{"id":1175,"date":"2026-09-11T09:34:57","date_gmt":"2026-09-11T09:34:57","guid":{"rendered":"https:\/\/www.osto.one\/resources\/?p=1175"},"modified":"2026-09-11T09:34:57","modified_gmt":"2026-09-11T09:34:57","slug":"insybit-security-questionnaire-48-hours-insurance-deal-2","status":"publish","type":"post","link":"https:\/\/www.osto.one\/resources\/case-studies\/insybit-security-questionnaire-48-hours-insurance-deal-2\/","title":{"rendered":"How Insybit answered a security questionnaire in 48 hours and closed a deal with one of India&#8217;s largest insurance players"},"content":{"rendered":"\n<!-- OSTO CASE STUDY | insybit-security-questionnaire-48-hours-v2 | replaces content at the existing live URL, keep the slug -->\n<style>\n.og{\n  --navy:#1c267a; --text:#0f1538; --muted:#0f1538; --light:#0f1538;\n  --border:#e7e9f2; --divider:#eceef5; --white:#ffffff;\n\n  --peri-50:#f4f5fd;  --peri-100:#e9ecfa; --peri-200:#cfd5f2; --peri-700:#4a52a8;\n  --sage-50:#f2f8f5;  --sage-100:#e3f0e9; --sage-200:#c3ddce; --sage-700:#3a6f5d;\n  --apri-50:#fdf6f0;  --apri-100:#fbe9dc; --apri-200:#f2cdb2; --apri-700:#a2603a;\n  --plum-50:#f8f3f9;  --plum-100:#f0e6f3; --plum-200:#dcc6e2; --plum-700:#6b4576;\n  --sky-50:#f1f7fb;   --sky-100:#e2eff7;  --sky-200:#bfd9e9;  --sky-700:#2f6a89;\n\n  --shadow:0 6px 22px rgba(15,21,56,.05);\n  --font:'Inter',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif;\n  font-family:var(--font); font-size:17px; line-height:1.75; color:var(--text);\n}\n.og p{margin:0 0 22px}\n.og h2{font-family:var(--font);font-size:clamp(25px,3vw,31px);font-weight:700;line-height:1.25;letter-spacing:-.5px;color:var(--navy);margin:52px 0 8px;scroll-margin-top:92px}\n.og h2::after{content:\"\";display:block;width:46px;height:5px;border-radius:3px;margin:12px 0 18px;background:var(--peri-200)}\n.og h2.c-sage::after{background:var(--sage-200)}\n.og h2.c-apri::after{background:var(--apri-200)}\n.og h2.c-plum::after{background:var(--plum-200)}\n.og h2.c-sky::after{background:var(--sky-200)}\n.og ul,.og ol{padding-left:22px;margin:0 0 24px}\n.og li{margin-bottom:9px}\n.og strong{font-weight:600}\n\n.og .dek{font-size:20px;line-height:1.6;color:var(--muted);margin:0 0 18px}\n.og .tags{margin:0 0 30px;padding:0;list-style:none;display:flex;flex-wrap:wrap;gap:8px}\n.og .tags li{margin:0}\n.og .tag{display:inline-block;font-size:12px;font-weight:600;letter-spacing:.7px;text-transform:uppercase;padding:6px 13px;border-radius:20px}\n.og .t-peri{background:var(--peri-100);color:var(--peri-700)}\n.og .t-sage{background:var(--sage-100);color:var(--sage-700)}\n\n.og .short{background:linear-gradient(135deg,var(--peri-100) 0%,var(--sage-100) 100%);border-radius:22px;padding:28px 32px;margin:0 0 30px}\n.og .short .k{font-size:13px;font-weight:700;letter-spacing:1.4px;text-transform:uppercase;color:var(--peri-700);margin:0 0 10px}\n.og .short p{font-size:19px;line-height:1.65;margin:0;color:var(--text)}\n\n.og .toc{background:var(--peri-50);border-radius:20px;padding:24px 28px;margin:0 0 34px}\n.og .toc .k{font-size:12px;font-weight:700;letter-spacing:1.3px;text-transform:uppercase;color:var(--peri-700);margin:0 0 12px}\n.og .toc ol{margin:0;padding-left:20px;columns:2;column-gap:34px}\n.og .toc li{margin-bottom:8px;break-inside:avoid;font-size:16px}\n.og .toc a{color:var(--navy);text-decoration:none;border-bottom:1px solid rgba(28,38,122,.22)}\n\n.og .callout{border-radius:4px;padding:24px 28px;margin:0 0 30px;background:var(--white);border:2px solid var(--navy)}\n.og .callout .k{font-weight:700;font-size:17px;margin:0 0 8px;color:var(--navy)}\n.og .callout p:last-child{margin-bottom:0}\n.og .callout.c-plum{background:var(--plum-50);border:none;border-radius:20px}\n.og .callout.c-plum .k{color:var(--plum-700)}\n\n.og figure{margin:0 0 30px}\n.og .sx{overflow-x:auto;-webkit-overflow-scrolling:touch;border-radius:20px;background:var(--white);box-shadow:var(--shadow)}\n.og .sx svg{display:block;width:100%;height:auto;min-width:600px}\n.og