Vyorith

Proof,not promises.

Security questionnaires answered from your own evidence, and ISO 27001 without the consultant’s calendar. Every answer cited. Every answer approved by someone who read it.

  • ISO 27001:2022
  • Excel, Word and PDF questionnaires
  • Every answer cites its source
Halden Bank — Supplier Security Assessment.xlsx
Access control · Row 14High

Is multi-factor authentication enforced for all administrative access to production systems?

Yes. Multi-factor authentication is required for all administrative and privileged access to production. SMS and voice-call codes are not permitted as a second factor. Access is granted on least privilege and reviewed quarterly.

PDFAccess Control Policy v3.0p. 4
“§5.2 Multi-factor authentication is mandatory for all privileged access. SMS and voice-call one-time passcodes are prohibited.”
ApproveEdit

Answers the questionnaires your buyers send — in the file they sent it in

  • SIG Lite
  • SIG Core
  • CAIQ
  • VSAQ
  • HECVAT
  • Your buyer’s own

Why Vyorith

Deals rarely die in procurement. They go quiet in the security review.

A buyer sends a spreadsheet of two hundred questions. Someone copies last year’s answers, hopes they are still true, and chases colleagues for the rest. Meanwhile the certification that would answer half of them sits on a consultant’s timeline.

Vyorith does both from the same evidence — and never lets an answer leave that nobody has read.

14
plain-language themes instead of clause numbers
93
Annex A controls mapped underneath, all of them
3
questionnaire formats answered in place: Excel, Word, PDF
1
body of evidence behind the audit and every questionnaire

Security questionnaires

Their spreadsheet. Your evidence. Nobody’s guesswork.

Vyorith drafts every answer from your policies, your approved past answers and the facts your team keeps current. Your reviewer’s job becomes reading and approving — with the evidence open beside each question.

You point. It answers.

Upload the file your buyer sent. Show Vyorith where the questions are and which cells take the answers — on a render of your actual spreadsheet. Only those rows are answered. For Word and PDF, you check the list of questions it found first.

Receipts on every answer

Each answer cites the document and page it came from. Quotes are checked word for word against the source, and your current signed policy outranks a retired version or a reference framework.

“I don’t know” is an answer

If your evidence doesn’t support an answer, the question is marked “No evidence” instead of being filled with something plausible. Answers that contradict each other are flagged before you approve.

Nothing ships unread

The final file carries only answers a person approved, written into the buyer’s own cells with their formatting untouched. Every edit and approval is kept in the question’s history.

Supplier Security Assessment.xlsx164 questions
  • 1 contradiction
    C22 says access is reviewed quarterly; C51 says annually.
  • 3 with no evidence
    C17 FedRAMP authorisation — nothing in your documents supports it.
  • 2 found on your website
    Taken only from your own official site, and marked lower-trust than your documents.
Export finalinto the original file
118 approved answers written46 left blank · not approved

Answer library

Answers go stale. Now you’ll know which ones.

Every answer you approve makes the next questionnaire faster. But an answer is only reusable while it is still true — so Vyorith reuses one word for word only when the question matches, it was confirmed recently, and nothing contradicts it. Anything older becomes a hint, checked against today’s evidence.

Library health reads the whole library the way a sharp buyer would: the pen test dated two years ago, the answer your new policy quietly overruled, the two answers that disagree. You fix each one where you find it.

Library health

412 of 448 answers ready to send as-is

  • Out of dateFix

    “Our most recent penetration test was completed in March 2024.”

    Tested yearly — this is past due.

  • Conflicts with your documentsFix

    “Passwords must be at least 8 characters.”

    Password Standard v2, p. 2 says 12.

  • Contradicts another answerFix

    “Backups are taken weekly.”

    Another approved answer says daily.

+ 6 answers saying the same thing four different ways

ISO 27001:2022

ISO 27001, minus the clause numbers.

Your team works through fourteen themes written in plain language. Underneath, every requirement in Clauses 4–10 and all 93 Annex A controls is mapped for them — so the work reads like running a company, and the output reads like an audit.

