Skip to content
SECQON

Answer security questionnaires from your own scan evidence

A prospective customer's security questionnaire lands, and half the questions ask about things you have never measured. SecQon's Security Questionnaire Pack re-presents a real scan of your internet-facing assets as 42 answers in the style of the SIG Lite and CAIQ questionnaires. Answers come from what the scan observed, and the questions no external test can answer are marked as such, with a note on who in your company can.

The problem

A deal is waiting on a spreadsheet of security questions, and you do not know how to answer the ones about vulnerability management or TLS without guessing.

You want to answer honestly, but a blank or a "we believe so" reads badly to a buyer's security team.

The same questions come back from every enterprise customer, and you are rewriting the answers from memory each time.

How SecQon helps

What SecQon does not do here

  • The pack answers questions about your internet-facing assets only. For the 14 questions it marks as not externally assessable, you still write the answer.
  • It is not a certification and does not replace a SOC 2 report or ISO 27001 certificate if a buyer requires one.
  • An optional language model may rephrase answered rows for readability. Rewrites that add numbers, links or stronger claims are discarded, and the pack says when wording was rewritten.
  • A questionnaire that asks about business-logic testing or human-led penetration testing needs a truthful "no" from us: we do not do either.

The plan we suggest

Starter $49 per month

Answering a customer security questionnaire.

1 verified asset, add more for $25 each (up to 4)

Choose StarterCompare all plans

The checks that matter for this

  • TLS & certificates

    Certificate trust and expiry, and whether your server still accepts TLS 1.0 or 1.1.

  • Security headers & cookies

    Missing or ineffective HSTS, CSP, clickjacking, nosniff and Referrer-Policy headers, plus cookie flags.

  • DNS & email security

    SPF, DMARC, CAA and DNSSEC — the records that stop spoofed email and mis-issued certificates.

  • Exposed ports & services

    36 high-risk TCP ports — databases, container control planes, remote admin — checked with one connect each.

Questions people ask

Which plan includes the questionnaire pack?

Starter and above. Free shows findings but has no written report or questionnaire pack.

Can I paste the answers straight into a customer's spreadsheet?

That is what it is for. The pack follows the question families used by SIG Lite and CAIQ, and every answer is derived from your scan, so you can copy it across and attach the dated report.

What happens if a check could not run on my site?

The question it would have answered is marked not assessed, with what would assess it. A check that could not complete never produces a "yes".

Does it answer questions about encryption at rest or MFA?

No. Nothing outside your systems can see those. The pack marks them as not externally assessable and names who in your company can answer.

Is AI writing my answers?

The answers come from the scan evidence. A language model may optionally rephrase answered rows; any rewrite that adds a number, a link or a stronger claim is discarded, and rewritten wording is labelled.

Last reviewed on 24 Sep 2026.

See what a scan finds on your own asset

Free for one verified asset, no card needed. Paid plans add the written report, more assets and deeper scans.

Start freeCompare plans