Documentation Index
Fetch the complete documentation index at: https://docs.matproof.com/llms.txt
Use this file to discover all available pages before exploring further.
Overview
The AI Questionnaire module handles both sides of the vendor assessment process:Respond to customers
Customers send you a security questionnaire. Matproof reads your existing policies, controls, and evidence to auto-fill the answers.
Assess your vendors
You send a questionnaire to a vendor. Track their responses and score their security posture from one place.
AI Questionnaire is included on every plan. Per-month answer-generation quotas vary by tier — see Plans & Pricing.
Importing a questionnaire
Matproof accepts the most common formats used in vendor assessments:- SIG Lite (Shared Assessments)
- CAIQ (Cloud Security Alliance)
- Custom Excel or Word questionnaires
- Go to Questionnaire (
/[orgId]/questionnaire) - Click New Questionnaire
- Select the type: Respond (incoming from customer) or Send (outgoing to vendor)
- Upload the file or paste the questions directly
- Matproof parses the questions and displays them in the editor
AI auto-fill (responding to customers)
When you receive a questionnaire from a customer, Matproof’s AI reads each question and matches it against:- Your published policies
- Your mapped controls and their evidence
- Your knowledge base of saved standard answers
- Open the imported questionnaire
- Click Auto-fill with AI
- Review each answer — green means high confidence, yellow means review recommended
- Edit any answers before exporting
Knowledge base
The knowledge base stores your approved answers to common security questions so they can be reused across questionnaires without re-generating them each time. To manage:- Go to Questionnaire → Knowledge Base (
/[orgId]/questionnaire/knowledge-base) - Add a question-answer pair manually, or save an answer directly from a questionnaire you have already reviewed
- Tag answers by topic (e.g., access control, encryption, incident response) for faster retrieval
Statement of Applicability (SOA)
The SOA is an ISO 27001 requirement. It lists every control from Annex A and states whether it applies to your organization, and if not, why it is excluded. To generate your SOA:- Go to Questionnaire → SOA (
/[orgId]/questionnaire/soa) - Matproof pre-populates applicability based on the frameworks you have activated and the controls you have mapped
- Review each control — mark as Applicable, Not applicable, or add an exclusion justification
- Export as PDF or Excel for your ISO 27001 audit
The SOA must be reviewed and updated at least annually under ISO 27001. Matproof tracks when the SOA was last modified so you can demonstrate this to auditors.
Sending questionnaires to vendors
Use this flow when you need to assess a third-party vendor’s security before onboarding them or as part of annual vendor reviews.- Go to Questionnaire → New Questionnaire → Send to Vendor
- Select a template (SIG Lite is recommended for most vendor assessments) or upload a custom one
- Enter the vendor’s name and contact email
- Set a response deadline
- Send — the vendor receives a link to fill in the form directly (no Matproof account required)
Exporting responses
Once you have reviewed and finalized your answers:- Open the questionnaire
- Click Export
- Choose the output format: Excel, Word, or PDF