How Winnow works

A security questionnaire is really two jobs in one envelope: writing down what is true about your product, and convincing somebody who has every reason to be sceptical. Winnow does both.

Answers the whole thing

Send the questionnaire in whatever form it arrived — a spreadsheet, a document, a link to somebody’s portal — and point us at your product. Every question comes back with an answer, in their format, ready to send. No blank page, no lost week.

Backs it up with proof

Plenty of these questions have an answer that can be established rather than asserted. Wherever that is true, Winnow goes and establishes it, and the evidence travels with the answer — so the person reading it can check your working instead of trusting you.

Tells you what to fix

Occasionally the honest answer is not the one you wanted. When that happens you hear it from us first, with a clear account of what is actually wrong and what it would take to put right — a short list you can act on, well before the customer sees anything.

Keeps up with your releases

An honest answer has a shelf life. Your product changes with every release, and answers written last year quietly stop being true. Winnow keeps them current, so the next customer gets today’s position and you are never defending a document you have outgrown.

Two kinds of answer

Not everything on one of these forms can be proved, and pretending otherwise is how the whole exercise lost its credibility. So we label every answer for what it honestly is.

Checked
We went and looked

Anything that can be established about the product you actually ship. The answer arrives with its evidence and the date it was confirmed, so the person reading it can satisfy themselves rather than take it on faith.

  • What your product is built from, and which parts genuinely matter
  • How it updates itself, and whether that can be tampered with
  • What it sends out, and where that goes
Stated
You told us, once

Everything that lives in a policy rather than in the product. Write it a single time and Winnow reuses it from then on, noting who approved it and when, clearly marked as a statement rather than a measurement.

  • How your team builds and reviews software
  • What happens when somebody reports a problem
  • Certifications, audits and outside reports

Most vendors send back a wall of undifferentiated text and hope nobody pushes back. Saying plainly which answers are proof and which are policy makes the whole document easier to believe — including the parts you couldn’t prove.

How we check

For the answers we can establish, there are three levels of proof. Each is harder evidence than the last, and most tools stop at the first.

1
Read the records

Start with what your build says about itself: the parts it was assembled from, how it was put together, how the service behind it is set up. Necessary, quick, and not remotely the same thing as proof — but it is as far as most tooling goes.

2
Work out what’s really true

Records are often wrong in both directions. A component listed as faulty was repaired months ago without its version number changing; another looks fine but was never updated. We work out what is actually in the thing you ship and which of it anyone could reach — the difference between a frightening list and a real problem.

3
Try it ourselves

The strongest evidence there is. With your permission and on equipment you nominate, we test the claim rather than reason about it — attempt the tampered update and confirm it is refused, watch what the product genuinely sends. Results with a date on them that nobody has to take on trust.

What Winnow isn’t

Security companies have a habit of implying they cover everything. Here is a straight list of what we don’t do, so nobody finds out the awkward way:

  • Not antivirus, and nothing that gets installed on your customers’ machines
  • Not a monitoring service with people watching screens overnight
  • Not a penetration test, and not a replacement for having one done
  • Not an auditor — we’ll help you answer the questions, but we don’t issue certificates
  • Not a lawyer: the commercial and contractual questions on these forms are still yours

What we do is narrow on purpose. Know what is genuinely true about the product you ship, put it in a form somebody else can check, and keep it that way as you release.

Keep in the loop