We use cookies and similar technologies to improve your experience and analyse usage. By continuing you agree to our Privacy Policy.

    VendorLens

    A security questionnaire alternative that uses the answers you already wrote

    You answer the same 200-question security questionnaire every quarter, in a different spreadsheet format each time. The answers barely change.

    VendorLens lets you publish your security posture once — controls, policies, certifications, subprocessors — and direct buyers to a trust portal. Most questionnaires can be retired or shrunk to a handful of buyer-specific questions.

    A security questionnaire alternative that uses the answers you already wrote — VendorLens trust portal screenshot

    Use cases

    Pre-empt the questionnaire

    Send the trust portal link with your proposal. Many buyers will not need a separate questionnaire at all.

    Answer once, reuse forever

    Structured sections cover the questions buyers actually ask. Update them in one place.

    Reduce security review time

    Buyers self-serve answers and download policies without pinging your security team.

    How it works

    1

    Map your answers to sections

    Use the built-in sections (Security Practices, Data Protection, Incident Response, etc.) or add your own.

    2

    Attach the supporting docs

    SOC 2, pen test summary, BCP, DPA — link them directly under the relevant section.

    3

    Publish the trust page

    Send the link instead of waiting for the next questionnaire.

    4

    Track which answers buyers read

    The audit log shows which sections and documents are viewed most.

    Manual process vs VendorLens

    TopicManual processWith VendorLens
    Per-deal questionnaireRe-answer 200 questions in a new spreadsheetSend one trust portal link
    Answer consistencyDifferent answers across dealsOne canonical answer per topic
    Time per dealDays to weeksMinutes
    ReusabilityEach spreadsheet is throwawayEvery answer compounds

    Frequently asked

    Will this completely replace security questionnaires?

    For most small and mid-market deals, yes. A published trust portal answers the questions that 80% of questionnaires actually care about — encryption at rest and in transit, access controls, incident response, subprocessor disclosure, certifications — and once a buyer has the underlying documents in hand, the questionnaire often becomes a formality or gets skipped entirely. For regulated industries (financial services, healthcare, government) you will still occasionally see formal SIG, CAIQ or VSAQ questionnaires that have to be returned in their exact format. Treat the portal as the source of truth: answer the questionnaire by copying from the canonical answers on your trust page rather than rewriting from scratch each time.

    Can I export my answers?

    You can copy answers from any trust page section directly into Excel, Google Sheets, Word or a buyer-supplied PDF. The section content is plain text with light formatting and translates cleanly into any questionnaire format. A bulk CSV export of all sections is on the near-term roadmap. For teams handling a heavy volume of long-form questionnaires, the recommended workflow today is to keep your canonical answers on the trust page, generate a versioned "questionnaire pack" PDF from the dashboard once per quarter, and use that pack as the input when a buyer-specific questionnaire actually does come in.

    Does VendorLens auto-fill SIG, CAIQ or VSAQ?

    Not yet. The current product focus is making your answers buyer-discoverable on a trust page so that the majority of questionnaires never reach your security team in the first place. Auto-fill of standard frameworks (SIG Lite, CAIQ, VSAQ) is on the roadmap and is the most common request from vendors above ~200 employees. In the meantime, the structured sections on your trust page are explicitly modelled on the topics those frameworks cover, so cross-referencing a frameworks-style questionnaire against your portal is mechanical rather than creative work.

    What about buyer-specific questions the portal cannot pre-answer?

    Every published trust page has a built-in "Request information" workflow for the inevitable buyer-specific questions — usually edge cases around data residency, support hours, custom contract terms, or integration with the buyer's SSO. Requests land in your dashboard with the buyer's contact details and the question, you reply once, and the answer is stored against the request in the audit log. Over time the most common ad-hoc questions tend to surface a missing section on the public trust page, and you can promote the answer from "answered in a request" to "documented for everyone" with a single click.

    Ready to publish your trust center?

    Start free, or talk to us about the design partner program.