Triage
Every row scored green, amber or red. Empty answers, evasive language and copy-paste fluff are flagged automatically.
A vendor security questionnaire is 100 to 400 rows of answers. Your job is to read every one and decide: is this credible? Is it complete? Do any answers contradict each other? Are the certification claims real, or copied from a template?
Today you do this in Excel. Scroll, skim, colour-code, hope you didn't miss anything. File it in a vendor folder. Tick the "vendor assessment complete" box.
A questionnaire returned and filed without review is theatre. A questionnaire read closely, with follow-ups on the weak spots, is where real risk surfaces.
Every row scored green, amber or red. Empty answers, evasive language and copy-paste fluff are flagged automatically.
Row 47 says "we encrypt at rest." Row 132 says "disk-level encryption not used." The engine clusters related answers and surfaces conflicts a human would miss scrolling through 300 rows.
"We are SOC 2 Type II certified." The engine checks the AICPA registry. "ISO 27001 certified." It checks the ISO directory. Verified, not found, expired, or insufficient data to check, each with a date stamp.
Red and amber rows become a short, specific follow-up questionnaire. Send it back. Get answers. Close the gap.
A one-page review report your procurement team, your auditor, or your client can actually read. Methodology, per-row flags, confidence levels, evidence. Not a spreadsheet. A defensible assessment.
The vendor's answers contain sensitive information about their architecture, their controls, their gaps. You shouldn't have to upload that to a SaaS platform to review it.
RepliSec runs locally. Local AI via Ollama, or no AI at all. Your vendor data never leaves your environment.
This is what separates RepliSec from a script. A multi-pass evidence engine sits between raw input and final output.
Input
→ Pass 1 Rules empty, evasive, generic, copy-paste
→ Pass 2 Patterns known vendor evasion language, N/A misuse
→ Pass 3 Semantic answer-question relevance, contradiction clustering
→ Pass 4 Verification registry lookups, cross-reference checks
→ Evidence what was checked, what was found, confidence, audit trail
→ Output scored rows + defensible report
A vibe-coded script does Pass 1 and maybe a crude Pass 3. RepliSec does all four and produces evidence.
Row 47: "We use industry-standard encryption"
Confidence 0.78 Amber
"Specify the encryption algorithm, key length, and scope. Confirm whether disk-level encryption is used, as Row 132 appears to contradict this answer."
You can't build that in a weekend. And even if you could, you wouldn't maintain the pattern library, the registry checkers, the clustering logic, and the format edge cases month after month.
Rigour, not just results.
The review side of RepliSec is being built with the people who do this work every week. If you receive questionnaires and have to judge the answers, we'd like your input on what a defensible review actually needs to contain.
RepliSec was created by Michael Doody after more than twenty-five years leading technology organisations across FTSE 100, PE-backed and global software businesses.
The project demonstrates a practical approach to grounded AI, where governance, explainability and privacy are considered from the beginning rather than added afterwards.