Pre-launch · working with a first group of design partners

Answer security questionnaires with the evidence attached.

Zerqis drafts answers from your own policies and puts a citation on every claim — the document, the section, the page. Where your evidence doesn’t support an answer, it says so instead of guessing.

We’ll return a fully cited draft within 24 hours. Free, we’ll sign your NDA first, and one person reads it. Exactly what happens to your file →

zerqis.io/respond/northwind-sig-lite

C.1.4 · Data Protection

Describe how data at rest is encrypted, including key management and rotation.

High · 0.91AI draft

All production data is encrypted at rest using AES-256 via AWS KMS with customer-managed keys1 Keys are automatically rotated every 90 days2

ApproveEditAssign

The reviewer’s screen. Hovering a citation marker highlights the source passage — verification costs zero clicks.

No customer logos yet — we’re pre-launch and won’t borrow credibility we haven’t earned. What we can show you instead:

Every answer is cited or refused
There is no third state. An answer without a source is never shipped.
Your evidence never trains a model
Retrieval is scoped to your tenant, and providers run under zero-retention terms.
The architecture is public
Threat model, data model and AI design are written down and reviewable before you commit.

The current workflow

A 280-question spreadsheet arrives, and a quarter of revenue waits on it.

You recognise most of the questions. You answered them four months ago, in a file you can no longer find, for a customer whose template was different.

20–40 hours

per review, across 4–6 people

Security answers most of it. Legal takes the DPA and sub-processor questions. Infra takes encryption and backups. Someone has to chase all three.

2–4 weeks

of deal latency

The questionnaire is rarely the bottleneck by itself. Waiting on the one person who knows the answer is.

Inconsistent answers

that become contractual exposure

You told one customer 30 days and another 90. Both were approved by a human. Nobody noticed until an auditor did.

How it works

Upload your policies once. Answer every questionnaire from them.

No template to fill in first, no content library to seed by hand. Zerqis reads the documents you already have.

  1. 1

    Add your evidence

    SOC 2, policies, DPA, pen test. Zerqis indexes them by section and page.

  2. 2

    Import the questionnaire

    Their spreadsheet, unchanged. We detect the question and answer columns and show you a preview.

  3. 3

    Review cited drafts

    Read the claim, check the source beside it, approve. Keyboard-only if you want.

  4. 4

    Export their file back

    Their template, their formatting, your answers in their answer column.

Evidence-first

Show the policy behind the answer.

Every sentence carries a marker. The marker points at a document, a section and a page — and the passage sits next to the answer, not behind a click.

zerqis.io/respond/…?q=E.1.1

E.1.1 · AI & Machine Learning

Do you maintain a documented inventory of all AI/ML models used in the product?

No answer generated — evidence is insufficient

No document in your evidence library describes an AI model inventory. The closest match (Information Security Policy §7) covers asset inventory but does not mention models.

Assign to ML EngineeringUpload evidence

What happens when the evidence isn’t there.

When your evidence doesn’t support an answer, Zerqis writes nothing.

Most tools will produce a confident paragraph regardless. In a security review that paragraph becomes a contractual representation — signed by you, on behalf of a control you may not have.

Zerqis returns the gap instead: what is missing, and who probably owns it. On a first questionnaire that is typically 10–18% of questions. It drops below 5% once your library is warm.

We’d rather answer fewer questions than answer one of them wrongly. If a competitor claims 95% coverage, ask to see the citations.

Getting answers out of other people

Send a review link to Legal. They don't need an account.

The 40 questions you can't answer alone are the ones that stall the deal. Assign them, and your colleague gets a page with their questions and nothing else.

  • No login, no seat

    A scoped link that expires. It costs you nothing and they learn nothing about the product.

  • Only their questions

    They see the twelve assigned to them. Not the project, not the other 268.

  • Their words, not the model's

    Zerqis shows what it found in your documents as a starting point. The reviewer is the source of truth.

  • Their draft survives a closed tab

    Answers save as they type.

zerqis.io/review/…
AC

Dhanush asked for your input

2 questions for Acme’s review with Northwind Bank

Saved

Do you notify customers before engaging a new sub-processor, and what is the objection period?

What we found in Acme’s documents

“Controller may object to a new Sub-processor within thirty (30) days of notice.”

Data Processing Agreement · p.9

Your response

Type your answer…

Trust Center

The fastest questionnaire is the one nobody sends.

