Ask HN: How do you respond to security questionnaires? A software company we are integrating with wants their 100 question security assessment questionnaire completed. Any advice? We are a two engineer team without a SOC audit and without a third party pen test that stores medical and financial data. These questionnaires are time consuming and redundant. It seems insecure to produce something that details our security too. Does a /security page with some details suffice? Am I just being lazy? |