How Insybit answered a security questionnaire in 48 hours and closed a deal with one of India’s largest insurance players

Insybit answered an insurer's security questionnaire in 48 hours with Osto

Insybit was one signature away from a contract with one of India’s largest insurance companies when the insurer’s security questionnaire arrived. After a week of getting nowhere with other vendors, it was answered in 48 hours with Osto, and the deal closed.

  • Case study
  • Security questionnaire

TL;DR

Insybit, an AI-powered marketing intelligence company, needed to clear an enterprise security questionnaire before a large Indian insurer would sign. Co-founder and CEO Saurabh Aggarwal spent close to a week looking for help without finding anyone who could move fast enough. Osto deployed real security controls, answered the security questionnaire from those running controls, and had it submitted within 48 hours of engagement. The insurer’s review cleared and the contract was signed.

48 hours

From engagement to submission

After five to seven days of going around the market with no answer.

Contract signed

With a major Indian insurer

A deal worth roughly Rs 15 to 16 lakh moved to signature once the review cleared.

20x+ return

On the Osto subscription

From this one contract alone, before counting any deal that follows.

The work was done and the relationship was strong. What stood between Insybit and the contract was a form.

One questionnaire away from signing

Insybit had been working toward a contract with one of India’s largest insurance companies for a while. The client liked the work, and the contract was close. Then procurement sent over the vendor security questionnaire.

For a large insurer this is standard. Before any technology vendor touches their data or systems, their procurement and IT security teams need evidence that the vendor meets a defined security bar. It is a gate, and the contract does not move until the security questionnaire is answered to their satisfaction.

Insybit had never needed a formal security programme. It had spent its energy on client results, and nothing about its controls was documented in the shape an enterprise security team expects. The questionnaire asked about things the team had simply never had to write down.

What Insybit is

Insybit is an AI-powered marketing intelligence company based in Gurugram, led by co-founder and CEO Saurabh Aggarwal. It builds data-driven solutions and custom AI tools that help brands make better decisions across their marketing stack, from Google Analytics and Adobe Analytics to WhatsApp engagement, conversion rate optimisation and marketing automation.

At a glanceInsybit
LeadershipSaurabh Aggarwal, Co-founder and CEO
HeadquartersGurugram, India
IndustryAI-powered marketing intelligence
Works acrossAnalytics, WhatsApp engagement, CRO, marketing automation and custom AI tooling
ClientsLarge enterprise brands, including one of India’s largest insurers

That position in the stack is exactly why the security question came up. A traditional agency runs campaigns. Insybit works inside a client’s analytics and customer engagement data and builds tooling on top of it. For a regulated insurer, a vendor with that kind of access gets reviewed properly, however good the work is.

What the security questionnaire asked

The insurer’s security questionnaire covered five areas. None of them could be answered with a promise.

AreaStatusWhat the reviewer wants to see
API securityRequiredHow exposed endpoints are protected against abuse and common attacks
Data handlingRequiredWhere client data lives, how it is stored and who can reach it
Access controlsRequiredHow access to systems and data is granted, limited and removed
Incident responseRequiredWhat happens, and who is told, if something goes wrong
CertificationsAskedAny audited proof of the above, such as SOC 2 or ISO 27001

The week that went nowhere

Saurabh spent five to seven days reaching out to vendors across the market. Nobody could move at the speed the deal needed, and nobody could handle both the answers and the security those answers referred to. The contract sat unsigned the whole time. Insybit reached Osto through a shared network connection.

5 to 7 days Vendor outreach, no answer, deal waiting Osto engaged Controls live WAF and CSPM Answered and submitted Deal signed 48 hours
The 48 hours ran from engagement to submission. The insurer’s own review time sits on top of that.

What Osto did in 48 hours

Osto took on both halves of the problem at once: the security the questionnaire was asking about, and the questionnaire itself. Answering credibly meant having real controls in place first, so that is where the work started.

A web application firewall in front of the application. Osto’s WAF went live in front of Insybit’s application and APIs, blocking common attacks and bot traffic before it reached the origin. That gave the application and API security questions a running control to point to.

CSPM across the cloud environment. Cloud security posture management scanned Insybit’s cloud setup for exposed storage, over-permissive access and similar misconfigurations, and tracked each fix. That gave the data handling and access questions something concrete behind them.

