From friendly branch trial to a spreadsheet of questions
One branch of a large agency group loved your trial. Now group IT and the data protection team are involved. They send a spreadsheet with a couple of hundred questions: where is data hosted, who has access, how are backups tested, do you have penetration test results, what is your incident process, list your sub-processors, how do you delete data at contract end. They also want a data processing agreement signed and a diagram of your architecture.
Your CTO fills it in at night. Many answers are honest but uncomfortable: partly, planned, not yet. The deal slows while the group waits for evidence you do not have.
Why a small team struggles with these reviews
A group that owns many branches holds a large amount of personal data and has a data protection officer, auditors and sometimes a parent company with strict supplier rules. Your product will hold part of that data. They are right to check.
The review is also rarely a single step. Group IT may approve the technical answers while the data protection team is still waiting on the processing agreement, and procurement will not raise a purchase order until both are closed. Questions come back in rounds, sometimes weeks apart, and each round needs the same person on your side to find time.
- Controls were built for speed at launch, and some, such as access logging or tested restores, were never finished.
- Evidence is missing even where the control exists, such as screenshots, policies or logs showing it works.
- Every review is answered from scratch in a new spreadsheet.
- The person who knows the answers is also the person building the product.
- Data protection questions, such as retention and deletion per agency, touch parts of the product nobody designed with them in mind.
What a stalled review costs
Corporate groups are the deals that change a proptech startup's revenue, and they are exactly the ones that run a review. A review that drags on for months delays that revenue and sometimes ends with a polite no. The engineering time goes too: weeks of senior attention spent on questionnaires rather than product, often repeated for the next group in slightly different words.
How we get you through the review and the next one
What we build has two parts: closing the real gaps, and making the evidence easy to produce.
- A gap review against the questions you actually receive, sorted into answered and evidenced, true but not evidenced, and not yet true.
- Building the missing controls that matter most to agency groups: SSO for staff, role-based access per branch, audit logs of data access and exports, encrypted backups with tested restores, and data deletion per agency at contract end.
- Evidence gathered from your real setup on AWS, Azure or wherever you host: configuration exports, restore test records, access reviews, dependency scanning reports.
- A current architecture diagram and data flow showing what agency data goes where, including every sub-processor.
- An answer library of reviewed, reusable answers with links to evidence, so each new questionnaire starts mostly filled in.
- A short security page or pack you can send before the questionnaire arrives, which often shortens it.
| Common question | What we give you |
|---|---|
| Where is our data hosted? | Region settings and a data flow diagram |
| Who can access it on your side? | Access roles, access review record, audit log |
| Are backups tested? | Scheduled restore test with results kept |
| What happens at contract end? | Deletion process per agency, with a record of deletion |
| Who are your sub-processors? | Maintained list, tied to the actual services in use |
Legal documents such as your data processing agreement are for you and your solicitor. We make sure what the technical answers say is true of the system.
The next review
The next group sends a different spreadsheet. Most questions map to entries in the answer library, each with evidence already attached. Your CTO spends an afternoon on the new questions rather than a fortnight on all of them, and sends the security pack with the reply. The group's IT team can see that answers such as tested restores are backed by records, not promises.
Is a security review holding up a deal?
- Your answers include several versions of planned or partly.
- Every questionnaire is answered from a blank spreadsheet.
- You cannot show a record of a backup restore test.
- Your sub-processor list is not certain to be complete.
- Only one person in the company can answer the technical questions.