Compliance

How do you handle customer security inquiries?

How to answer this security questionnaire question, with an expert response your security or GRC team can adapt.

Expert answer

Provide a defined channel for security questionnaires and inquiries, backed by a trust center with your certifications, policies, and documentation. This lets you respond quickly and consistently.

What the security reviewer is checking

This meta-question — you are answering it inside the very process it asks about — checks whether security responsiveness is an operating function or a favor. Reviewers want defined intake channels (a security contact address, a trust center, a support path that routes security topics correctly), realistic response commitments, and self-service access to standard artifacts like audit reports and policies so routine diligence does not require meetings. They also probe the edges: how you handle vulnerability reports from customers or researchers, whether ongoing questionnaires and annual reassessments are supported, and who fields the technical follow-up call when written answers are not enough.

Example response you can adapt

This is an illustrative template, not a real vendor's security posture. Replace every claim with what is actually true for your organization before submitting it.
Security inquiries have a dedicated path with committed response times. Our trust center provides self-service access to our SOC 2 Type II report, penetration test summary, policies, and subprocessor list — most artifacts are available instantly under click-through NDA, so standard due diligence needs no back-and-forth. Security questionnaires submitted through the trust center or to our security contact address are acknowledged within one business day and completed within five business days for standard formats (SIG, CAIQ, and custom spreadsheets), with complex assessments scheduled against a committed date. Technical follow-ups are handled by the security team directly, including architecture review calls with your assessors when written responses are insufficient. Vulnerability reports from customers or researchers go to our disclosure address, are acknowledged within two business days, and are triaged under the same severity SLAs as internal findings. Annual reassessments and continuous monitoring requests are supported, and customers can subscribe to trust center updates for new audit reports and subprocessor changes.

Evidence reviewers expect you to attach

  • Trust center URL and its artifact index
  • Documented response SLAs for security inquiries and questionnaires
  • Vulnerability disclosure policy
  • Sample completed questionnaire (SIG or CAIQ), shareable under NDA

Follow-up questions reviewers ask next

  • What is your turnaround time for a full custom security questionnaire?
  • Can our assessors get a technical call with your security team?
  • How do we obtain your SOC 2 report and penetration test results?
  • How are we notified of subprocessor changes or new audit reports?
  • Where do we report a suspected vulnerability in your platform?

Answer every security questionnaire in minutes

Wolfia drafts accurate, cited answers to security questionnaires and RFPs from your existing documentation. See it work on your own questions.Book a demo