Insybit was one signature away from a contract with one of India’s largest insurance companies when the insurer’s security questionnaire arrived. After a week of getting nowhere with other vendors, it was answered in 48 hours with Osto, and the deal closed.
TL;DR
Insybit, an AI-powered marketing intelligence company, needed to clear an enterprise security questionnaire before a large Indian insurer would sign. Co-founder and CEO Saurabh Aggarwal spent close to a week looking for help without finding anyone who could move fast enough. Osto deployed real security controls, answered the security questionnaire from those running controls, and had it submitted within 48 hours of engagement. The insurer’s review cleared and the contract was signed.
48 hours
From engagement to submission
After five to seven days of going around the market with no answer.
Contract signed
With a major Indian insurer
A deal worth roughly Rs 15 to 16 lakh moved to signature once the review cleared.
20x+ return
On the Osto subscription
From this one contract alone, before counting any deal that follows.
The work was done and the relationship was strong. What stood between Insybit and the contract was a form.
On this page
One questionnaire away from signing
Insybit had been working toward a contract with one of India’s largest insurance companies for a while. The client liked the work, and the contract was close. Then procurement sent over the vendor security questionnaire.
For a large insurer this is standard. Before any technology vendor touches their data or systems, their procurement and IT security teams need evidence that the vendor meets a defined security bar. It is a gate, and the contract does not move until the security questionnaire is answered to their satisfaction.
Insybit had never needed a formal security programme. It had spent its energy on client results, and nothing about its controls was documented in the shape an enterprise security team expects. The questionnaire asked about things the team had simply never had to write down.
What Insybit is
Insybit is an AI-powered marketing intelligence company based in Gurugram, led by co-founder and CEO Saurabh Aggarwal. It builds data-driven solutions and custom AI tools that help brands make better decisions across their marketing stack, from Google Analytics and Adobe Analytics to WhatsApp engagement, conversion rate optimisation and marketing automation.
| At a glance | Insybit |
|---|---|
| Leadership | Saurabh Aggarwal, Co-founder and CEO |
| Headquarters | Gurugram, India |
| Industry | AI-powered marketing intelligence |
| Works across | Analytics, WhatsApp engagement, CRO, marketing automation and custom AI tooling |
| Clients | Large enterprise brands, including one of India’s largest insurers |
That position in the stack is exactly why the security question came up. A traditional agency runs campaigns. Insybit works inside a client’s analytics and customer engagement data and builds tooling on top of it. For a regulated insurer, a vendor with that kind of access gets reviewed properly, however good the work is.
What the security questionnaire asked
The insurer’s security questionnaire covered five areas. None of them could be answered with a promise.
| Area | Status | What the reviewer wants to see |
|---|---|---|
| API security | Required | How exposed endpoints are protected against abuse and common attacks |
| Data handling | Required | Where client data lives, how it is stored and who can reach it |
| Access controls | Required | How access to systems and data is granted, limited and removed |
| Incident response | Required | What happens, and who is told, if something goes wrong |
| Certifications | Asked | Any audited proof of the above, such as SOC 2 or ISO 27001 |
The week that went nowhere
Saurabh spent five to seven days reaching out to vendors across the market. Nobody could move at the speed the deal needed, and nobody could handle both the answers and the security those answers referred to. The contract sat unsigned the whole time. Insybit reached Osto through a shared network connection.
What Osto did in 48 hours
Osto took on both halves of the problem at once: the security the questionnaire was asking about, and the questionnaire itself. Answering credibly meant having real controls in place first, so that is where the work started.
A web application firewall in front of the application. Osto’s WAF went live in front of Insybit’s application and APIs, blocking common attacks and bot traffic before it reached the origin. That gave the application and API security questions a running control to point to.
CSPM across the cloud environment. Cloud security posture management scanned Insybit’s cloud setup for exposed storage, over-permissive access and similar misconfigurations, and tracked each fix. That gave the data handling and access questions something concrete behind them.
The questionnaire, answered from the stack. With the controls running, Osto worked through the security questionnaire and wrote each answer from what was actually deployed rather than from a policy template. It was answered and submitted within 48 hours of engagement.
“We had spent almost a week trying to figure this out with different vendors. Nothing was moving. Osto came in, understood the problem immediately, and had us sorted in 48 hours. The deal closed.”
