Someone posted this about an app they had built for their own industry, a small niche where everybody knows everybody, which most of that industry now uses daily:

… I built the whole thing with AI. I can’t sit down and write the code by hand.

In the same post they described who had turned up: “They are big. Over $100 million in revenue. They want me to build a portal for them plus apps.” A company that size does not sign anything without sending a spreadsheet first. A software security assessment questionnaire is a list of questions a customer’s side sends before they will buy, arriving with a deadline nobody discussed with you.

Three piles sort the whole form. What is already true, which is most of it. What has to change before the answer is yes. What you can defer with a date attached. A false yes is the only outcome worth avoiding, because those answers are often attached to the agreement afterwards.

Every platform answer on this page was read on 26 August 2026 from the vendor’s own documentation and from the questionnaire standards that publish theirs, then held up against what the same question turned out to be true of in the 26 AI-built applications read in June and July 2026; no customer’s form was filled in to write it.

Three guides ranking for this search were read in full on 26 August 2026, and all three are written for a company with a security function. One tells you to gather your strongest internal subject matter experts; another assumes you own firewalls, intrusion detection and a patch process. None of the three says what to write when the honest answer is that you do not have the thing being asked about, which is the row an owner gets stuck on.

Who actually sent this, and what they are trying to find out

The sender is usually procurement or a vendor risk function, one step removed from the person who wanted to buy your product. They are building a record that they asked, in a form their system can score. The thirteen rows this page sorts into a table are the ones that decide the outcome; the rest is filing.

A reviewer who is auditing you wants to find something. A reviewer who is filing you wants a complete set of answers with no blanks, because a blank gets the file sent back to them. Most of what reads as interrogation is a checklist someone has to close before the purchase order can move.

The form usually arrives out of a vendor due diligence software platform, which is why the deadline, the reminders and the scoring are automated even when a human wrote the covering email. A row marked failed is a scoring rule firing, and a scoring rule can be argued with.

The worry gets said out loud on the customer’s side. On 14 August 2026 a thread in r/HealthTech was titled Anyone else nervous about AI-generated healthcare apps skipping compliance?. You are being asked to prove you are the exception, by someone with no way to look at your code.

You may also recognise the form itself, because a handful of standard ones circulate. The CAIQ sits inside the Cloud Controls Matrix, which the Cloud Security Alliance’s Cloud Controls Matrix page describes as 197 control objectives structured in 17 domains, with the CAIQ offering “a simple set of ‘yes/no’ questions to assess cloud providers”; version 4.1 of the two is combined, and a provider can self-assess with the STAR Level 1 form and submit it to the STAR Registry. The SIG comes from Shared Assessments, and as of 26 August 2026 its own page at sharedassessments.org/sig returned a Microsoft Entra sign-in interstitial to an automated fetch, so nothing about the SIG’s current size is claimed here. Google’s VSAQ repository carries the banner “This repository was archived by the owner on Nov 25, 2022. It is now read-only”, and its README says “VSAQ is not an official Google product (experimental or otherwise); it’s just code that happens to be owned by Google.” The Vendor Security Alliance’s questionnaire is named the same way, because as of 26 August 2026 vendorsecurityalliance.org returned no readable body text to an automated fetch either.

Two of the four standard forms you are told to expect are therefore sign-in gated or archived, worth knowing before you hunt the canonical version of something your customer already sent you.

A customer’s questionnaire and an investor’s technical review ask overlapping questions for two different reasons, and what a technical reviewer opens first is its own subject.

The software vendor due diligence checklist, read from the side that has to answer it

Every result on page one for the software vendor due diligence checklist on 26 August 2026 was written for the person doing the assessing, and the titles promise the same shape. Six buckets, this page’s own grouping of what those forms ask, cover it: company information, financial standing, reputational checks, cyber, operational, and exit or continuity. From the assessor’s chair those are categories. From yours they are six different amounts of work.

