A 29-Question Security Assessment, Auto-Created for Every Vendor
Send a structured security questionnaire to any vendor, track their response, and approve or reject based on evidence — scoped per application, so a low-risk vendor and a critical one don't get the same blanket treatment.
Book a DemoSelect an application
A default 29-question security assessment is auto-created for it — no blank-slate setup.
Customize if needed
Edit questions, and the system tracks versions — even multiple active versions at once.
Send the form
Share a public link — the vendor fills it in with no Zeeks account required.
Review the response
Track status from submitted through under review to approved, rejected, or needs revision.
Every default form covers the same ground an enterprise security review would — not just a checkbox questionnaire. Each question carries a priority (critical / recommended / optional), a Yes/No or three-option response type, and a place for the vendor to attach evidence.
| Category | What it covers |
|---|---|
| Governance & Compliance | ISO 27001 / SOC 2 / HIPAA / GDPR / PCI DSS scope, formal security policy, audit cadence, data residency, cyber liability insurance |
| Identity & Access Management | Mandatory MFA, Privileged Access Management, access review cadence |
| Data Security | Encryption at rest/in transit, Data Loss Prevention, retention & disposal on termination |
| Application Security | VAPT cadence, API security controls, bug bounty / vulnerability disclosure |
| Cloud / Infrastructure | Shared responsibility model, SaaS SLA/uptime commitments |
| Network Security | TLS enforcement, DDoS/IDS/IPS/WAF controls |
| Incident Response | Documented & tested IR plan, breach-notification SLA, forensic readiness |
| Supply Chain | Software Bill of Materials, subcontractor/subprocessor disclosure |
| Security Training | Mandatory awareness training cadence |
| Business Continuity / DR | Documented & tested BCP/DR, RTO/RPO, last DR test results |
| Risk Management | Formal risk register and regular risk assessments |
Search and filter responses by vendor name, company, email, form, or status, with a score field per response for at-a-glance risk comparison.