figcaption{font-size:14px;line-height:1.6;color:var(--muted);margin-top:12px}\n.og .swipe{display:none}\n\n.og table{width:100%;border-collapse:collapse;margin:0 0 28px;font-size:15px;background:var(--white);border-radius:18px;overflow:hidden;box-shadow:var(--shadow)}\n.og th{text-align:left;padding:14px 16px;font-weight:700;font-size:12.5px;letter-spacing:.8px;text-transform:uppercase}\n.og td{border-bottom:1px solid var(--divider);padding:13px 16px;vertical-align:top;line-height:1.6}\n.og tr:last-child td{border-bottom:none}\n.og .h-peri th{background:var(--peri-100);color:var(--peri-700)}\n.og .h-sage th{background:var(--sage-100);color:var(--sage-700)}\n.og .h-plum th{background:var(--plum-100);color:var(--plum-700)}\n\n.og .trio{display:grid;grid-template-columns:repeat(3,1fr);gap:14px;margin:0 0 28px}\n.og .tcard{border-radius:18px;padding:20px 22px}\n.og .tcard .n{font-size:16px;font-weight:700;margin:0 0 4px}\n.og .tcard .g{font-size:13px;font-weight:600;margin:0 0 10px;opacity:.8}\n.og .tcard p{font-size:14px;line-height:1.55;margin:0;color:var(--muted)}\n.og .tcard.a{background:var(--sky-50)}   .og .tcard.a .n,.og .tcard.a .g{color:var(--sky-700)}\n.og .tcard.b{background:var(--sage-50)}  .og .tcard.b .n,.og .tcard.b .g{color:var(--sage-700)}\n.og .tcard.c{background:var(--plum-50)}  .og .tcard.c .n,.og .tcard.c .g{color:var(--plum-700)}\n\n.og .pill{display:inline-block;font-size:11px;font-weight:700;letter-spacing:.8px;text-transform:uppercase;padding:5px 11px;border-radius:20px;white-space:nowrap}\n.og .p-req{background:var(--plum-200);color:#4d2f57}\n.og .p-exp{background:var(--sky-100);color:var(--sky-700)}\n.og .p-imp{background:#eef0f4;color:var(--muted)}\n.og .p-ask{background:var(--apri-100);color:var(--apri-700)}\n.og .p-yes{background:var(--sage-100);color:var(--sage-700)}\n.og .p-no{background:#eef0f4;color:var(--muted)}\n\n.og details{background:var(--white);border-radius:14px;margin:0 0 10px;box-shadow:0 2px 10px rgba(15,21,56,.04)}\n.og summary{cursor:pointer;padding:16px 20px;font-weight:600;font-size:17px;color:var(--navy);list-style:none;display:flex;justify-content:space-between;gap:16px;align-items:flex-start}\n.og summary::-webkit-details-marker{display:none}\n.og summary::after{content:\"+\";font-size:22px;line-height:1;color:var(--peri-700);flex:0 0 auto}\n.og details[open] summary::after{content:\"\\2013\"}\n.og details p{padding:0 20px 18px;margin:0;font-size:16px;line-height:1.7}\n\n.og .related{font-size:15px;color:var(--muted);border-top:1px solid var(--divider);padding-top:22px;margin-top:40px}\n\n@media(max-width:700px){\n  .og{font-size:16px}\n  .og .dek{font-size:18px}\n  .og .short p{font-size:17px}\n  .og .short,.og .toc,.og .callout{padding:22px 20px}\n  .og .toc ol{columns:1}\n  .og .trio{grid-template-columns:1fr}\n  .og .swipe{display:inline;font-weight:600;color:var(--peri-700)}\n  .og table{font-size:14px}\n  .og th,.og td{padding:11px 12px}\n}\n<\/style>\n<div class=\"og\">\n<p class=\"dek\">Insybit was one signature away from a contract with one of India&#8217;s largest insurance companies when the insurer&#8217;s security questionnaire arrived. After a week of getting nowhere with other vendors, it was answered in 48 hours with Osto, and the deal closed.<\/p>\n<ul class=\"tags\">\n  <li><span class=\"tag t-peri\">Case study<\/span><\/li>\n  <li><span class=\"tag t-sage\">Security questionnaire<\/span><\/li>\n<\/ul>\n<div class=\"short\">\n  <p class=\"k\">TL;DR<\/p>\n  <p>Insybit, an AI-powered marketing intelligence company, needed to clear an enterprise security questionnaire before a large Indian insurer would sign. Co-founder and CEO Saurabh Aggarwal spent close to a week looking for help without finding anyone who could move fast enough. Osto deployed real security controls, answered the security questionnaire from those running controls, and had it submitted within 48 hours of engagement. The insurer&#8217;s review cleared and the contract was signed.