You won the evaluation. Then their security team sent a spreadsheet with 214 rows.
Nobody warned you that the last mile of enterprise sales is a questionnaire, a request for a report you do not have, and three weeks of silence while somebody "checks internally". This page is about getting that unstuck — and about not being in the same position on the next deal.
For teams under fifty with no compliance hire and a deal in the diary.
Two hundred questions, six real ones
Most questionnaires are one template inherited from a bigger company, asked in eleven different ways. Underneath, the reviewer wants six things.
Who on your team can reach our data, how did they get that, and what happens on the day they leave? The honest version of this answer is a list, kept current, not a policy PDF.
Which other companies touch our data if we sign with you? Every vendor in your stack is now part of their risk assessment, which is why the list has to be real.
How does code get to production, and does anyone else look at it first? They are asking whether one person can ship to your database at 3am unobserved.
What happens when something goes wrong, and how fast will you tell us? A named owner and a written plan beat an elegant diagram.
If your infrastructure disappears on a Sunday, what is the plan and when was it last tested? "We have backups" is not an answer, it is a hope.
Can someone independent confirm any of this? That is the SOC 2® or ISO 27001 question, and it is the one that actually ends the thread.
What to do about the deal in front of you
Nothing here requires you to hire a compliance person or to have finished anything.
Answer honestly, once
Put the answers somewhere reusable instead of in a reply-all. The second questionnaire is always eighty per cent the first one, and you should never have to write it twice.
Publish what is true
A trust center with your posture, subprocessors and policies turns "send us your security documentation" into a link. Reviewers like links; they get to close the ticket.
Close the obvious gaps
Offboarding, access reviews, a risk register that exists, policies your team has actually read. Unglamorous, quick, and the difference between "in progress" and "not started".
Get examined
An independent CPA firm examines your controls. A Type I looks at a point in time; a Type II looks at a period, commonly three months or more. Both start with the same preparation.
Most buyers will accept "examination scheduled, here is our trust center and our answers" if it is specific and dated. What loses deals is vagueness, not the absence of a PDF.
We cannot get you a report by Friday
Anyone who says otherwise is selling you something that will not survive the reviewer's second question. What software can compress is the preparation — the evidence, the policies, the register, the description of how your system works.
For reference: AuditBadger has completed its own SOC 2® Type II examination, and preparing for our Type I took under two weeks on the product itself. Your mileage depends on how much of this already exists.
How SOC 2 actually worksCollect evidence on a schedule, draft policies from how you work, keep the vendor and risk registers current, and assemble the SOC 2® system description section by section from what is already in the platform.
Decide which risks you accept, read and assert the system description on your behalf — management asserts it, not a vendor and not a language model — or perform the examination. That is the independent CPA firm, and that independence is the entire value of the report.
Why the domain does not match the logo
Humadroid was the old company name. The compliance product took over and became AuditBadger, but the old domains are still ours and we send a little cold mail from them — one deliverability problem should not be able to mute the entire business.
The product and the people are at auditbadger.com. If the message that brought you here landed badly, reply and tell us — we read every one and we would rather cut the list.
Answer it once. Reuse it forever.
One flat price, unlimited users, onboarding by the founders. Or start with the free policy generator — the first four answers on most questionnaires are policies you do not have yet.
Deal in a hurry? Book a founder demo and bring the questionnaire.