
I built a free, open-source tool that drafts security questionnaire answers from your own evidence and KB - and abstains instead of guessing
I'm a CyberSec student, interning at a US based product company in compliance and security and after talking to people in GRC I kept hearing the same complaint: security questionnaires (SIG, CAIQ, bespoke vendor assessments) are a black hole of time - copy-pasting from old responses, hunting through policies, re-answering the same 200 questions in a slightly different order.
The AI tools pitched at this scared me more than they helped, for two reasons that I think matter specifically to GRC:
- They hallucinate. A tool that confidently writes "Yes, we hold ISO 27001" when you don't isn't saving time - it's manufacturing a misrepresentation you'll have to defend in an audit or a contract dispute. In this field a wrong answer is worse than a slow one.
- They're SaaS. Answering a questionnaire means feeding your entire control environment — gaps and all - to a third-party model. That's a data-classification problem most GRC teams shouldn't wave through.
- They're expensive for small or mid sized SaaS vendors
So I built QRESPONDER to be the opposite:
- Grounded + cited. Every answer is drawn only from your own documents (policies, SOC 2, prior questionnaires) and cites the exact source it came from — so a reviewer can verify it, not just trust it.
- It abstains. If your evidence doesn't support an answer, it says "needs review" and routes it to a human instead of inventing something. The default is honesty, not coverage.
- Human-in-the-loop by design. It drafts; you approve. Nothing goes out unreviewed.
- Runs on your own infrastructure. With a local model, your control environment never leaves your network — no third-party data sharing, no telemetry.
- Pulls evidence from Confluence, Notion, SharePoint, Drive, or a folder, and handles whole questionnaires in Excel/Word/PDF, writing answers back into the file.
It's open source and free to self-host. I built it in the open because I'd rather it be genuinely useful to practitioners than a locked-down product.
I'd really value feedback from people who actually run this process. Does the "cite everything + abstain" approach match how you'd want to review answers? What's missing for it to fit a real TPRM/assurance workflow? Where would it fall down in front of an auditor?
Repo + a short demo: https://github.com/scorpionus007/QResponder
Video Demo :- https://youtu.be/iA5OhlzQEr0