For security teams answering inbound vendor reviews.
Security questionnaires, answered from your policies.
SIG, SIG Lite, CAIQ, or a prospect's custom spreadsheet. Upload your security policies, import the questionnaire, and review drafts that cite the exact source passage.
No credit card. No answer library to build first.
The problem
Every prospect sends the same 200 questions in a different format.
Security reviews arrive as SIG workbooks, CAIQ spreadsheets, and homegrown Excel files with merged cells. The answers live in your ISMS policies, your SOC 2 report, and the last five questionnaires someone on your team filled in by hand. Each new review means finding those answers again, under a deal deadline, with legal exposure if you overstate your posture.
Answer-library tools ask you to spend weeks curating a Q&A bank before they help. Mattercite skips that step: it reads the policy documents you already maintain and drafts each answer with a citation, so your reviewer verifies instead of rewrites.
Formats
The questionnaires you actually receive.
| Questionnaire | What it is | How Mattercite handles it |
|---|---|---|
| SIG / SIG Lite | Shared Assessments standardized information gathering questionnaire, typically a large Excel workbook | Import the workbook as received. Question numbering and section headers are stripped, only the questions remain. |
| CAIQ | Cloud Security Alliance Consensus Assessment Initiative Questionnaire for cloud vendors | Import as Excel or CSV. Answers draft from your cloud security policies and prior CAIQ responses. |
| Custom vendor reviews | A prospect's own security spreadsheet or document | Paste it or drop the file: Excel, CSV, Word, or PDF. Rows that already contain answers import as answered. |
Why it holds up
Answers a security reviewer can defend.
- Cited, not asserted. Every answer carries the source file and page, with the supporting quote. Checking a claim takes seconds.
- N/A over invention. If your documents do not support an answer, you get N/A, not a confident guess about controls you may not have.
- Approval gate. Every answer is a draft until a human approves it. Nothing exports un-reviewed.
- Current by construction. Update a policy and the answers follow. No answer bank drifting out of date.
Questions
The short version.
Does Mattercite handle SIG and SIG Lite questionnaires?
Yes. Import the SIG or SIG Lite file in the format it arrived (Excel, CSV, Word, or PDF), and Mattercite drafts each answer from your uploaded policy documents with a citation to the source passage.
What if my policies do not cover a question?
The answer comes back as N/A instead of being invented. You can add the missing document, write the answer yourself, or use the flagged Recommend feature that drafts from common practice and requires your validation.
Will my security documents be used to train AI models?
No. Documents stay inside an isolated workspace on AWS, are never used to train models, and are never shared across workspaces. See the security overview and our subprocessor list.
Can I reuse answers from questionnaires we answered before?
Yes. Upload prior completed questionnaires as source documents, or import an existing Q&A list as CSV or Excel. Mattercite uses both alongside your policies.
The next security review does not have to eat a week.
100 questions on us. No credit card.