<\/p>\n<\/div>\n<div class=\"trio\">\n  <div class=\"tcard a\">\n    <p class=\"n\">48 hours<\/p>\n    <p class=\"g\">From engagement to submission<\/p>\n    <p>After five to seven days of going around the market with no answer.<\/p>\n  <\/div>\n  <div class=\"tcard b\">\n    <p class=\"n\">Contract signed<\/p>\n    <p class=\"g\">With a major Indian insurer<\/p>\n    <p>A deal worth roughly Rs 15 to 16 lakh moved to signature once the review cleared.<\/p>\n  <\/div>\n  <div class=\"tcard c\">\n    <p class=\"n\">20x+ return<\/p>\n    <p class=\"g\">On the Osto subscription<\/p>\n    <p>From this one contract alone, before counting any deal that follows.<\/p>\n  <\/div>\n<\/div>\n<p>The work was done and the relationship was strong. What stood between Insybit and the contract was a form.<\/p>\n<div class=\"toc\">\n  <p class=\"k\">On this page<\/p>\n  <ol>\n    <li><a href=\"#gate\">One questionnaire away from signing<\/a><\/li>\n    <li><a href=\"#insybit\">What Insybit is<\/a><\/li>\n    <li><a href=\"#asked\">What the security questionnaire asked<\/a><\/li>\n    <li><a href=\"#done\">What Osto did in 48 hours<\/a><\/li>\n    <li><a href=\"#written\">Why written answers were not enough<\/a><\/li>\n    <li><a href=\"#results\">The results<\/a><\/li>\n    <li><a href=\"#lessons\">What other founders can take from this<\/a><\/li>\n    <li><a href=\"#faq\">FAQ<\/a><\/li>\n  <\/ol>\n<\/div>\n\n<h2 id=\"gate\">One questionnaire away from signing<\/h2>\n<p>Insybit had been working toward a contract with one of India&#8217;s largest insurance companies for a while. The client liked the work, and the contract was close. Then procurement sent over the vendor security questionnaire.<\/p>\n<p>For a large insurer this is standard. Before any technology vendor touches their data or systems, their procurement and IT security teams need evidence that the vendor meets a defined security bar. It is a gate, and the contract does not move until the security questionnaire is answered to their satisfaction.<\/p>\n<p>Insybit had never needed a formal security programme. It had spent its energy on client results, and nothing about its controls was documented in the shape an enterprise security team expects. The questionnaire asked about things the team had simply never had to write down.<\/p>\n\n<h2 id=\"insybit\" class=\"c-sage\">What Insybit is<\/h2>\n<p>Insybit is an AI-powered marketing intelligence company based in Gurugram, led by co-founder and CEO Saurabh Aggarwal. It builds data-driven solutions and custom AI tools that help brands make better decisions across their marketing stack, from Google Analytics and Adobe Analytics to WhatsApp engagement, conversion rate optimisation and marketing automation.<\/p>\n<table class=\"h-sage\">\n  <thead>\n    <tr><th style=\"width:30%\">At a glance<\/th><th>Insybit<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td>Leadership<\/td><td>Saurabh Aggarwal, Co-founder and CEO<\/td><\/tr>\n    <tr><td>Headquarters<\/td><td>Gurugram, India<\/td><\/tr>\n    <tr><td>Industry<\/td><td>AI-powered marketing intelligence<\/td><\/tr>\n    <tr><td>Works across<\/td><td>Analytics, WhatsApp engagement, CRO, marketing automation and custom AI tooling<\/td><\/tr>\n    <tr><td>Clients<\/td><td>Large enterprise brands, including one of India&#8217;s largest insurers<\/td><\/tr>\n  <\/tbody>\n<\/table>\n<p>That position in the stack is exactly why the security question came up. A traditional agency runs campaigns. Insybit works inside a client&#8217;s analytics and customer engagement data and builds tooling on top of it. For a regulated insurer, a vendor with that kind of access gets reviewed properly, however good the work is.<\/p>\n\n<h2 id=\"asked\" class=\"c-plum\">What the security questionnaire asked<\/h2>\n<p>The insurer&#8217;s security questionnaire covered five areas. None of them could be answered with a promise.