Vendor Security Questionnaire (SIG / CAIQ) review
Vendor security questionnaire (SIG / CAIQ-style) with NIST CSF + ISO 27001 baseline.
Review your document — free → See a sample report- 7 document-specific checks
- + 102 general checks
- Nothing uploaded
- Free forever (MIT)
What it checks
Information security policy / governance
VSQ must confirm a written information security policy approved by management.
Critical · PRV-027
Access control — role-based, least privilege, MFA
VSQ must describe access control: RBAC, least privilege, MFA, and quarterly access reviews.
Critical · PRV-028
Encryption at rest and in transit
VSQ must confirm encryption at rest and in transit with stated algorithms.
Critical · PRV-029
Audit / certifications — SOC 2 / ISO 27001
VSQ must identify current third-party audits / certifications and provide a contact for report distribution.
Critical · PRV-030
Vulnerability management + penetration testing
VSQ must describe patch / vulnerability management cadence and annual third-party penetration testing.
Critical · PRV-031
Incident response + breach notification SLA
VSQ must describe the incident-response process and breach-notification SLA to customers.
Critical · PRV-032
Subprocessor / fourth-party disclosure
VSQ must list material subprocessors / fourth parties and their function.
Warning · PRV-033
Every run also applies 102 general checks that belong to any agreement: structure, parties and signatures, defined terms, cross-references, dates, amounts, and one-sided terms.
Often reviewed with
How it works
- Open vaulytica.com — no account, nothing to install.
- Drop your PDF or DOCX. The document type is detected and only the checks that belong to it run, inside your browser tab.
- Get a Word report in which every finding quotes the clause and cites the rule and source behind it — one of 1,825 checks across 268 document types.
More privacy & data protection documents
- Biometric Data Consent (BIPA-style)
- Children's Privacy Notice (COPPA)
- Cookie / Tracking Notice
- Data Sharing Agreement (Research / Inter-Agency)
- DPA — CCPA Service Provider (CPRA-aligned)
- DPA — Controller to Processor (EU/UK)
- DPA — Multi-State US (CCPA, VCDPA, CPA, CTDPA, UCPA, TDPSA, OCPA, DPDPA)
- DPA — Processor to Sub-Processor (EU/UK GDPR)
- Data Protection Impact Assessment (GDPR Art. 35)
- Data-Incident Notification Template
- Privacy Notice (GDPR)
- Privacy Notice (US / CCPA)
- Privacy Policy Linter
- Records of Processing Activities (GDPR Art. 30)
- EU Standard Contractual Clauses — Module 2 (Controller to Processor)
- EU Standard Contractual Clauses — Module 3 (Processor to Processor)
- SMS / Telemarketing Consent Disclosure
- UK International Data Transfer Addendum / IDTA
- Vendor Security Addendum