The security questionnaire and the early-stage AI vendor
Guide · enterprise · 3 min read · last verified 2026-07-22
An early-stage AI vendor will fail parts of any standard security questionnaire: no SOC 2, no dedicated security organization, hosting in a single region. None of that is automatically disqualifying. A useful review separates controls that exist and are tested from certifications that attest to them, prices each gap against the purchase's actual risk tier, and treats candour about what is missing as evidence of maturity rather than proof of its absence. What follows is written from both sides of the table: Magrios is an early-stage vendor that publishes its own gaps, so the vendor-side advice here is practiced, not theoretical.
Why do standard questionnaires misfire on young vendors?
The standardized instruments — the Shared Assessments SIG, the Cloud Security Alliance's CAIQ — were designed to compare mature organizations. Hundreds of items presume dedicated functions: a CISO, an internal audit calendar, a vendor-management office. Scored literally, they reject every early-stage vendor on earth. Waived wholesale, they protect nothing. The workable middle is substance scoring: for each item that matters at your risk tier, accept either the attestation or the named, verifiable control behind it.
What is a vendor risk tier explains how to decide which items matter. For a tool that reads only public data, the list is shorter than the questionnaire.
What is the difference between certifications and controls?
A SOC 2 report is an auditor's attestation that stated controls operated over a period. It is valuable, expensive, and trailing — the controls exist first, the report follows later. Which means the absence of the report is not the absence of the controls, and the review's job is to tell those apart.
| Questionnaire item | Mature-vendor answer | Acceptable early-stage answer |
|---|---|---|
| Certification | SOC 2 Type II report | A public statement of what is missing, plus the controls below |
| Tenant isolation | Covered in audit scope | Fail-closed design described plainly, with a dedicated automated test suite |
| Access control | Access-management policy suite | Deny-by-default roles, owner-only billing, authorization tests on every change |
| Data protection | DPA and data-flow mapping | A one-sentence input surface; payment data held by the payment providers |
| Availability | Multi-region SLA | Single region stated plainly, with automated backups and restore verification |
The right-hand column is not hypothetical: it is Magrios's current answer set, published on its trust page. It appears here because the honest early-stage answer should be a real, inspectable thing rather than a template.
What is the candour test?
The strongest single signal in an early-stage review costs nothing to run: does the vendor volunteer what it lacks? A vendor that says “no, we do not have that yet — here is what exists instead” has handed you an auditable statement you can hold them to. An answer set with no noes in it is advertising with a signature line.
The same test runs in the product direction. A tool that visibly refuses to answer beyond its evidence — that reports “no public evidence found” instead of improvising — will tend to fill in your questionnaire the same way. Refusals are a trust signal, not a weakness; refusals and receipts makes the fuller argument.
How should an early-stage vendor answer?
Four rules, each practiced here:
- Answer no as no. A padded no reads as a yes, and a questionnaire is a document with your signature under it.
- Attach the compensating control to every no. “No SOC 2; isolation and permission floors are covered by automated tests that run on every change” is a complete answer. “No” alone is an invitation to disqualify you.
- Date nothing you have not scheduled. “Planned” without a date is decoration, and buyers have read it a hundred times.
- Publish what you can. A public trust page pre-answers half of most questionnaires and proves the answers were not drafted for one deal.
Which gaps should still stop a deal?
Tier-dependent, but some floors hold at every stage. Walk away if the vendor will not name its subprocessors, cannot show that tenant isolation and access control are tested rather than merely described, handles payment data itself without certification, or discloses gaps only when cornered. For a public-data-only research tool, a missing SOC 2 is survivable; missing isolation tests are not. And if enterprise rollout mechanics matter to your deployment, verify what is real versus roadmap on identity before the contract assumes it — SSO vs SCIM covers what buyers actually need there.
The procurement question set folds these floors into a sendable list.