Vendor security reviews

ShipShape and vendor security questionnaires

This is the one we are genuinely built for, rather than adjacent to.

The control we speak to

The rows that actually appear

Do you perform application security testing? Describe the scope and frequency. Are secrets kept out of client-side code? Do you test against the OWASP Top 10? Do you use LLM components and how is prompt injection mitigated?

What we produce for it

  • A questionnaire packet that answers those rows directly, filled in from your real scan rather than from a template.
  • Dual OWASP classification (classic Top 10 and LLM Top 10) plus CWE per finding, which is the vocabulary the reviewer is using.
  • Honest 'not tested' rows with the compensating context, which reviewers trust more than a page of green ticks.
  • A shareable dated report link you can send to whoever asked, without them needing an account.

What we do NOT do

  • We cannot answer the rows about your staff, your policies, your suppliers or your incident response. Most of a questionnaire is not about scanning.
  • We produce a self-assessment. No accredited third party has reviewed it, and our documents say so on their face.
Run a scan