Glossary
Security review glossary
Plain-English definitions of the terms that come up when customers review your security — the questionnaires, frameworks, and processes behind every vendor assessment.
- Security questionnaire
- A security questionnaire is a structured set of questions a prospective or existing customer sends to a vendor to evaluate how that vendor protects data and manages risk. It typically covers access controls, encryption, compliance certifications (like SOC 2 or ISO 27001), incident response, and data handling. Completing one is usually a prerequisite for closing a B2B deal.
- SIG questionnaire
- The SIG (Standardized Information Gathering) questionnaire is a standardized set of third-party risk questions maintained by Shared Assessments. It gives buyers a consistent, industry-recognized way to assess a vendor’s security, privacy, and resilience controls across many risk domains, instead of every company writing its own questionnaire from scratch.
- CAIQ
- The CAIQ (Consensus Assessments Initiative Questionnaire) is a standardized questionnaire from the Cloud Security Alliance (CSA) that lets a cloud service provider document which security controls it has in place. Its questions map to the CSA’s Cloud Controls Matrix (CCM), so buyers can assess a cloud vendor against a widely recognized control framework.
- Vendor security assessment
- A vendor security assessment is the process a company uses to evaluate the security and privacy risk of a third-party vendor — typically before signing a contract and periodically afterward. It usually combines a security questionnaire, a review of compliance reports and certifications, and sometimes evidence requests or a call, and it feeds the buyer’s third-party risk management (TPRM) program.
- SOC 2 vs ISO 27001
- SOC 2 and ISO 27001 are the two most common ways a company demonstrates its security posture. SOC 2 is an attestation report, produced by a CPA firm, on how well your controls meet the AICPA’s Trust Services Criteria. ISO 27001 is an international standard you get certified against, focused on establishing and maintaining an information security management system (ISMS). Buyers often accept either, and larger vendors pursue both.
- Trust center
- A trust center (or trust page) is a public-facing page where a company publishes its security and compliance posture — certifications like SOC 2 and ISO 27001, subprocessors, policies, and control summaries — so that prospective customers can self-serve answers before sending a security questionnaire. A good trust center deflects some review work by answering common questions up front.
Bring us your ugliest questionnaire
We’re onboarding a small group of design partners — certified teams on Drata or Vanta handling 10+ questionnaires a quarter. Watch the agent run the entire workflow live, on your real evidence — you approve every answer.
Get early accessor email hello@provebase.ai