For security teams answering inbound vendor reviews.

Security questionnaires, answered from your policies.

SIG, SIG Lite, CAIQ, or a prospect's custom spreadsheet. Upload your security policies, import the questionnaire, and review drafts that cite the exact source passage.

No credit card. No answer library to build first.

The problem

Every prospect sends the same 200 questions in a different format.

Security reviews arrive as SIG workbooks, CAIQ spreadsheets, and homegrown Excel files with merged cells. The answers live in your ISMS policies, your SOC 2 report, and the last five questionnaires someone on your team filled in by hand. Each new review means finding those answers again, under a deal deadline, with legal exposure if you overstate your posture.

Answer-library tools ask you to spend weeks curating a Q&A bank before they help. Mattercite skips that step: it reads the policy documents you already maintain and drafts each answer with a citation, so your reviewer verifies instead of rewrites.

Formats

The questionnaires you actually receive.

QuestionnaireWhat it isHow Mattercite handles it
SIG / SIG LiteShared Assessments standardized information gathering questionnaire, typically a large Excel workbookImport the workbook as received. Question numbering and section headers are stripped, only the questions remain.
CAIQCloud Security Alliance Consensus Assessment Initiative Questionnaire for cloud vendorsImport as Excel or CSV. Answers draft from your cloud security policies and prior CAIQ responses.
Custom vendor reviewsA prospect's own security spreadsheet or documentPaste it or drop the file: Excel, CSV, Word, or PDF. Rows that already contain answers import as answered.

Why it holds up

Answers a security reviewer can defend.

  • Cited, not asserted. Every answer carries the source file and page, with the supporting quote. Checking a claim takes seconds.
  • N/A over invention. If your documents do not support an answer, you get N/A, not a confident guess about controls you may not have.
  • Approval gate. Every answer is a draft until a human approves it. Nothing exports un-reviewed.
  • Current by construction. Update a policy and the answers follow. No answer bank drifting out of date.

Questions

The short version.

Does Mattercite handle SIG and SIG Lite questionnaires?

Yes. Import the SIG or SIG Lite file in the format it arrived (Excel, CSV, Word, or PDF), and Mattercite drafts each answer from your uploaded policy documents with a citation to the source passage.

What if my policies do not cover a question?

The answer comes back as N/A instead of being invented. You can add the missing document, write the answer yourself, or use the flagged Recommend feature that drafts from common practice and requires your validation.

Will my security documents be used to train AI models?

No. Documents stay inside an isolated workspace on AWS, are never used to train models, and are never shared across workspaces. See the security overview and our subprocessor list.

Can I reuse answers from questionnaires we answered before?

Yes. Upload prior completed questionnaires as source documents, or import an existing Q&A list as CSV or Excel. Mattercite uses both alongside your policies.

The next security review does not have to eat a week.

100 questions on us. No credit card.