The journey

Fourteen themes, in the right order

Governance before access, risk before controls. Themes open as the ones they depend on are done, so nothing is built on a foundation that isn’t there yet.

  1. Governance
  2. Scope
  3. Risk
  4. People
  5. Access
  6. Assets
  7. Infrastructure
  8. Development
  9. Suppliers
  10. Incidents
  11. Continuity
  12. Physical
  13. Privacy
  14. Audit

Gap assessment

Start from what you have

Each document is read against what an auditor expects of it, topic by topic, quoting the passages it relies on.

  • PDFInformation Security PolicyCovered
  • Access Control PolicyCovered
  • Risk Register2 weak topics

Statement of Applicability

Pre-filled. Never auto-signed.

Your theme answers fill in the SOA as you go. A person confirms every control — an SOA nobody decided is one an auditor won’t accept.

A.8.5Secure authentication
Applicable · ImplementedConfirm

Risk register

Read, not just stored

Upload it in Excel, Word or PDF. Every risk is extracted, missing owners and treatments are flagged, and each risk is mapped to the controls that address it.

R-07Lost or stolen laptop
No ownerA.8.1 · A.8.24

Policies

Drafted in your terms

Missing a policy? Vyorith drafts it for your organisation. Your team revises it, and approves each version by name.

Acceptable Use Policy
Version 2 · revisedApprove

AI drafts. People decide. Nothing counts as evidence until a named person on your team approves it.

Recorded, with who and when

How it works

From first login to audit‑ready, without a blank page.

  1. 01

    We do our homework first

    Before you type a word, Vyorith reads your company’s own website. Five intake questions later, you have a document checklist written for your business, not a template.

  2. 02

    Bring what you have

    Policies, the risk register, last year’s questionnaires. The gap assessment shows what’s covered, what’s thin and what’s missing — and never stops you moving on.

  3. 03

    Work the themes

    Answer in plain language. Missing policies are drafted for you to revise, and the Statement of Applicability fills itself in for you to confirm.

  4. 04

    Answer, approve, send

    Questionnaires are answered from the same evidence. Every approved answer joins your library, so each questionnaire starts further ahead than the last.

Security

Built to pass the questionnaire it answers.

You’re trusting us with the documents that describe your defences. We hold ourselves to the standard your buyers hold you to.

Works with what you run

  • MCP serverAsk your evidence from your AI assistant or any MCP client.
  • REST APIDocuments, runs, facts and search, with an OpenAPI spec.
  • WebhooksSigned events when documents are indexed, runs finish and the SOA is finalised.
  • Two factors, no exceptions

    Every account signs in with an authenticator app. There is no setting to turn it off.

  • No self sign-up

    Accounts are created by an administrator, and only for the email domains your workspace allows.

  • Workspaces kept apart

    Each company’s data is scoped to its own workspace — checked in the application and enforced again in the database.

  • Roles that mean something

    Admins, members and read-only viewers. Sensitive actions are written to an audit log.

  • Your evidence stays yours

    Documents are used to answer your questions, and not to train anyone’s models.

  • Your own website, or nothing

    Web lookups are off unless you switch them on, and even then read only your company’s official site.

For companies

The one in the deal.

Procurement asked for ISO 27001 and a questionnaire the size of a novel. Get both done from one body of evidence, with your own people making every decision that matters.

  • A guided path to audit-ready, in plain language
  • Missing policies drafted for you to revise
  • Questionnaires answered from the same evidence

For consultancies

The one behind a dozen of them.

Run every client engagement from one place, with the same method and the same standard of output — and never a client’s document in the wrong room.

  • One workspace per client, kept strictly apart
  • Switch clients without mixing a single file
  • Invite client staff as members or read-only viewers
Talk to us

FAQ

The questions your auditor would ask us.

Not here? Ask us — we answer the hard ones too.

It’s built not to. Every answer cites the document and page it came from, and each quoted passage is checked word for word against the source — a quote that isn’t there is removed. When your evidence doesn’t support an answer, the question is marked “No evidence” for a person to handle.

Bring the questionnaire that’s stalling a deal.

We’ll show you it answered from your own documents — cited, checked and waiting for your approval. Access is by invitation.