Built a cheaper alternative to Vanta for answering vendor security questionnaires, curious if this is actually needed at small company size.
So I've spent the last few weeks building this thing called PolicyIQ. Basically you upload your company's security policies (pdf or word docs) and then upload a vendor security questionnaire someone sent you, and it reads through your policies and drafts…
So I've spent the last few weeks building this thing called PolicyIQ. Basically you upload your company's security policies (pdf or word docs) and then upload a vendor security questionnaire someone sent you, and it reads through your policies and drafts answers for every question. It marks each one as answered, needs review, or policy gap, and it won't just make something up if it can't find good enough matching info in your docs, it'll actually say policy gap instead of faking an answer. It also catches when two of your own policy docs contradict each other, which happened in my testing (one doc said something was approved, another said the same thing was prohibited) and it flags that instead of just picking one silently. You approve everything before it goes out and there's an audit log, then you export to excel when you're done. I built this because Vanta and Drata and similar tools start around 10-40k a year which is just not realistic for a small team, but small teams still have to deal with these same annoying questionnaires. I'm charging 99 to 249 a month instead. What I actually don't know is whether a company with like 10-50 people even gets enough of these questionnaires to bother paying for something like this, or if it's rare enough that just doing it by hand is fine. If anyone here has dealt with this at a small company I'd genuinely like to know when it started feeling like a real problem for you. screenshot below is one of the actual answers it gave, showing it flagging a policy gap instead of guessing.
已收录讨论
PolicyIQ.replit.app
这条评论已被删除。
Low-Effort/AI content is auto-removed. I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.
Company owner here with <10 employees but under multiple compiance obligations so definitely interested in GRC products like this. Pricing seems fair. However, in its current form no serious business would even consider using your product. Issues at a glance: - generic replit domain, instantly signals low quality products if you couldn’t even bother setting up your own DNS and/or hosting infra - privacy policy, ToS 404 - that’s a direct GDPR violation and you can be fined as of right now because at the very least you already process visitor IPs and also email addresses if someone contacts you - no company name stated - if you do not even have a legal entity I’m not giving you any data, let alone my most sensitive security related policies - compliance proof? At the very least I would look for ISO27k1 and preferably SOC Type 2 as well Also, “built in a few weeks” suggests heavy vibe coding which just doesn’t fly for products that require any trust at all.
这条评论已被删除。