Agentic compliance for SaaS Companies

Your second and third framework, and every questionnaire, without a second team.

Customers ask for SOC 2, then ISO 27001, then TISAX® or NIS2, and every deal brings a security questionnaire. Teddy maps each new framework onto the controls you already have and answers security reviews from your live evidence.

ReusableNew frameworks build on your controls
Same dayQuestionnaires answered and reviewed
Answer libraryApproved answers used again
The SaaS problem

One framework is never the last.
And every deal brings a questionnaire.

SOC 2 opens the first enterprise deals. Then the next customer wants ISO 27001, an automotive buyer wants TISAX®, and each one sends 200 questions. Without a shared foundation, every request becomes a new project.

01Customers ask for more frameworks

Each new framework is mapped onto the controls you already run.

02Security questionnaires

The Questionnaire Agent drafts every answer from your evidence.

03Security team time

Your team reviews only new or changed answers.

04Spreadsheets, a new framework request and a chatbot. The deal still waits.

Security copies last year’s answers, a customer now asks for ISO 27001 and TISAX® on top of SOC 2, and a chatbot can only guess. With Teddy, the second and third framework reuse what SOC 2 already proves, and the Questionnaire Agent answers from live evidence.

How it works

From the first framework to every questionnaire

Teddy builds one control set from your first framework, adds each new one on top and answers security reviews from the same evidence.

01 Certification Agent

Start with SOC 2 or ISO 27001

Your first framework becomes the foundation: one control set, evidence collected from your systems, policies written from how you actually work.

SOC 2 Type IIReport issued
Controls in place112
Evidence collected automatically214 items
Policies approved18
02 Gap Audit Agent

Add the second and third framework on top

ISO 27001, TISAX® or NIS2 map onto the controls you already have. You only build what is really missing.

Comply manyReuse from SOC 2
ISO 27001 Annex A controls covered71 of 93
TISAX® requirements covered76%
New tasks for both34
03 Questionnaire Agent

Import any questionnaire

Excel, Word or PDF. Every question is mapped to your controls and every framework you hold.

Northwind RetailExcel · 214 questions
Mapped to controls214
Answered before162
New questions52
04 Questionnaire Agent

Security reviews only what matters

Answers come with their sources. Security sees what is new or changed, grouped by topic, not 214 rows.

For review13 answers
Subprocessors and data residency6
Incident response timelines4
Teddy: Northwind will likely ask for your ISO 27001 date. I added the planned certification to the cover note.
05 Teddy

A library that keeps getting better

Every approved answer is saved and kept current as your controls change, so the next questionnaire and the next framework go faster.

Answer libraryAlways current
Approved answers1,284
Updated after policy changes37
Questionnaires this quarter23
Never stuck

Sales asks. Teddy answers with approved evidence.

Sales asks in plain language and gets answers Security has already approved. New frameworks and new questions go to the right person with the draft ready.

1

Ask TeddyDo we have ISO 27001? Where is our data hosted? Sales gets approved answers instantly.

2

Agents do the workNew frameworks mapped, questionnaires drafted, evidence kept fresh.

3

Our team backs you upCompliance engineers take you through audits, certification bodies and customer calls.

TeddyAcme Inc. · Sales
Globex wants TISAX®. How far are we?
Most of it is already covered by your SOC 2 and ISO 27001 controls.
  • TISAX® requirements covered76%
  • Prototype protectionGap
  • Assessment with an audit providerNot booked
Shall I plan the remaining work and suggest assessment dates?
Plan TISAX®Ask our team
CEYour compliance engineer takes you through the assessment.
FAQ

Questions SaaS teams ask

How much of ISO 27001 does SOC 2 already cover?

Usually most of the technical controls. Teddy shows exactly which ones carry over and what is missing, such as the Statement of Applicability and the risk process.

Which questionnaire formats are supported?

Excel, Word and PDF. Teddy maps every question to your controls, whatever the layout.

How do we know the answers are right?

Every answer is drafted from your live controls and evidence, with the source linked. Nothing is sent before Security approves it.

Do we need a framework before we can answer questionnaires?

No. Teddy answers from the program you have today. When customers keep asking for a certificate or an audit report, Teddy takes you there too.

The next framework and the next questionnaire, this quarter.

Bring one of your own questionnaires to the demo.

What changes with Teddy

The next framework and the next questionnaire, without a second team

TypicalDays per questionnaire

Security copies last year’s answers, and every new framework starts as a separate project.

With TeddyWithin weeks

The next framework is built on the controls you already have, and questionnaires are drafted immediately from your evidence.

Why Teddy

Teddy was built by former CISOs and GRC managers who answered the same security questions for customer after customer. Answers should come from evidence, not from last year’s spreadsheet.

Meet the founders →