Magrios / Knowledge / enterprise / The security questionnaire and the early-stage A

The security questionnaire and the early-stage AI vendor

Guide · enterprise · 3 min read · last verified 2026-07-22

Reviewed before publication Editorial board Independent commercial review
In shortHow buyers should read an early-stage vendor's security questionnaire, and how an honest early-stage vendor should answer one — with Magrios's own published gaps as the worked example.

An early-stage AI vendor will fail parts of any standard security questionnaire: no SOC 2, no dedicated security organization, hosting in a single region. None of that is automatically disqualifying. A useful review separates controls that exist and are tested from certifications that attest to them, prices each gap against the purchase's actual risk tier, and treats candour about what is missing as evidence of maturity rather than proof of its absence. What follows is written from both sides of the table: Magrios is an early-stage vendor that publishes its own gaps, so the vendor-side advice here is practiced, not theoretical.

Why do standard questionnaires misfire on young vendors?

The standardized instruments — the Shared Assessments SIG, the Cloud Security Alliance's CAIQ — were designed to compare mature organizations. Hundreds of items presume dedicated functions: a CISO, an internal audit calendar, a vendor-management office. Scored literally, they reject every early-stage vendor on earth. Waived wholesale, they protect nothing. The workable middle is substance scoring: for each item that matters at your risk tier, accept either the attestation or the named, verifiable control behind it.

What is a vendor risk tier explains how to decide which items matter. For a tool that reads only public data, the list is shorter than the questionnaire.

What is the difference between certifications and controls?

A SOC 2 report is an auditor's attestation that stated controls operated over a period. It is valuable, expensive, and trailing — the controls exist first, the report follows later. Which means the absence of the report is not the absence of the controls, and the review's job is to tell those apart.

| Questionnaire item | Mature-vendor answer | Acceptable early-stage answer |

|---|---|---|

| Certification | SOC 2 Type II report | A public statement of what is missing, plus the controls below |

| Tenant isolation | Covered in audit scope | Fail-closed design described plainly, with a dedicated automated test suite |

| Access control | Access-management policy suite | Deny-by-default roles, owner-only billing, authorization tests on every change |

| Data protection | DPA and data-flow mapping | A one-sentence input surface; payment data held by the payment providers |

| Availability | Multi-region SLA | Single region stated plainly, with automated backups and restore verification |

The right-hand column is not hypothetical: it is Magrios's current answer set, published on its trust page. It appears here because the honest early-stage answer should be a real, inspectable thing rather than a template.

What is the candour test?

The strongest single signal in an early-stage review costs nothing to run: does the vendor volunteer what it lacks? A vendor that says “no, we do not have that yet — here is what exists instead” has handed you an auditable statement you can hold them to. An answer set with no noes in it is advertising with a signature line.

The same test runs in the product direction. A tool that visibly refuses to answer beyond its evidence — that reports “no public evidence found” instead of improvising — will tend to fill in your questionnaire the same way. Refusals are a trust signal, not a weakness; refusals and receipts makes the fuller argument.

How should an early-stage vendor answer?

Four rules, each practiced here:

Which gaps should still stop a deal?

Tier-dependent, but some floors hold at every stage. Walk away if the vendor will not name its subprocessors, cannot show that tenant isolation and access control are tested rather than merely described, handles payment data itself without certification, or discloses gaps only when cornered. For a public-data-only research tool, a missing SOC 2 is survivable; missing isolation tests are not. And if enterprise rollout mechanics matter to your deployment, verify what is real versus roadmap on identity before the contract assumes it — SSO vs SCIM covers what buyers actually need there.

The procurement question set folds these floors into a sendable list.

Frequently asked questions

Can I buy from a vendor without SOC 2?

Yes, when the risk tier supports it. SOC 2 is an attestation that controls operated; the controls can exist and be tested without the report. For a public-data-only tool, accept named compensating controls — tested tenant isolation, deny-by-default access, provider-held payment data — and treat unprompted disclosure of the gap as a maturity signal.

How should an early-stage vendor answer a security questionnaire?

Answer no as no, and attach the compensating control to every no. Date nothing unscheduled — “planned” without a date is decoration. Publish what you can on a public trust page, so answers predate any single deal. A questionnaire is a signed document; padded answers become misrepresentations with your signature under them.

Which questionnaire items are non-negotiable at any stage?

Subprocessors named. Tenant isolation and access control tested, not merely described. Payment data held by payment providers unless the vendor is certified to hold it. And gaps disclosed without cornering. A vendor can be early-stage on certifications and still meet all four; a vendor that fails them is not early — it is unready.

Further reading — chosen for this article
Entities in this research
Magriossecurity questionnaireSOC 2SIG questionnaireCAIQcandourtenant isolation
Related knowledge

What is a security questionnaire? A practical definition · shared entities

What Is a Paper Process? A Practical Definition · shared entities

Vendor risk assessment for AI-powered market intelligence tools · shared entities

Single-Tenant vs Multi-Tenant: What Enterprise Buyers Are Really Asking For · shared entities

Recently updated

Magrios vs Athena · 2026-07-22

What is AI share of voice? A practical definition · 2026-07-22

What is Citation surface? A practical definition · 2026-07-22

Magrios vs Writesonic · 2026-07-22

Where does your brand stand?
Check your AI visibility free — real evidence, not a score.
Check my visibility or run the full analysis →