The engine that answers your clients' supplier security questionnaires and ISO/IEC 27001:2022 evidence — same-day, from live infrastructure telemetry, with a human signing off anything the AI isn't sure about. Hand back the buyer's own workbook, or a proof pack the buyer can verify. Cyber Essentials v3.3 built in.
Not sure what questionnaires already cost you? Work it out in a minute →
How it works
An open-source collector runs inside your estate and strips secrets, hostnames and PII locally — only sanitized, pseudonymized evidence ever leaves. Adapters for Trivy, Entra, Okta, Google Workspace, PingOne and JumpCloud.
Audit the collector on GitHub →Pass/fail verdicts are computed by deterministic rules — the 14-day patching window, global MFA scope — never by an AI. Each verdict records which rule decided it and which version of that rule, so the answer stays derivable a year from now.
AI drafts the auditor-grade narrative, citing the individual telemetry facts behind it and the matching framework policy. Low-confidence drafts are flagged into a review queue for human sign-off, with a full audit trail of who approved what.
Return the buyer's own workbook, filled in — or a proof pack they can verify themselves without an account. Anything nobody could answer comes out as a ranked list of work you can quote for.
Compliance calls are rule-based code, never an LLM's opinion — and every verdict carries the version of the rule that produced it.
Drop in an Excel, PDF, Word or CSV questionnaire — we pull out the questions and triage each one. The file is parsed in your browser and never leaves it.
Buyers want their own spreadsheet returned, not a PDF. Approved answers are written into the original .xlsx — its formatting, dropdowns and other sheets untouched — in your browser.
Every export carries a content hash and a verification link. The recipient opens it, recomputes the hash in their own browser, and sees who issued the pack and when. No account, no login.
Questions the engine could not answer are grouped by cause and ranked by how many answers each fix unblocks — remediation scope you can put on a quote, straight out of the run.
Upload a questionnaire and we say whether that template — or a revision of it — has come through before, so you are not mapping the same buyer's spreadsheet twice.
Triage reports how many of the incoming questions your team has already answered here, and offers back the exact answer a person chose — kept separate from what merely looks similar.
ISO/IEC 27001:2022 Annex A and Cyber Essentials v3.3 built in.
Flagged drafts require audit-trailed sign-off before they ship.
Import your own or your client's policy documents; drafted answers cite them alongside the built-in corpus, with their real review dates.
Row-level security in the database, not just app code.
Sign in with Google or Microsoft — no new passwords, and removing someone ends their session immediately, not at the next expiry.
What comes out of a run
What the buyer sees at securevoo.com/v/…
Illustrative. The hash is published with the rule for recomputing it, so a recipient can check the pack in any language, years later, without us — and the page shows them no answers, only whether the document is the one we issued.
Trust you can verify
PostgreSQL row-level security on a non-owner role — a missing filter can't leak data. Verified by adversarial tests run against production.
The agent that runs on your machines is published under MIT — read exactly what leaves your estate before you install it.
Answers draft from telemetry inside an enforced freshness window; stale or missing evidence fails closed instead of guessing.
A proof pack publishes a SHA-256 over its own bytes and the rule for recomputing it, so a recipient can check it in any language, years later, without us.
Every verdict is stamped with the deterministic gate that decided it and that gate's version — change a rule and packs already issued still say what they were written under.
Your security team's first question — “how do you handle our data?” — is answered on a single Security & Trust page.
A run is one completed questionnaire or assessment — the £500–£2,500 billable event you already charge for. Your run cost is £12–£15; keep the spread. Invoiced, VAT excluded.
£249 / mo
3 workspaces · 10 runs/mo · +£69/ws · +£15/run
Any-format SAQ intake · deterministic verdicts · evidence bundles · review queue.
£649 / mo
10 workspaces · 40 runs/mo · +£59/ws · +£12/run
Everything in Boutique · custom policy imports · per-tenant API keys for CI.
£1,299 / mo
25 workspaces · fair-use unlimited runs
Multi-client switcher · priority support · volume answer-runs across your book.
See full pricing →One urgent questionnaire? Same-day Emergency Unblock →Work out what questionnaires cost you today →
FAQ
If your consultants burn days on client security questionnaires, run them through Securevoo and review evidence-backed answers instead of writing them. See how it works for consultancies →
Request a demo