Publish your certifications, policies and sub-processor list at trust.yourcompany.com. Prospects self-serve at 11pm without emailing anyone.

trust.acme.com
AC

Acme Corp

Trust Center

SOC 2
ISO 27001
GDPR
CCPA
SOC 3 Report 2026Download
SOC 2 Type II Report🔒 Request access
Penetration Test 2026🔒 Request access
  • Gate what should be gated

    SOC 2 and pen tests sit behind an access request with click-through NDA. Acceptance is recorded with the NDA version.

  • Approve in one click

    Requests arrive with the requester's company matched against your open deals.

  • Revoke instantly

    Every grant expires. Access is a link you can turn off, not a file you emailed.

  • Sub-processor changes, handled

    Subscribers are notified before you add one — the Art. 28(2) obligation most teams do by hand.

Consistency

Detect contradictory responses before an auditor does.

Answering the same question two different ways across two customers is an audit finding waiting to happen. Zerqis links every answer to its evidence, which makes the conflicts findable.

zerqis.io/library

Log retention period

12 months vs 90 days

Northwind Bank — SIG Lite

Security logs are retained for 12 months in hot storage and 7 years in archive.

Globex — CAIQ v4

Audit logs are retained for 90 days.

Both answers were approved by a human.

This is the part that compounds. After two years, your answer library is the record of how your company describes itself under scrutiny — every claim tied to the document that backs it, the person who approved it, and the date.

Zerqis also tells you what you cannot answer, and which document would fix it. Most teams find the gap list more useful than the answers.

zerqis.io/evidence/gaps
78%of a standard 280-question set is answerable from your evidence

AI model inventory and governance

Needs: AI Governance Policy

14 unanswered

Business continuity testing

Needs: BCDR test report

11 unanswered

Secure development lifecycle

Needs: Secure Development Policy

9 unanswered

What changes

The measure isn't hours saved. It's whether the deal closes this quarter.

Security teams don't get budget for convenience. They get it for removing a blocker in front of revenue.

Before and after Zerqis
TodayWith Zerqis
Find last quarter's answers across Slack, Drive and someone's memoryDraft from your policy library, cited to the page
Email Legal and waitSend a scoped review link; see when it's answered
Reformat into the customer's template by handExport their original workbook, formatting intact
Hope the answers match what you told the last customerContradictions surfaced before you send
Discover missing policies during the reviewSee the gap list before the questionnaire arrives

We’re not going to put a fabricated percentage here. We haven’t run enough real reviews to quote one honestly — and you’d be right not to believe it if we did. Send us a questionnaire and we’ll measure it on your data.

Questions we get

The things a security reviewer asks first.

Do you train models on our documents?

No. Your evidence is used to retrieve passages for your own answers and nothing else. Model providers run under zero-retention terms for inference, and every AI vendor we use is named on our own sub-processor list.

How is our data separated from other customers'?

Every record carries a tenant id, enforced in the application and again by row-level security in PostgreSQL as a second, independent check. Retrieval is filtered by tenant inside the search itself, not after it. The isolation tests run against a real database on every change.

What happens if the AI is wrong?

A human approves every answer before it leaves the product — there is no auto-send. Each claim shows the passage it came from, so checking is reading, not investigating. And where the evidence is thin, Zerqis declines rather than guessing.

Our questionnaires are ugly spreadsheets. Merged cells, three header rows.

That's the normal case. We detect the question and answer columns and show you a preview before anything is committed, so a bad parse is something you correct rather than discover later. On export we reopen your original file and write only into the answer column — merged cells, hidden sheets, formulas and formatting are left alone.

Can we use it without giving you our SOC 2 report?

Yes. Start with policies you'd share publicly and see how the drafts read. Gated documents can stay out of Zerqis entirely — coverage will be lower, and the gap list will tell you exactly by how much.

Are you SOC 2 certified?

Not yet — we're pre-launch. We're building toward Type I and will publish our own trust center on the same product. We'd rather tell you that than imply otherwise, and we understand if that rules us out for now.

What does it cost?

Design partners pay nothing while we're learning. Pricing after that starts at $500/month. We'd rather agree a number after you've seen it work on your own questionnaire.

Send us the last questionnaire you completed.

We’ll return a fully drafted response within 24 hours, with a citation on every answer pointing back to a page in your own policies — and an honest list of the questions your evidence can’t answer yet.

Free, and we’ll sign your NDA before you send anything. One person reads it, it doesn’t go through any model unless you ask, and it’s deleted on request or after 30 days. The full commitments. Redact whatever you like — we only need the questions.

Prefer to look around first? Open the product with sample data.