<\/p>\n<table class=\"h-plum\">\n  <thead>\n    <tr><th>Area<\/th><th>Status<\/th><th>What the reviewer wants to see<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td><a href=\"https:\/\/www.osto.one\/resources\/glossary\/api-security\/\">API security<\/a><\/td><td><span class=\"pill p-req\">Required<\/span><\/td><td>How exposed endpoints are protected against abuse and common attacks<\/td><\/tr>\n    <tr><td>Data handling<\/td><td><span class=\"pill p-req\">Required<\/span><\/td><td>Where client data lives, how it is stored and who can reach it<\/td><\/tr>\n    <tr><td>Access controls<\/td><td><span class=\"pill p-req\">Required<\/span><\/td><td>How access to systems and data is granted, limited and removed<\/td><\/tr>\n    <tr><td><a href=\"https:\/\/www.osto.one\/resources\/glossary\/incident-response\/\">Incident response<\/a><\/td><td><span class=\"pill p-req\">Required<\/span><\/td><td>What happens, and who is told, if something goes wrong<\/td><\/tr>\n    <tr><td>Certifications<\/td><td><span class=\"pill p-ask\">Asked<\/span><\/td><td>Any audited proof of the above, such as SOC 2 or ISO 27001<\/td><\/tr>\n  <\/tbody>\n<\/table>\n<div class=\"callout\">\n  <p class=\"k\">The week that went nowhere<\/p>\n  <p>Saurabh spent five to seven days reaching out to vendors across the market. Nobody could move at the speed the deal needed, and nobody could handle both the answers and the security those answers referred to. The contract sat unsigned the whole time. Insybit reached Osto through a shared network connection.<\/p>\n<\/div>\n<figure>\n<div class=\"sx\">\n<svg viewBox=\"0 52 760 160\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" role=\"img\" aria-label=\"Timeline: five to seven days searching for vendors with no result, then Osto engaged, controls deployed, the questionnaire answered and submitted within 48 hours, and the contract signed.\">\n  <defs><marker id=\"isA\" markerWidth=\"8\" markerHeight=\"8\" refX=\"6.5\" refY=\"4\" orient=\"auto\"><path d=\"M0,0 L8,4 L0,8 z\" fill=\"#4a52a8\"\/><\/marker><\/defs>\n  <rect x=\"14\" y=\"70\" width=\"250\" height=\"70\" rx=\"13\" fill=\"#fbe9dc\"\/>\n  <text x=\"139\" y=\"99\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"700\" fill=\"#a2603a\">5 to 7 days<\/text>\n  <text x=\"139\" y=\"119\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10.5\" fill=\"#0f1538\">Vendor outreach, no answer, deal waiting<\/text>\n  <line x1=\"268\" y1=\"105\" x2=\"286\" y2=\"105\" stroke=\"#4a52a8\" stroke-width=\"2\" marker-end=\"url(#isA)\"\/>\n  <rect x=\"292\" y=\"70\" width=\"104\" height=\"70\" rx=\"13\" fill=\"#1c267a\"\/>\n  <text x=\"344\" y=\"99\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"700\" fill=\"#ffffff\">Osto<\/text>\n  <text x=\"344\" y=\"118\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10.5\" fill=\"#b9c1e6\">engaged<\/text>\n  <line x1=\"400\" y1=\"105\" x2=\"418\" y2=\"105\" stroke=\"#4a52a8\" stroke-width=\"2\" marker-end=\"url(#isA)\"\/>\n  <rect x=\"424\" y=\"70\" width=\"112\" height=\"70\" rx=\"13\" fill=\"#cfd5f2\"\/>\n  <text x=\"480\" y=\"99\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"700\" fill=\"#4a52a8\">Controls live<\/text>\n  <text x=\"480\" y=\"118\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10.5\" fill=\"#0f1538\">WAF and CSPM<\/text>\n  <line x1=\"540\" y1=\"105\" x2=\"558\" y2=\"105\" stroke=\"#4a52a8\" stroke-width=\"2\" marker-end=\"url(#isA)\"\/>\n  <rect x=\"564\" y=\"70\" width=\"90\" height=\"70\" rx=\"13\" fill=\"#cfd5f2\"\/>\n  <text x=\"609\" y=\"99\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"700\" fill=\"#4a52a8\">Answered<\/text>\n  <text x=\"609\" y=\"118\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10.5\" fill=\"#0f1538\">and submitted<\/text>\n  <line x1=\"658\" y1=\"105\" x2=\"672\" y2=\"105\" stroke=\"#3a6f5d\" stroke-width=\"2\" marker-end=\"url(#isA)\"\/>\n  <rect x=\"676\" y=\"70\" width=\"72\" height=\"70\" rx=\"13\" fill=\"#e3f0e9\"\/>\n  <text x=\"712\" y=\"99\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"700\" fill=\"#3a6f5d\">Deal<\/text>\n  <text x=\"712\" y=\"118\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"700\" fill=\"#3a6f5d\">signed<\/text>\n  <line x1=\"292\" y1=\"168\" x2=\"654\" y2=\"168\" stroke=\"#4a52a8\" stroke-width=\"1.5\"\/>\n  <line x1=\"292\" y1=\"160\" x2=\"292\" y2=\"176\" stroke=\"#4a52a8\" stroke-width=\"1.5\"\/>\n  <line x1=\"654\" y1=\"160\" x2=\"654\" y2=\"176\" stroke=\"#4a52a8\" stroke-width=\"1.5\"\/>\n  <text x=\"473\" y=\"196\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"700\" fill=\"#4a52a8\">48 hours<\/text>\n<\/svg>\n<\/div>\n<figcaption>The 48 hours ran from engagement to submission. The insurer&#8217;s own review time sits on top of that.<\/figcaption>\n<\/figure>\n\n<h2 id=\"done\" class=\"c-sky\">What Osto did in 48 hours<\/h2>\n<p>Osto took on both halves of the problem at once: the security the questionnaire was asking about, and the questionnaire itself. Answering credibly meant having real controls in place first, so that is where the work started.<\/p>\n<p><strong>A web application firewall in front of the application.<\/strong> Osto&#8217;s <a href=\"https:\/\/www.osto.one\/resources\/glossary\/waf\/\">WAF<\/a> went live in front of Insybit&#8217;s application and APIs, blocking common attacks and bot traffic before it reached the origin. That gave the application and API security questions a running control to point to.<\/p>\n<p><strong>CSPM across the cloud environment.<\/strong> <a href=\"https:\/\/www.osto.one\/resources\/glossary\/cspm\/\">Cloud security posture management<\/a> scanned Insybit&#8217;s cloud setup for exposed storage, over-permissive access and similar misconfigurations, and tracked each fix. That gave the data handling and access questions something concrete behind them.<\/p>\n<p><strong>The questionnaire, answered from the stack.<\/strong> With the controls running, Osto worked through the security questionnaire and wrote each answer from what was actually deployed rather than from a policy template. It was answered and submitted within 48 hours of engagement.<\/p>\n<div class=\"callout c-plum\">\n  <p>&#8220;We had spent almost a week trying to figure this out with different vendors. Nothing was moving. Osto came in, understood the problem immediately, and had us sorted in 48 hours. The deal closed.&#8221;<\/p>\n  <p><strong>Saurabh Aggarwal<\/strong>, Co-founder and CEO, Insybit<\/p>\n<\/div>\n\n<h2 id=\"written\" class=\"c-apri\">Why written answers were not enough<\/h2>\n<p>A security questionnaire can be filled in with policy documents in an afternoon. Enterprise reviewers know that, which is why the follow-up questions exist. A completed questionnaire is also often referenced in the contract, so every answer becomes something the vendor has committed to.<\/p>\n<table class=\"h-peri\">\n  <thead>\n    <tr><th>When the reviewer<\/th><th>Policy-only answer<\/th><th>Control-backed answer<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td>Asks for evidence<\/td><td>Another document<\/td><td>A screenshot, a report or a log from the running control<\/td><\/tr>\n    <tr><td>Asks a follow-up<\/td><td>A scramble to find out what is actually true<\/td><td>A quick look at the dashboard<\/td><\/tr>\n    <tr><td>Writes it into the contract<\/td><td>A commitment nobody is yet meeting<\/td><td>A description of what is already happening<\/td><\/tr>\n    <tr><td>Sends the next questionnaire<\/td><td>The same scramble again<\/td><td>Answers that already exist and can be reused<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<h2 id=\"results\" class=\"c-sage\">The results<\/h2>\n<table class=\"h-sage\">\n  <thead>\n    <tr><th>Outcome<\/th><th>Status<\/th><th>What happened<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td>Security questionnaire<\/td><td><span class=\"pill p-yes\">Done<\/span><\/td><td>Answered and submitted