Ask HN: How do you deal with security questionnaires?
"How do you manage security keys?"
"What encryption do you use?"
Unless you are self-employed, they are massive questions full of nuance and probably have 50 different answers on 50 different systems but these companies believe they have the right to ask.
I know we can use a Security-as-a-service company to answer these on our behalf but I wondered what more established companies do? Do you just say, "here is the standard security page and that's all you're getting", or do you also spend many hours answering "what backups do you take?"