {{tls_version, e.g. TLS 1.2+}} for all public endpoints. Keys are managed via {{kms_or_provider}}. This draft must match your actual stack before send.
Clearly marked SAMPLE. Every draft must be edited to match your stack. See also preview.html.
SAMPLE
Q: Where is customer data stored?
Draft: Customer data for {{product_name}} is stored in {{cloud_provider, e.g. AWS / GCP / Azure}} in {{primary_region, e.g. us-east-1}}. We do {{or do not}} replicate to {{secondary_region_or_none}}. We do not store customer data on employee laptops as a system of record.
SAMPLE
Q: Do you enforce multi-factor authentication (MFA)?
Draft: MFA is {{required / encouraged}} for {{who, e.g. all employees with production or customer-data access}}. Customer-facing MFA is {{supported_via, e.g. TOTP / SSO IdP MFA}} on {{plans}}.
SAMPLE
Q: What is your employee offboarding process for access?
Draft: On termination or role change, we revoke access to {{systems_list}} within {{target_timeframe, e.g. same business day}}. Offboarding is tracked via {{checklist_or_ticket_tool}}.
This packet is an educational template pack to help you organize answers and drafts for vendor security questionnaires. It is not a SOC 2 (or other) audit, attestation, certification, penetration test, or legal/compliance advice. Using it does not make your company “SOC 2 certified” or “compliant.” Have qualified counsel/auditor review before you submit answers to customers. You are solely responsible for accuracy of any answers you send.
We do not claim this pack makes you “SOC 2 ready,” “certified,” “attested,” or “compliant,” and it does not guarantee you will pass any audit or questionnaire.
Instant ZIP after payment. No sales call. Edit every draft before you send it.
Get Pre-SOC Vendor Security Deal Packet — $99Digital ZIP · instant download after payment · TrustStack Pack · SKU TS-SEC-01 · all sales final / no refunds on digital goods.
This is an educational template pack — not a SOC 2 (or other) audit, attestation, certification, pen test, or legal/compliance advice. Using it does not make your company “SOC 2 certified” or “compliant.” You own accuracy of any answers you send; have counsel/auditor review before submitting to customers.
Delivery issues only: support@truststackpack.com (placeholder — confirm when domain is live)