• Fair Source · FSL-1.1-ALv2
  • Source Available
  • Local First
  • Invite-only Alpha

You sent the questionnaire. They sent it back. Now what?

A vendor security questionnaire is 100 to 400 rows of answers. Your job is to read every one and decide: is this credible? Is it complete? Do any answers contradict each other? Are the certification claims real, or copied from a template?

Today you do this in Excel. Scroll, skim, colour-code, hope you didn't miss anything. File it in a vendor folder. Tick the "vendor assessment complete" box.

A questionnaire returned and filed without review is theatre. A questionnaire read closely, with follow-ups on the weak spots, is where real risk surfaces.

What it does

Upload the returned questionnaire. Get a triage report.

Triage

Every row scored green, amber or red. Empty answers, evasive language and copy-paste fluff are flagged automatically.

Contradict

Row 47 says "we encrypt at rest." Row 132 says "disk-level encryption not used." The engine clusters related answers and surfaces conflicts a human would miss scrolling through 300 rows.

Verify

"We are SOC 2 Type II certified." The engine checks the AICPA registry. "ISO 27001 certified." It checks the ISO directory. Verified, not found, expired, or insufficient data to check, each with a date stamp.

Follow up

Red and amber rows become a short, specific follow-up questionnaire. Send it back. Get answers. Close the gap.

Export

A one-page review report your procurement team, your auditor, or your client can actually read. Methodology, per-row flags, confidence levels, evidence. Not a spreadsheet. A defensible assessment.

Local first

Runs on your machine. Not someone else's cloud.

The vendor's answers contain sensitive information about their architecture, their controls, their gaps. You shouldn't have to upload that to a SaaS platform to review it.

RepliSec runs locally. Local AI via Ollama, or no AI at all. Your vendor data never leaves your environment.

Engineering

The evidence layer.

This is what separates RepliSec from a script. A multi-pass evidence engine sits between raw input and final output.

Input
  → Pass 1  Rules          empty, evasive, generic, copy-paste
  → Pass 2  Patterns       known vendor evasion language, N/A misuse
  → Pass 3  Semantic       answer-question relevance, contradiction clustering
  → Pass 4  Verification   registry lookups, cross-reference checks
  → Evidence               what was checked, what was found, confidence, audit trail
  → Output                 scored rows + defensible report

A vibe-coded script does Pass 1 and maybe a crude Pass 3. RepliSec does all four and produces evidence.

Row 47: "We use industry-standard encryption"

  • Pass 1Generic language. "Industry-standard" matches evasion pattern #3.
  • Pass 2No specific cipher named (AES-256, ChaCha20, etc.).
  • Pass 3Answer does not specify algorithm, key management, or scope.
  • Pass 4N/A. No certification claim to verify.
  • ContradictionRow 132 claims "disk-level encryption not used." CONFLICTS

Confidence 0.78 Amber

Follow-up suggested

"Specify the encryption algorithm, key length, and scope. Confirm whether disk-level encryption is used, as Row 132 appears to contradict this answer."

You can't build that in a weekend. And even if you could, you wouldn't maintain the pattern library, the registry checkers, the clustering logic, and the format edge cases month after month.

Rigour, not just results.

Audience

Who is this for?

  • Fractional and virtual CISOs Reviewing vendor questionnaires for multiple clients, where your name is on the assessment.
  • GRC consultants and security advisors Who need to produce defensible review reports, not just gut-feel notes.
  • MSP and MSSP analysts Handling vendor assessment volume across customer portfolios.
  • Procurement and vendor management teams In mid-market organisations told to "do the cyber review" with no tool and no training.
  • PE and VC diligence analysts Who need a fast, structured read on a target's security posture from their returned questionnaire.
Vendor side

Back to answering questionnaires?

If you're on the seller side, answering questionnaires to win deals, RepliSec for vendors is what you want.

RepliSec for vendors
Early Access

Help shape the buyer side.

The review side of RepliSec is being built with the people who do this work every week. If you receive questionnaires and have to judge the answers, we'd like your input on what a defensible review actually needs to contain.

  • Receive preview builds
  • Test against your own returned questionnaires
  • Shape the review report format
  • Help shape the roadmap

No spam. We'll only use this to send Early Access details.

About

Created by The Impact CTO.

RepliSec was created by Michael Doody after more than twenty-five years leading technology organisations across FTSE 100, PE-backed and global software businesses.

The project demonstrates a practical approach to grounded AI, where governance, explainability and privacy are considered from the beginning rather than added afterwards.

The Impact CTO · hello@replisec.com