Completing Security Questionnaires and Vendor Risk Assessments

Last updated: September 16, 2025

When working with enterprise customers, you may need to complete security questionnaires or vendor risk assessments as part of their procurement process. Here's what you need to know about our current capabilities and documentation.

Available Security Documentation

Mycroft can provide the following security documentation to help with vendor assessments:

  • SOC 2 Type 2 Report - Mycroft's complete SOC 2 compliance report is available and can be shared under NDA

  • Security questionnaire responses - Our Virtual CISO offering can help complete security questionnaires for your specific vendor assessment process

Authentication and SSO Support

When completing security questionnaires, please note Mycroft's current authentication capabilities:

  • OIDC (OpenID Connect) - Fully supported

  • Microsoft Entra ID - Supported

  • SAML - Not currently supported

Privacy Impact Assessments

We do not currently have a formalized Privacy Impact Assessment (PIA) document. However, our team can help facilitate the creation of one if required by your customer's compliance process.

Getting Help with Security Questionnaires

If you need assistance completing a security questionnaire or vendor risk assessment:

  1. Contact our Virtual CISO team with the specific questionnaire or assessment platform details

  2. We can help provide accurate responses based on our current security posture and capabilities

  3. For complex assessments, we recommend having both customer and vendor teams review responses for accuracy

Note: Automated AI assistance for filling out security questionnaires is planned for future development but not currently available.