Skip to main content
Trust · Vendor due diligence

Your security review, answered.

Vijilan completes SIG, CAIQ, HECVAT and custom vendor questionnaires as part of your due diligence, with answers that come from independently audited controls rather than from a brochure.

In short

Vijilan completes formal third-party security questionnaires during vendor due diligence, including the Shared Assessments SIG in Lite and Core scopes, the Cloud Security Alliance CAIQ, HECVAT for higher education, and questionnaires written by a buyer’s own risk team. Answers are backed by two independent audits, SOC 2 Type II and ISO/IEC 27001, with HIPAA, PCI DSS and CMMC Level 2 evidence packs available on request.

What we complete

Four things reviewers send,
and what each one is for.

SIG
Standardized Information Gathering

The Shared Assessments questionnaire. Broad third-party risk coverage across many control domains, in a Lite scope and a fuller Core scope. Usually asked for by enterprise procurement and financial services vendor risk teams.

CAIQ
Consensus Assessments Initiative Questionnaire

The Cloud Security Alliance questionnaire, mapped to the CSA Cloud Controls Matrix. Focused on cloud security controls. Usually asked for by teams whose review is organized around cloud posture.

HECVAT
Higher Education Community Vendor Assessment Toolkit

The questionnaire colleges and universities use to assess any vendor that touches institutional data. Usually asked for by a campus security office or procurement.

Custom reviews
Your own questionnaire

A spreadsheet, a portal or a document written by your own risk team. Usually asked for when an organization has standardized on its own control set rather than an industry one.

What backs our answers

Three different kinds of assurance,
kept apart on purpose.

Certifications

Independently audited against a published standard.

  • SOC 2 Type II
  • ISO/IEC 27001
Evidence packs, on request

Documentation mapping our controls to a framework that has no certification of its own. Not a certification, and we do not describe it as one.

  • HIPAA
  • PCI DSS
  • CMMC Level 2
Partner program

A designation describing a commercial relationship with a vendor. It is not an audit and it does not assess Vijilan’s controls.

  • CrowdStrike Powered Service Provider

Audit reports and evidence packs are shared under NDA. Send a mutual NDA to sales@vijilan.com and the pack goes out once it is countersigned.

How it works

Three steps,
no portal to learn.

01
Tell us which questionnaire

Send the SIG, CAIQ or HECVAT you need, or attach your own. If you are not sure which applies, say so and we will tell you what reviewers in your sector usually send.

02
We complete it with evidence

Answers come from the controls behind our audits rather than from marketing copy, and each one points at the evidence that supports it.

03
You review it with our team

A working session on anything that needs context. A reviewer who wants to push on an answer should be able to talk to somebody who can defend it.

Turnaround: two business days from the day we receive it.

Request

Tell us which questionnaire,
and when you need it.

work email required · no file upload in this version
FAQ

What reviewers ask,
answered plainly.

Which security questionnaires do you complete?

SIG in both its Lite and Core scopes, the Cloud Security Alliance CAIQ, HECVAT for higher education, and custom questionnaires written by your own risk team, including ones hosted in a GRC portal.

Can I get your SOC 2 report?

Yes. The SOC 2 Type II report and the ISO/IEC 27001 certificate are shared under NDA, along with the evidence packs.

Is Vijilan HIPAA certified?

No, and neither is anyone else. HIPAA has no certification scheme. Vijilan maintains a HIPAA evidence pack that is available on request, and the same is true of PCI DSS and CMMC Level 2. The only two things Vijilan is certified for are SOC 2 Type II and ISO/IEC 27001, both independently audited.

Will you answer our own questionnaire rather than a standard one?

Yes. Send the spreadsheet or the portal invitation. A custom questionnaire usually takes longer than a standard one because the answers cannot be reused directly, so tell us your deadline when you send it.

Can partners use this for their own clients reviews?

Yes. An MSP, MSSP, VAR or distributor whose client is running a vendor review can request the completed questionnaire and pass it on. We never compete with our partners for their clients, so the review goes through your relationship rather than around it.

What is the difference between a certification, an evidence pack and a partner designation?

A certification is the result of an independent audit against a published standard, which for Vijilan means SOC 2 Type II and ISO/IEC 27001. An evidence pack is the documentation that shows how controls map to a framework that has no certification of its own, such as HIPAA. A partner program designation, such as CrowdStrike Powered Service Provider, describes a commercial relationship with a vendor and is not an audit of anything.

Vendor due diligence

Send us the questionnaire.
We will answer it.

SIG, CAIQ, HECVAT or your own. Backed by SOC 2 Type II and ISO/IEC 27001, with evidence packs on request.