Saurabh Aggarwal, Co-founder and CEO, Insybit
Why written answers were not enough
A security questionnaire can be filled in with policy documents in an afternoon. Enterprise reviewers know that, which is why the follow-up questions exist. A completed questionnaire is also often referenced in the contract, so every answer becomes something the vendor has committed to.
| When the reviewer | Policy-only answer | Control-backed answer |
|---|---|---|
| Asks for evidence | Another document | A screenshot, a report or a log from the running control |
| Asks a follow-up | A scramble to find out what is actually true | A quick look at the dashboard |
| Writes it into the contract | A commitment nobody is yet meeting | A description of what is already happening |
| Sends the next questionnaire | The same scramble again | Answers that already exist and can be reused |
The results
| Outcome | Status | What happened |
|---|---|---|
| Security questionnaire | Done | Answered and submitted within 48 hours of engaging Osto, after a week stuck elsewhere |
| Insurance contract | Done | The insurer’s review cleared and a contract worth roughly Rs 15 to 16 lakh was signed |
| WAF and CSPM | Live | Running controls that the next enterprise questionnaire can be answered from |
| VAPT and source code assessment | Next | A structured test of the application and codebase, so findings are fixed before a client audit finds them |
| SOC 2 and ISO 27001 | Next | Audited certification as the enterprise client base grows |
The contract value is the easy number to point to. The bigger change is what happens next time. Before Osto, every enterprise security questionnaire would have meant the same week of outreach and the same uncertainty about whether the deal would hold. Now the controls are running and the answers exist, so the next review starts from evidence instead of a blank form.
What other founders can take from this
The gate comes late
Usually after the deal is won
Enterprise buyers send the security questionnaire once they have decided they want you, which is when a delay hurts most.
Answers need controls
Documents alone fall short
The fastest credible response comes from someone who can deploy the security and write the answers together.
The second one is cheaper
Evidence gets reused
Once controls are live and answers are banked, the next buyer’s review is mostly retrieval.
For a step-by-step view of the process, the security questionnaire guide for startups covers it in detail, and this breakdown of a deal lost to a questionnaire shows what happens when the gate is not cleared.
How Osto handles security questionnaires
Osto answers a security questionnaire from your live control state. Web and API protection, cloud posture, endpoint, access and VAPT all run in the same platform, so an answer about MFA coverage or encryption at rest comes from the system enforcing it. The same controls map to SOC 2, ISO 27001 and the DPDP Act, and every answer is kept for the next buyer.
No in-house security team is needed. The certificate is a byproduct of the security, not the other way around.
Platform walkthrough
Clear the security gate before it blocks a deal
Osto deploys the controls and answers the security questionnaire from them, so your next enterprise review starts with evidence already in place.
Book a demoOne platform, everything · Security without slowing down
Frequently asked questions
How did Insybit answer a security questionnaire in 48 hours?
Osto deployed a web application firewall and cloud security posture management first, then wrote each answer from those running controls rather than from policy templates. The completed security questionnaire was submitted within 48 hours of engaging Osto, after Insybit had spent close to a week trying other vendors.
What does an insurance company security questionnaire usually cover?
Typically application and API security, data handling and storage, access controls, incident response and breach notification, and any certifications such as SOC 2 or ISO 27001. Indian insurers are regulated by IRDAI, whose cybersecurity guidelines extend to vendors that handle their data, so these reviews tend to be thorough.
Can you answer a security questionnaire without SOC 2 or ISO 27001?
Yes, if the answers are true and backed by controls. A certificate answers whole sections at once, but many buyers will accept evidence from running controls, with certification shown as planned work. Insybit had neither certification when it cleared the insurer’s review.
Why do security questionnaires stall enterprise deals?
Because they arrive late, usually after the buyer has decided, and they need evidence rather than opinions. A team without documented controls has to find a vendor, deploy something and then write answers, all while the contract waits. That lead time is the stall.
How does Osto speed up security questionnaires?
Security controls and questionnaire answers come from the same platform. Osto’s AI Security Questionnaires draft answers from the live control state, the team reviews them, and every approved answer is kept, so the second questionnaire takes a fraction of the time of the first.