  • Company information: who you are, where you are registered, how many people work there. A two-person company clears this in ten minutes and should say “two” rather than invent a team structure. Nobody is disqualified for being small at this row, only for being vague.
  • Financial standing: how long you have been trading and whether you will still exist in three years. If you are pre-revenue or single-customer, say so and let the customer decide. This bucket usually produces a contract term rather than a rejection.
  • Reputational: litigation, sanctions, adverse media. Almost always empty for an app built by its owner, and the fastest bucket to close honestly.
  • Cyber: the one this page is mostly about, and the only bucket where an app built with AI tools has a genuinely different profile from a normal supplier.
  • Operational: support hours, incident contact, uptime history, change management. Cheap to answer truthfully and cheap to improve, because most of it is a written commitment rather than a code change.
  • Exit or continuity: what happens to the customer’s data if you stop trading or they leave. An export path and a stated deletion period settle it.

Four of the six can be cleared on paper in an afternoon by an owner who cannot read code. The cyber bucket needs looking at the app, and continuity is the one people answer carelessly because it feels far away. Different forms use different bucket names, and the mapping is nearly always one to one.

The checklist a reviewer walks item by item is written out in full on its own page; this one reads the same ground from the side that has to answer.

What you can answer honestly today

Most of the form is already true. A managed platform hands a small app real answers at no cost: encryption in transit and at rest, a named region, a hosting provider with its own certificate, backups that exist, a named payment processor. Owners routinely defer rows they could have answered yes to that morning.

Start with where the data sits, because it is the row people guess at. Supabase’s regions page says the region you choose determines where your primary project data is stored, and adds that “Region selection is a data-location control, not proof of regulatory compliance”. The first half gives you a factual answer to the country question. The second stops you claiming more from it than it carries, which is the overreach a reviewer is trained to catch.

Defaults are what an app built with AI tools runs on. Vercel’s regions page, last updated 11 August 2026, lists 20 compute-capable regions behind more than 126 points of presence, and states that Vercel Functions default to running in the iad1 region, Washington, D.C., USA. If nobody changed that, the honest answer to “where is customer data processed” names two places rather than one. Filling in the platform rows from Vercel’s own documents is a page in its own right, because each certificate covers one narrow question about how the vendor runs its systems.

Your platform’s certificate is a real answer to the rows about your platform. Supabase’s SOC 2 documentation says the SOC 2 Type 2 report is available to Enterprise and Team Plan customers and is downloadable from the Legal Documents section in the organization dashboard. On a lower plan the honest sentence is that the platform holds the report and you cannot obtain a copy at your plan, which is a different answer from “no”.

The profile that gets sent one of these forms is more common than it sounds. Someone described themselves in public like this:

I am a special education teacher and the developer of a special education workflow application I have built on the Base44 platform.

An application handling children’s records, built by someone who works in that school system. Another owner wrote:

I’ve built a video compliance app that scans our video edits for each clients compliance failures and flags them when a rule is broken. It’s been incredibly valuable for us, but it’s becoming more expensive than I can justify at this point.

A third described their product’s reach without using the word security:

It is a complete suite that encompasses everything an EHS Manager, General Manager or consultant would need.

Three owners running compliance-shaped software on a builder, each one deal away from a spreadsheet, each able to answer the platform rows today from published documents. Which builders will commit contractually was asked plainly in r/specode on 17 August 2026, in a post titled Which no-code app builders will sign a HIPAA BAA?. Answer that class of row from the builder’s current page and quote the sentence you found, because the answer moves.

What you have to change before the answer is yes

Six rows account for nearly all of the honest noes on a small app, and two of them close with a setting rather than a project. The AxonBuild audits measured how often each bites.

The cohort behind those counts is fixed: 26 AI-built applications read in June and July 2026, with a finding ledger kept over the 21 third-party public repositories, as opposed to the five that were AxonBuild’s own projects, every finding confirmed against the code rather than pattern-matched.

Start with tenant isolation, the row a customer cares about most and the one an owner is least able to check. Nine of the 21 third-party apps in that ledger had a row-level security gap, counted from the 26-app cohort these figures come from. The row asks whether one customer can read another’s data, and the check is two accounts in two browser windows.

Secrets come next, and the size of the change is the part people get wrong. In the same ledger, 6 of the 21 third-party apps shipped a real secret, 3 of them permanently in the repository history. Rotation fixes the live key and leaves the old one in history, so the honest answer to “how do you store keys and secrets” covers current practice plus whatever cleanup the history needs.

