Before You Start
Have these on hand:- The invitation email containing your secure collection portal link and one-time passcode
- Your current security, privacy, compliance, resilience, and related risk documentation — provide whichever materials are available and relevant to your organization and services. Examples include:
- Independent assurance reports and certifications (e.g., SOC 1/SOC 2, ISO certifications and Statement of Applicability)
- Penetration testing, vulnerability assessment, or other independent security testing reports
- PCI DSS RoC/AoC or other industry/regulatory attestations
- Information security, data protection, privacy, and compliance policies
- Business continuity, disaster recovery, incident response, and operational resilience documentation
- Artificial intelligence governance, security, or responsible AI policies
- Cyber insurance certificates
- BAAs, DPAs, or other relevant data protection/security agreements
- Architecture, network, or data-flow diagrams
- Risk assessments, security assessments, or audit reports
- Any other documentation that demonstrates your security, privacy, compliance, AI governance, or resilience controls
Step-by-Step
1
Open your invitation
You’ll receive an email with a secure link and passcode to your collection portal. Select Respond to Request to begin. VISO TRUST also sends reminder emails while the request is open.If you can’t find the email, check your spam folder or ask your contact at the requesting organization to resend it.

2
Enter the collection portal
The Welcome page names the organization assessing you and summarizes what’s being requested — the specific documents and any questions. There’s no long questionnaire to fill in by hand. Select Get started to continue.A sidebar tracks your progress through the four stages: Welcome, Upload artifacts, Provide information, and Submit.
If the request is due to expire within a week, you’ll see a Need more time option. Select it to extend the request by an additional week.

3
Upload your documents
On Upload artifacts, add each requested item by dragging and dropping a file or selecting select files. Each artifact type shows examples of what qualifies — hover an item such as Third party audits to see them. Each document is analyzed automatically once uploaded, so you don’t answer questions the documents already cover.

4
Handle anything you don't have
You can’t leave a request blank. For any document you don’t have or can’t share, mark the attestation that you do not have, or will not provide, that item — this lets the assessment proceed.
5
Answer any additional questions
On Provide information, answer any questions the requesting organization included. All questionnaires appear on a single page, organized into sections, with a navigation panel showing each section’s progress. Complete all required questions before submitting — if any are missing, the portal jumps you to the first unanswered question.
6
Certify and submit
On Submit, certify that the information you’ve provided is accurate and submit. This records your formal attestation and time-stamps it.
7
What happens next
Follow up Questionnaires: If controls remain unvalidated after initial review, a client may send a focused follow-up questionnaire — a few targeted questions, not a full re-do. All questionnaires in the request appear on a single page, organized into sections — the standard VISO TRUST questionnaire followed by any supplemental questionnaires. A navigation panel beside the questions lists each section with its answered count and progress, and highlights the section currently in view.
If any responses are missing, the portal jumps to the first unanswered question so the vendor can fill in the gaps.
The portal shows a Certify and Submit page in the end.Remediation Request: If more information/artifacts are required, a client may send a remediation request. You receive an email from VISO TRUST with link and passcode and the remediation request(s) listed and the target due date. You’ll receive the remediation email again 30 days before the target due date. Once you submit the required information, you’re done.
If any responses are missing, the portal jumps to the first unanswered question so the vendor can fill in the gaps.
The portal shows a Certify and Submit page in the end.Remediation Request: If more information/artifacts are required, a client may send a remediation request. You receive an email from VISO TRUST with link and passcode and the remediation request(s) listed and the target due date. You’ll receive the remediation email again 30 days before the target due date. Once you submit the required information, you’re done.
If You’re Not the Right Person
Two options are available from the Welcome page:- Forward the request — send it to the right colleague. They receive a new email with their own secure link and passcode.
- Opt out — use this only if your organization is no longer doing business with the requesting organization. Opting out ends the assessment and can’t be undone.
What Happens Next
Follow-up questionnaires. If controls remain unvalidated after the initial review, the requesting organization may send a focused follow-up questionnaire — a few targeted questions, not a full re-do. You typically have 7 days to respond. The portal experience is the same as the initial request. Remediation requests. If specific control gaps need to be closed, the requesting organization may send a remediation request. You’ll receive an email from VISO TRUST with a link, a passcode, the requested items, and a target due date, plus a reminder 30 days before that date. Once you submit the required information, you’re done.Quick FAQ
Do I need a password or account? No account is needed. Access is through the secure link and passcode provided in your invitation email — just follow the portal’s prompts. Which documents should I send? Whatever the request lists — commonly a SOC 2 or ISO 27001 report, a pen test summary, key policies, and insurance. Provide what you have and attest for what you don’t. Our documents are confidential. Uploads go through a secure portal, and VISO TRUST maintains strict data protection practices:- Encryption — all data is encrypted in transit and at rest using industry-standard protocols.
- Access control — only authorized personnel can access your data, governed by strict access controls to prevent unauthorized use or sharing.
Related Pages
- Assessments — how the requesting organization runs the assessment
- Questionnaire Answering — more detail on the collection portal and follow-up questionnaires
- Trust Profiles — keep your documentation in one place so future requests answer themselves