u/scorpionus007

I built a free, open-source tool that drafts security questionnaire answers from your own evidence and KB - and abstains instead of guessing
▲ 7 r/grc+1 crossposts

I built a free, open-source tool that drafts security questionnaire answers from your own evidence and KB - and abstains instead of guessing

I'm a CyberSec student, interning at a US based product company in compliance and security and after talking to people in GRC I kept hearing the same complaint: security questionnaires (SIG, CAIQ, bespoke vendor assessments) are a black hole of time - copy-pasting from old responses, hunting through policies, re-answering the same 200 questions in a slightly different order.

The AI tools pitched at this scared me more than they helped, for two reasons that I think matter specifically to GRC:

  1. They hallucinate. A tool that confidently writes "Yes, we hold ISO 27001" when you don't isn't saving time - it's manufacturing a misrepresentation you'll have to defend in an audit or a contract dispute. In this field a wrong answer is worse than a slow one.
  2. They're SaaS. Answering a questionnaire means feeding your entire control environment — gaps and all - to a third-party model. That's a data-classification problem most GRC teams shouldn't wave through.
  3. They're expensive for small or mid sized SaaS vendors

So I built QRESPONDER to be the opposite:

  • Grounded + cited. Every answer is drawn only from your own documents (policies, SOC 2, prior questionnaires) and cites the exact source it came from — so a reviewer can verify it, not just trust it.
  • It abstains. If your evidence doesn't support an answer, it says "needs review" and routes it to a human instead of inventing something. The default is honesty, not coverage.
  • Human-in-the-loop by design. It drafts; you approve. Nothing goes out unreviewed.
  • Runs on your own infrastructure. With a local model, your control environment never leaves your network — no third-party data sharing, no telemetry.
  • Pulls evidence from Confluence, Notion, SharePoint, Drive, or a folder, and handles whole questionnaires in Excel/Word/PDF, writing answers back into the file.

It's open source and free to self-host. I built it in the open because I'd rather it be genuinely useful to practitioners than a locked-down product.

I'd really value feedback from people who actually run this process. Does the "cite everything + abstain" approach match how you'd want to review answers? What's missing for it to fit a real TPRM/assurance workflow? Where would it fall down in front of an auditor?

Repo + a short demo: https://github.com/scorpionus007/QResponder
Video Demo :- https://youtu.be/iA5OhlzQEr0

u/scorpionus007 — 14 days ago

Need a Leicester City Jersey 2014/15 or 15/16 in India

I was looking to buy a Leicester City Jersey 214/15 15/16 season eith Vardy on the back, Haven't been able to find anywhere online, any offline or thrift stores that might have it anywhere in India?

Anywhere in India is okay I might contact the seller and order, Budget maxm - 800-1200 rs

u/scorpionus007 — 18 days ago