within 48 hours of engaging Osto, after a week stuck elsewhere<\/td><\/tr>\n    <tr><td>Insurance contract<\/td><td><span class=\"pill p-yes\">Done<\/span><\/td><td>The insurer&#8217;s review cleared and a contract worth roughly Rs 15 to 16 lakh was signed<\/td><\/tr>\n    <tr><td>WAF and CSPM<\/td><td><span class=\"pill p-yes\">Live<\/span><\/td><td>Running controls that the next enterprise questionnaire can be answered from<\/td><\/tr>\n    <tr><td>VAPT and source code assessment<\/td><td><span class=\"pill p-exp\">Next<\/span><\/td><td>A structured test of the application and codebase, so findings are fixed before a client audit finds them<\/td><\/tr>\n    <tr><td>SOC 2 and ISO 27001<\/td><td><span class=\"pill p-exp\">Next<\/span><\/td><td>Audited certification as the enterprise client base grows<\/td><\/tr>\n  <\/tbody>\n<\/table>\n<p>The contract value is the easy number to point to. The bigger change is what happens next time. Before Osto, every enterprise security questionnaire would have meant the same week of outreach and the same uncertainty about whether the deal would hold. Now the controls are running and the answers exist, so the next review starts from evidence instead of a blank form.<\/p>\n\n<h2 id=\"lessons\">What other founders can take from this<\/h2>\n<div class=\"trio\">\n  <div class=\"tcard a\">\n    <p class=\"n\">The gate comes late<\/p>\n    <p class=\"g\">Usually after the deal is won<\/p>\n    <p>Enterprise buyers send the security questionnaire once they have decided they want you, which is when a delay hurts most.<\/p>\n  <\/div>\n  <div class=\"tcard b\">\n    <p class=\"n\">Answers need controls<\/p>\n    <p class=\"g\">Documents alone fall short<\/p>\n    <p>The fastest credible response comes from someone who can deploy the security and write the answers together.<\/p>\n  <\/div>\n  <div class=\"tcard c\">\n    <p class=\"n\">The second one is cheaper<\/p>\n    <p class=\"g\">Evidence gets reused<\/p>\n    <p>Once controls are live and answers are banked, the next buyer&#8217;s review is mostly retrieval.<\/p>\n  <\/div>\n<\/div>\n<p>For a step-by-step view of the process, the <a href=\"https:\/\/www.osto.one\/resources\/guides\/security-questionnaires-for-startups\/\">security questionnaire guide for startups<\/a> covers it in detail, and <a href=\"https:\/\/www.osto.one\/resources\/blog\/security-questionnaire-killed-enterprise-deal\/\">this breakdown of a deal lost to a questionnaire<\/a> shows what happens when the gate is not cleared.<\/p>\n\n<h2 id=\"osto\" class=\"c-sky\">How Osto handles security questionnaires<\/h2>\n<p>Osto answers a <a href=\"https:\/\/www.osto.one\/resources\/glossary\/security-questionnaire\/\">security questionnaire<\/a> from your live control state. <a href=\"https:\/\/www.osto.one\/resources\/glossary\/waf\/\">Web and API protection<\/a>, cloud posture, endpoint, access and <a href=\"https:\/\/www.osto.one\/resources\/glossary\/vapt\/\">VAPT<\/a> all run in the same platform, so an answer about <a href=\"https:\/\/www.osto.one\/resources\/glossary\/mfa\/\">MFA<\/a> coverage or <a href=\"https:\/\/www.osto.one\/resources\/glossary\/encryption-at-rest\/\">encryption at rest<\/a> comes from the system enforcing it. The same controls map to <a href=\"https:\/\/www.osto.one\/resources\/glossary\/soc-2\/\">SOC 2<\/a>, <a href=\"https:\/\/www.osto.one\/resources\/glossary\/iso-27001\/\">ISO 27001<\/a> and the <a href=\"https:\/\/www.osto.one\/resources\/glossary\/dpdp-act\/\">DPDP Act<\/a>, and every answer is kept for the next buyer.<\/p>\n<p>No in-house security team is needed. The certificate is a byproduct of the security, not the other way around.<\/p>\n\n<!