Patching is the cheapest row on the form. Across all 26 applications in the cohort, 9 were still on a framework release carrying a publicly known hole a stranger could reach, and the fix was usually a one-line version bump. Close that row before you send the form back rather than after.

Personal data placement is the row that turns into a negotiation. In the 21-app ledger, at least 5 of the third-party apps had personal data sitting somewhere it should not have been: plaintext where the schema claimed otherwise, or a table with no isolation. “What personal data do you hold and where” is answered from the actual list of tables, buckets and logs.

If the product has an AI feature, expect a row about it, newer than the rest of the form. Among the 14 third-party applications in the cohort with an AI surface, 8 had untrusted text reaching the model’s instructions, which is how a stranger ends up steering what your feature says. For most apps built this year the answer is that users can influence it, and what you describe is the boundary you put around that.

Logging is where a platform default does the most useful work of any sentence here. The same Supabase SOC 2 documentation states that “Supabase sets Postgres connection logging to off by default for new projects.” A row asking whether database access is logged has a checkable answer rather than a guess. Nothing about the running app tells you which way it is set, and most owners have never opened it.

Two rows here look like settings and turn out to be documents. The row asking how long you keep customer data has no honest answer until a retention schedule exists, and writing one is its own job. The row asking what happens when a customer asks you to delete their data is answered by a deletion runbook, not by a sentence in a spreadsheet.

What you can defer without lying

A deferred row has four parts: the thing that is not true today, the date, the reason, and what you will send when it is done. Written that way it is a commitment a reviewer can file.

Security questionnaire rows routed to Today, Change first, or Defer with a date and four required details
An unqualified yes on a row you cannot check becomes a term in a contract you have not read yet.

Ask your buyer whether the completed form is attached to the agreement or incorporated by reference. Plenty of vendor contracts do exactly that, and if yours does, the row you guessed at is a warranty.

Three things are genuinely deferrable for a small supplier, with the honest caveat that the customer decides and this page does not.

The first is an independent test of the running app. One row on most of these forms asks for the findings of an outside review of the running app rather than a description of your own controls, and whether your app needs that review at all is a decision with its own page. A row that names a penetration test is asking for a test of the running app by someone outside your company, and the exact wording of that request decides which kind of test will be accepted.

The second is an attestation from a CPA firm. The AICPA’s page on the SOC suite of services describes SOC as a suite of service offerings CPAs may provide in connection with system-level controls, an examination somebody performs on you rather than a form you complete. That takes months and money, and a dated “not yet” is a normal answer from a supplier your size.

The third is a written programme: a policy set, a risk register, a training record. Cheap to start and impossible to backdate, so a date is the right answer.

Owners who go looking on their own find the awkward rows before their customer does. One of them wrote:

I’ve been doing a fairly detailed GDPR and data-governance review of a customer-facing app I’m building on Lovable, and I came across something I suspect quite a few users/founders may not have considered.

Which is why the AI row is worth reading twice. If your product sends customer text to a model provider, the form asks what that provider keeps, and the phrase you will meet is zero data retention, an arrangement where the provider does not store the inputs and outputs it processes for you. Neither large provider makes it automatic. OpenAI’s guide to your data says abuse monitoring logs “are generated for all API feature usage and retained for up to 30 days” by default, that the zero data retention controls “are subject to prior approval by OpenAI and acceptance of additional requirements”, that under it the store parameter for /v1/responses and /v1/chat/completions is always treated as false, and that endpoints including the Assistants APIs, Vector Stores, Fine-tuning and Batches are not eligible at all. Anthropic’s zero data retention article describes the agreement as one where Anthropic “does not store their inputs or outputs except where needed to comply with law or combat misuse or harm”, applies it to eligible APIs, to products accessed with a Commercial organization API key including Claude Code accessed through the API, and to Claude Code for Enterprise plans, and excludes the consumer plans. Both pages were read on 26 August 2026, and both vendors moved them to a new host within the last year, so recheck before you answer.

