SaaSDossier

01 · Vendor security questionnaire and DDQ support

Prepare a vendor security questionnaire or DDQ from evidence already published.

Start with a dated, source-linked record of what the vendor has published, then identify what still needs to be asked.

OpenAI · Dossier No. 003 · Documented

SOC 2 Type II

Recorded as Documented: the reviewed vendor-published sources establish this field for the evidence date, quoted and cited in the dossier.
Evidence date 2026-06-22
OpenAI · Dossier No. 003 · Question surfaced

SOC 2 Type I report

Not identified in the vendor-published sources reviewed. This does not establish absence of the control.
Buyer-ready follow-up
Disclaimer. SaaSDossier is independent documentation research and is not affiliated with, endorsed by, or certified by any vendor reviewed. Built from vendor-published sources reviewed at the time of preparation. SaaSDossier is a compiled evidence record — not an audit, certification, rating, legal opinion, vendor approval, or substitute for professional vendor-risk, legal, procurement, GRC, vCISO, or security review.

02 · Where teams lose the time

Do not begin with an empty questionnaire.

Vendor security questionnaires and DDQs often force teams to search across the vendor's published material before a single line can be answered — trust centres, security pages, privacy documents, DPAs, subprocessor lists, retention terms, infrastructure documentation and official vendor support material.

  • Trust centres
  • Security pages
  • Privacy documents
  • DPAs
  • Subprocessor lists
  • Retention terms
  • Infrastructure documentation
  • Official vendor support material

SaaSDossier organises reviewed vendor-published evidence into one consistent record, so the buyer begins with the published material already assembled. It does not promise that every questionnaire line will be answered — where the reviewed sources do not establish a field, that field becomes a question surfaced for review.

03 · How teams use it

A practical starting workflow.

  1. Identify the vendor and evidence date.
    Each record is dated. The evidence date tells the review team exactly what the record covers.
  2. Review the structured evidence record.
    55 fields across 10 domains, each in one of two states, each Documented field carrying its source.
  3. Map relevant Documented evidence to questionnaire or DDQ lines.
    The vendor's own published wording, quoted and cited, next to the line it speaks to.
  4. Carry Question surfaced items into the buyer's vendor follow-up.
    Field-level questions, ready to send to the vendor in writing.

The buyer remains responsible for the questionnaire, assessment, professional review and approval decision.

04 · What is in the record

What the record gives your review team.

  • A finished, dated PDF record
  • Reviewed vendor-published sources
  • Source-linked evidence
  • A fixed 55-field framework
  • Documented and Question surfaced states
  • A source register
  • Framework mapping
  • Buyer-ready follow-up questions
  • Human review before release

05 · Where it fits

Where it fits in the review.

Vendor security questionnaireBegin from the vendor-published evidence already organised, rather than a blank form.
DDQ or due-diligence questionnaireMap relevant published evidence to review lines and carry the rest forward as precise questions.
Third-party-risk or vendor security reviewA dated, source-linked record of what is documented and what still needs asking.
Procurement, Security, Privacy, GRC or Legal handoffOne consistent evidence record every function can read on the same terms.

SaaSDossier supports the work leading to the decision. It does not make the decision.

06 · Boundaries

What SaaSDossier does not do.

  • It does not automatically complete the buyer's questionnaire.
  • It does not score or rate the vendor.
  • It does not certify compliance.
  • It does not approve or reject the vendor.
  • It is not live monitoring.
  • It does not replace professional vendor-risk, legal, procurement, GRC, vCISO or security review.

07 · The released records

Start with a released record.

Licensed Editions are US$1,500 each. OpenAI Public Edition is free.

Cover of the Stripe Security Evidence Dossier
Licensed Edition · Dossier No. 001

Stripe

46 Documented9 Questions surfacedof 55

Evidence date 22 June 2026 · 14 vendor pages reviewed

Source-linked · reviewed before release

US$1,500 View Get on Whop
Cover of the HubSpot Security Evidence Dossier
Licensed Edition · Dossier No. 002

HubSpot

49 Documented6 Questions surfacedof 55

Evidence date 22 June 2026 · 11 vendor pages reviewed

Source-linked · reviewed before release

US$1,500 View Get on Whop
Cover of the OpenAI Security Evidence Dossier
Public Edition · Dossier No. 003

OpenAI

47 Documented8 Questions surfacedof 55

Evidence date 22 June 2026 · 14 vendor pages reviewed

Source-linked · reviewed before release

Cover of the Anthropic Security Evidence Dossier
Licensed Edition · Dossier No. 004

Anthropic

47 Documented8 Questions surfacedof 55

Evidence date 24 June 2026 · 14 vendor pages reviewed

Source-linked · reviewed before release

US$1,500 View Get on Whop

The OpenAI Public Edition is free and complete — the clearest way to inspect the format before licensing a vendor dossier.

08 · Questions

Questionnaire and DDQ questions.

Does SaaSDossier complete a vendor security questionnaire or DDQ for me?

No. SaaSDossier provides a finished evidence record built from reviewed vendor-published sources. Your team can use relevant evidence when working through questionnaire lines and carry unresolved items forward as questions, but your organisation remains responsible for the questionnaire and its decisions.

Does “Question surfaced” mean the vendor lacks the control?

No. It means the reviewed vendor-published sources did not establish that field for the evidence date. It identifies what still needs to be asked; it does not establish that a control, practice or capability is absent.

Can the record support a third-party-risk or procurement review?

Yes. It can give Security, Privacy, GRC, Legal and Procurement a consistent, dated record of the vendor-published evidence reviewed and the questions still requiring follow-up. It does not score or approve the vendor.

Is SaaSDossier a live monitoring or questionnaire platform?

No. Each SaaSDossier is a dated, human-reviewed evidence record. It is not live monitoring, an automated questionnaire platform, an audit, certification, rating or vendor approval.

09 · Next

Start the next review with the record already organised.

Disclaimer. SaaSDossier is independent documentation research and is not affiliated with, endorsed by, or certified by any vendor reviewed. Built from vendor-published sources reviewed at the time of preparation. SaaSDossier is a compiled evidence record — not an audit, certification, rating, legal opinion, vendor approval, or substitute for professional vendor-risk, legal, procurement, GRC, vCISO, or security review.