-- ============ CTA ============ -->\n<div style=\"background:linear-gradient(135deg,#1c267a 0%,#3f4796 48%,#6b4576 100%);border-radius:22px;padding:38px 34px;margin:40px 0 12px;box-shadow:0 10px 26px rgba(28,38,122,.2);text-align:center;\">\n  <p style=\"display:inline-block;background:rgba(255,255,255,.16);color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:11px;font-weight:700;letter-spacing:1.2px;text-transform:uppercase;padding:6px 14px;border-radius:20px;margin:0 0 16px;\">Platform walkthrough<\/p>\n  <p style=\"color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:26px;line-height:1.3;font-weight:700;letter-spacing:-.4px;margin:0 0 12px;\">Clear the security gate before it blocks a deal<\/p>\n  <p style=\"color:#cfd3ea;font-family:'Inter',-apple-system,sans-serif;font-size:16px;line-height:1.65;margin:0 auto 26px;max-width:520px;\">Osto deploys the controls and answers the security questionnaire from them, so your next enterprise review starts with evidence already in place.<\/p>\n  <a href=\"https:\/\/osto.one\/book-demo\/\" style=\"display:inline-block;background:#ffffff;color:#1c267a;font-family:&#039;Inter&#039;,-apple-system,sans-serif;font-weight:700;font-size:16px;text-decoration:none;border-bottom:none;padding:14px 32px;border-radius:12px;margin:0;\" target=\"_blank\" rel=\"noopener\"><span style=\"color:#1c267a;\">Book a demo<\/span><\/a>\n  <p style=\"color:#b3b8d8;font-family:'Inter',-apple-system,sans-serif;font-size:13px;margin:18px 0 0;\">One platform, everything &middot; Security without slowing down<\/p>\n<\/div>\n\n<h2 id=\"faq\">Frequently asked questions<\/h2>\n<details>\n  <summary>How did Insybit answer a security questionnaire in 48 hours?<\/summary>\n  <p>Osto deployed a web application firewall and cloud security posture management first, then wrote each answer from those running controls rather than from policy templates. The completed security questionnaire was submitted within 48 hours of engaging Osto, after Insybit had spent close to a week trying other vendors.<\/p>\n<\/details>\n<details>\n  <summary>What does an insurance company security questionnaire usually cover?<\/summary>\n  <p>Typically application and API security, data handling and storage, access controls, incident response and breach notification, and any certifications such as SOC 2 or ISO 27001. Indian insurers are regulated by IRDAI, whose cybersecurity guidelines extend to vendors that handle their data, so these reviews tend to be thorough.<\/p>\n<\/details>\n<details>\n  <summary>Can you answer a security questionnaire without SOC 2 or ISO 27001?<\/summary>\n  <p>Yes, if the answers are true and backed by controls. A certificate answers whole sections at once, but many buyers will accept evidence from running controls, with certification shown as planned work. Insybit had neither certification when it cleared the insurer&#8217;s review.<\/p>\n<\/details>\n<details>\n  <summary>Why do security questionnaires stall enterprise deals?<\/summary>\n  <p>Because they arrive late, usually after the buyer has decided, and they need evidence rather than opinions. A team without documented controls has to find a vendor, deploy something and then write answers, all while the contract waits. That lead time is the stall.<\/p>\n<\/details>\n<details>\n  <summary>How does Osto speed up security questionnaires?<\/summary>\n  <p>Security controls and questionnaire answers come from the same platform. Osto&#8217;s AI Security Questionnaires draft answers from the live control state, the team reviews them, and every approved answer is kept, so the second questionnaire takes a fraction of the time of the first.<\/p>\n<\/details>\n<p class=\"related\"><strong>Related glossary terms:<\/strong> <a href=\"https:\/\/www.osto.one\/resources\/glossary\/security-questionnaire\/\">Security Questionnaire<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/waf\/\">WAF<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/cspm\/\">CSPM<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/api-security\/\">API Security<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/incident-response\/\">Incident Response<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/vapt\/\">VAPT<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/soc-2\/\">SOC 2<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/iso-27001\/\">ISO 27001<\/a><\/p>\n<\/div>\n\n<script type=\"application\/ld+json\">\n{\n \"@context\": \"https:\/\/schema.org\",\n \"@type\": \"FAQPage\",\n \"mainEntity\": [\n  {\n   \"@type\": \"Question\",\n   \"name\": \"How did Insybit answer a security questionnaire in 48 hours?