Your builder’s documentation draws the same line. Lovable’s security documentation makes the app owner, not the builder, responsible for meeting whatever security requirements the use case calls for, and singles out apps handling sensitive data or doing critical work. Of its Basic scan and Deep scan it says that “These tools help identify common security issues, but they cannot guarantee complete security.” A scan result is a useful sentence in an answer, and stops there.

Sometimes the ask goes past anything a form can hold. One founder in talks with a large buyer found the buyer wanted self-hosting, an audited control report and a promise that no data is retained, and their builder could offer none of the three. When the ask is that the app run on the customer’s own servers, the question stops being about the form and becomes which of your app’s layers can move and which cannot. A customer requirement is one of the five reasons owners give for leaving a builder, and it is the one that most often turns out not to require leaving.

Every row, and whether you can answer it today

The thirteen rows below cover what a customer’s form actually asks a small software supplier. The middle column is what tends to be true on day one, before anybody has changed anything.

The row on the formWhat is usually true on day one for an app built with AI toolsWhat you can check yourself in under a minuteVerdict
Where customer data is stored, and in which countryWhatever region the platform defaulted to. Supabase’s regions page, read 26 August 2026, calls region selection a data-location control rather than proof of complianceRead the region name in the project settings, then in your host’sToday
Encryption in transit and at restOn by default on every managed platform in common useCheck the site certificate, then quote the platform’s own encryption sentenceToday
Who on your side can reach production dataEveryone ever added, plus any AI tool handed a connection stringList the platform organization’s members and the database roles that existChange first
Whether one customer can reach another customer’s dataRow-level security gaps appeared in 9 of the 21 third-party apps in AxonBuild’s fixed 26-app study, read June and July 2026Sign in as two accounts in two windows and open the first one’s record from the secondChange first
How API keys and secrets are stored6 of those 21 apps shipped a live key, and for 3 of them it remains in the repository history, so rotation on its own does not close the rowSearch the repository for key, secret and tokenChange first where history is involved
Whether access is logged, and for how longSupabase’s SOC 2 documentation, read 26 August 2026, says Postgres connection logging is off by default for new projectsOpen the platform’s logging settings and read the current valueChange first, then Today
How long customer data is keptNo stated period exists, because nobody wrote oneName the table you would delete from and after how longChange first
What happens when a customer asks for their data to be deletedDeletion is manual and undocumented, and backups get forgottenDescribe the steps out loud. More than four means write the runbook firstChange first
Your list of sub-processorsLonger than you think: host, database, email sender, payment processor, model provider, analytics, plus free tiers, client SDKs and whatever your builder bundlesTrace where customer data goes, starting from every account you pay for and adding the services that never bill youToday, once traced
Whether the product sends customer data to an AI model, and what that provider keeps8 of the 14 third-party apps with an AI surface in that study had untrusted text reaching the model’s instructions. OpenAI’s data guide, read 26 August 2026, says abuse monitoring logs are kept up to 30 days by defaultRead the current retention page of whichever provider holds your model API keyToday for the vendor half, change first for the boundary
Whether an independent test of the running app has been done, and whenIt has notNothing to check. A purchase decision rather than a settingDefer with a date
Whether backups have been restored from, not only takenBackups run on the platform’s schedule and have never been restoredOpen the platform’s backup list and look for any restore eventDefer with a date, unless the row is pass or fail
Who the customer calls in an incident, and how fastOne personal email address, no stated response timeWrite the address, the hours and the target response timeToday

Two habits make the table useful. Answer from a screen you have opened, and date anything you read on a vendor page, because four of these rows are settings a vendor can change without telling you.

What to send back, and what to ask before you write it

Send the answers in the customer’s own form, in their row order, with deferred rows carrying a date and a named next step. A reviewer scoring a hundred suppliers wants their sheet back, filled in, and nothing else.

Two questions are worth asking first: which rows are pass or fail, and who scores the exceptions. The first tells you where to spend the week. The second tells you whether a red row is a rejection or a conversation, and it is almost always a conversation when a human owns the exception queue.

One thing is worth pushing back on: a row asking about a control your app does not have because your app does not do that thing at all. A form written for a company with warehouses will ask about physical access to your data centre. You do not have one. Say so, name the platform that does, and point at its certificate.