The questionnaire, answered from the stack. With the controls running, Osto worked through the security questionnaire and wrote each answer from what was actually deployed rather than from a policy template. It was answered and submitted within 48 hours of engagement.

“We had spent almost a week trying to figure this out with different vendors. Nothing was moving. Osto came in, understood the problem immediately, and had us sorted in 48 hours. The deal closed.”

Saurabh Aggarwal, Co-founder and CEO, Insybit

Why written answers were not enough

A security questionnaire can be filled in with policy documents in an afternoon. Enterprise reviewers know that, which is why the follow-up questions exist. A completed questionnaire is also often referenced in the contract, so every answer becomes something the vendor has committed to.

When the reviewerPolicy-only answerControl-backed answer
Asks for evidenceAnother documentA screenshot, a report or a log from the running control
Asks a follow-upA scramble to find out what is actually trueA quick look at the dashboard
Writes it into the contractA commitment nobody is yet meetingA description of what is already happening
Sends the next questionnaireThe same scramble againAnswers that already exist and can be reused

The results

OutcomeStatusWhat happened
Security questionnaireDoneAnswered and submitted within 48 hours of engaging Osto, after a week stuck elsewhere
Insurance contractDoneThe insurer’s review cleared and a contract worth roughly Rs 15 to 16 lakh was signed
WAF and CSPMLiveRunning controls that the next enterprise questionnaire can be answered from
VAPT and source code assessmentNextA structured test of the application and codebase, so findings are fixed before a client audit finds them
SOC 2 and ISO 27001NextAudited certification as the enterprise client base grows

The contract value is the easy number to point to. The bigger change is what happens next time. Before Osto, every enterprise security questionnaire would have meant the same week of outreach and the same uncertainty about whether the deal would hold. Now the controls are running and the answers exist, so the next review starts from evidence instead of a blank form.

What other founders can take from this

The gate comes late

Usually after the deal is won

Enterprise buyers send the security questionnaire once they have decided they want you, which is when a delay hurts most.

Answers need controls

Documents alone fall short

The fastest credible response comes from someone who can deploy the security and write the answers together.

The second one is cheaper

Evidence gets reused

Once controls are live and answers are banked, the next buyer’s review is mostly retrieval.

For a step-by-step view of the process, the security questionnaire guide for startups covers it in detail, and this breakdown of a deal lost to a questionnaire shows what happens when the gate is not cleared.

How Osto handles security questionnaires

Osto answers a security questionnaire from your live control state. Web and API protection, cloud posture, endpoint, access and VAPT all run in the same platform, so an answer about MFA coverage or encryption at rest comes from the system enforcing it. The same controls map to SOC 2, ISO 27001 and the DPDP Act, and every answer is kept for the next buyer.

No in-house security team is needed. The certificate is a byproduct of the security, not the other way around.

Platform walkthrough

Clear the security gate before it blocks a deal

Osto deploys the controls and answers the security questionnaire from them, so your next enterprise review starts with evidence already in place.

Book a demo

One platform, everything · Security without slowing down

Frequently asked questions

How did Insybit answer a security questionnaire in 48 hours?

Osto deployed a web application firewall and cloud security posture management first, then wrote each answer from those running controls rather than from policy templates. The completed security questionnaire was submitted within 48 hours of engaging Osto, after Insybit had spent close to a week trying other vendors.

What does an insurance company security questionnaire usually cover?

Typically application and API security, data handling and storage, access controls, incident response and breach notification, and any certifications such as SOC 2 or ISO 27001. Indian insurers are regulated by IRDAI, whose cybersecurity guidelines extend to vendors that handle their data, so these reviews tend to be thorough.

Can you answer a security questionnaire without SOC 2 or ISO 27001?

Yes, if the answers are true and backed by controls. A certificate answers whole sections at once, but many buyers will accept evidence from running controls, with certification shown as planned work. Insybit had neither certification when it cleared the insurer’s review.

Why do security questionnaires stall enterprise deals?

Because they arrive late, usually after the buyer has decided, and they need evidence rather than opinions. A team without documented controls has to find a vendor, deploy something and then write answers, all while the contract waits. That lead time is the stall.

How does Osto speed up security questionnaires?

Security controls and questionnaire answers come from the same platform. Osto’s AI Security Questionnaires draft answers from the live control state, the team reviews them, and every approved answer is kept, so the second questionnaire takes a fraction of the time of the first.