\",\n   \"acceptedAnswer\": {\n    \"@type\": \"Answer\",\n    \"text\": \"Osto deployed a web application firewall and cloud security posture management first, then wrote each answer from those running controls rather than from policy templates. The completed security questionnaire was submitted within 48 hours of engaging Osto, after Insybit had spent close to a week trying other vendors.\"\n   }\n  },\n  {\n   \"@type\": \"Question\",\n   \"name\": \"What does an insurance company security questionnaire usually cover?\",\n   \"acceptedAnswer\": {\n    \"@type\": \"Answer\",\n    \"text\": \"Typically application and API security, data handling and storage, access controls, incident response and breach notification, and any certifications such as SOC 2 or ISO 27001. Indian insurers are regulated by IRDAI, whose cybersecurity guidelines extend to vendors that handle their data, so these reviews tend to be thorough.\"\n   }\n  },\n  {\n   \"@type\": \"Question\",\n   \"name\": \"Can you answer a security questionnaire without SOC 2 or ISO 27001?\",\n   \"acceptedAnswer\": {\n    \"@type\": \"Answer\",\n    \"text\": \"Yes, if the answers are true and backed by controls. A certificate answers whole sections at once, but many buyers will accept evidence from running controls, with certification shown as planned work. Insybit had neither certification when it cleared the insurer's review.\"\n   }\n  },\n  {\n   \"@type\": \"Question\",\n   \"name\": \"Why do security questionnaires stall enterprise deals?\",\n   \"acceptedAnswer\": {\n    \"@type\": \"Answer\",\n    \"text\": \"Because they arrive late, usually after the buyer has decided, and they need evidence rather than opinions. A team without documented controls has to find a vendor, deploy something and then write answers, all while the contract waits. That lead time is the stall.\"\n   }\n  },\n  {\n   \"@type\": \"Question\",\n   \"name\": \"How does Osto speed up security questionnaires?\",\n   \"acceptedAnswer\": {\n    \"@type\": \"Answer\",\n    \"text\": \"Security controls and questionnaire answers come from the same platform. Osto's AI Security Questionnaires draft answers from the live control state, the team reviews them, and every approved answer is kept, so the second questionnaire takes a fraction of the time of the first.\"\n   }\n  }\n ]\n}\n<\/script>\n","protected":false},"excerpt":{"rendered":"<p>Insybit was one signature away from a contract with one of India&#8217;s largest insurance companies when the insurer&#8217;s security questionnaire\u2026<\/p>\n","protected":false},"author":8,"featured_media":1176,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[42],"tags":[31],"class_list":["post-1175","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-case-studies","tag-security-questionnaire"],"_links":{"self":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1175","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/comments?post=1175"}],"version-history":[{"count":1,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1175\/revisions"}],"predecessor-version":[{"id":1177,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1175\/revisions\/1177"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media\/1176"}],"wp:attachment":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media?parent=1175"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/categories?post=1175"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/tags?post=1175"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}