The pressure to make this go away with a product is real enough that people build against it. On 25 July 2026 a thread in r/SaaS was titled Built a cheaper alternative to Vanta for answering vendor security questionnaires,.... Tools that draft answers exist and some are good. The signature is still yours.

What AxonBuild does with a form like this is narrow. Show Bilal the app and the rows you cannot answer on a free 20-minute video call. He will explain what needs checking in the code for each one and, if you want a change made, check the app and give you a fixed quote. Nothing is written for you and nothing is handed over as a file.

Common questions about a customer’s security questionnaire

Can I answer a customer’s software security assessment questionnaire if I cannot read my own code?

Yes, most of it. The company, financial, reputational, operational and continuity buckets need no code at all, and the platform rows are answered from your vendors’ published documents. Someone who can read code is needed for a small set of cyber rows: whether one customer can reach another’s data, where secrets live, and whether anything reaching your AI feature can steer it. Usually three or four rows out of a hundred.

What is on a software vendor due diligence checklist?

Six buckets, which is the grouping this page uses for what those forms ask: company information, financial standing, reputational checks, cyber, operational, and exit or continuity. Cyber carries encryption, access, isolation, logging and incident response. Exit carries data export and deletion if you stop trading or the customer leaves. Everything else is identification and record keeping.

My customer asked for SOC 2 as well. Is that the same thing?

No. A questionnaire is a form you fill in and sign. SOC is described by the AICPA as a suite of service offerings CPAs may provide in connection with system-level controls, an examination performed on you by an accounting firm that issues its own report. If your customer asked for both, ask which one gates the deal, because the form can be returned this week and the examination cannot.

Is it dishonest to answer “not yet” on a row?

No. A dated “not yet” with a reason is a normal supplier answer and reviewers see it constantly. The dishonest answer is an unqualified yes that is untrue, and it is worse than a no because your completed form is often attached to the agreement. Ask whether that is the case here before wording a borderline row.

Does my builder’s certificate answer the questions about my app?

No. It answers the vendor half, how the platform runs its own systems, which is real and worth quoting. It says nothing about whether your data is separated correctly or who can reach production. The rows about your platform’s own certificates are answered from the platform’s own pages, and what Base44’s published controls settle and why vendor diligence on Supabase is two requests rather than one are both worked through where they belong.

Who fills this in if I do not have anyone technical?

You do, for most rows, because most rows are about your company and your vendors rather than your code. A class of sellers exists for the rest: compliance consultants, fractional security people, and the questionnaire-answering products. AxonBuild does not answer security questionnaires, does not certify anything and does not produce a document. What it can do is look at your app with you on a free 20-minute video call, explain which of the code rows need checking, and, if you want a change made, check the code, quote it, and build and test it.

If a tool writes the answers, are they still my answers?

Yes, and you sign them. Vanta, Drata, Secureframe, Conveyor and Whistic all sell some version of drafting answers from a stored library, and that is useful once the library holds true sentences. The risk is a library seeded with aspirational answers, which then autofills the same wrong claim into every form you return. Check the first one line by line before you trust the second.

What if the form asks about something my app does not do at all?

Say so and say why, in one sentence. “Not applicable: the application holds no cardholder data, payments are processed by a named provider” is a complete answer. A blank looks like an oversight and gets the file sent back; a reasoned not-applicable gets scored. Name the vendor who does carry the control whenever one does.

How long should I take to send it back?

Ask which rows are pass or fail before you start, then work to that. A fast wrong answer costs more than a slow right one, because a wrong answer can become a contract term while a slow one only annoys somebody. If a row needs a real change, date it rather than holding the whole form until it is done.

Where this leaves you

Open the form, mark every row today, change first, or defer, and count the piles. On most AI-built apps the first pile is bigger than the owner expected and the third is smaller, the opposite of how it feels the day the spreadsheet lands. The middle pile is the work, and it is usually six rows.

Neither the investor’s reviewer nor the reviewer’s own item-by-item order changes the thing this page keeps coming back to: the answer you cannot check is the one that follows you into the contract.