vaulytica

Vendor Security Questionnaire (SIG / CAIQ) review

Vendor security questionnaire (SIG / CAIQ-style) with NIST CSF + ISO 27001 baseline.

Review your document — free → See a sample report

What it checks

Information security policy / governance

VSQ must confirm a written information security policy approved by management.

Critical · PRV-027

Access control — role-based, least privilege, MFA

VSQ must describe access control: RBAC, least privilege, MFA, and quarterly access reviews.

Critical · PRV-028

Encryption at rest and in transit

VSQ must confirm encryption at rest and in transit with stated algorithms.

Critical · PRV-029

Audit / certifications — SOC 2 / ISO 27001

VSQ must identify current third-party audits / certifications and provide a contact for report distribution.

Critical · PRV-030

Vulnerability management + penetration testing

VSQ must describe patch / vulnerability management cadence and annual third-party penetration testing.

Critical · PRV-031

Incident response + breach notification SLA

VSQ must describe the incident-response process and breach-notification SLA to customers.

Critical · PRV-032

Subprocessor / fourth-party disclosure

VSQ must list material subprocessors / fourth parties and their function.

Warning · PRV-033

Every run also applies 102 general checks that belong to any agreement: structure, parties and signatures, defined terms, cross-references, dates, amounts, and one-sided terms.

Often reviewed with

How it works

  1. Open vaulytica.com — no account, nothing to install.
  2. Drop your PDF or DOCX. The document type is detected and only the checks that belong to it run, inside your browser tab.
  3. Get a Word report in which every finding quotes the clause and cites the rule and source behind it — one of 1,825 checks across 268 document types.
Review your document — free →

More privacy & data protection documents

Every document type →