A client asked for proof.
Start with what you can verify.

A security questionnaire mixes device facts with business commitments. Separating them is the first useful answer.

Practical guide5 minute read

The questionnaire often arrives just before a contract is signed. Before ticking the boxes, identify which answers you can support with evidence and who owns the rest.

Three questions hiding in one document.

“Are your devices encrypted?” asks about a technical control. “Do you maintain an incident response plan?” asks about how the business operates. “Are you certified?” asks for a separate kind of assurance. One record cannot turn these into the same thing.

Device facts

What can be observed?

Encryption, protection status, patch status, and configuration on the machines actually assessed.

Business practices

Who owns the answer?

Access decisions, backups, policies, supplier reviews and the people responsible for them.

External assurance

What was independently assessed?

Certification and audit evidence, where required. A technical report does not create either.

Start by marking each question with its evidence source and its owner. If the wording covers more than one area, split the answer rather than stretching a device result to cover the business.

Replace “yes” with a record.

An answer is stronger when the reader can identify the devices, the period, the observed state and the exceptions. A screenshot of a setting may show one device at one moment. It does not, by itself, establish the same state across a team or over a period.

Illustrative answer · fictional team and device data
“Are all company laptops encrypted?”
Too broad

Yes. Our laptops are encrypted.

Scoped to the evidence

Disk encryption was observed on the seven Macs assessed for this record. An eighth listed Mac was not assessed and is excluded from this answer. The record states the observation dates for each device.

Seven observed. One unknown. Neither disappears in the summary.

In cybee, the Trust Passport is a dated, sealed technical record. It identifies what the assessed Macs reported and makes the gaps part of the same page. The recipient can check that the page has not changed against cybee’s sealed copy. That check establishes integrity; it is not independent assurance about the organisation.

An unknown needs an owner, not a green tick.

A missing device may be offline, unenrolled or outside the supported scope. None of those states means it is secure. Say “seven of eight Macs assessed” so the missing device stays visible.

The same discipline applies beyond devices. A Mac’s encryption state says nothing about the recovery of a cloud account. A clean protection status says nothing about whether backups can be restored. Give those questions to the person who owns the service or process, and attach the relevant evidence separately. For connected Google Workspace accounts, cybee provides account activity and MFA observations in their own record. See the Google Workspace scope

A score is a summary.

Read it together with its benchmark, assessment date, device coverage and open findings. Improving the score does not turn unassessed systems into assessed ones.

If a gap can be fixed, record the change and assess again. Keep the earlier record distinct from the later one. A correction today should never become a statement that the setting had always been correct.

Training is another part of the security work. cybee includes short modules and completion tracking in the paid plan. The device record does not answer the training question. Security training

Send the answer with its limits attached.

  1. Match the question.

    Check whether it asks about devices, the whole company, a period, or a specific system.

  2. Check the covered devices.

    Confirm that the devices relevant to the client’s request appear in the record. Explain any that do not.

  3. Read the exceptions.

    Open findings and missing observations belong in the response, alongside the passing controls.

  4. Keep a copy of what was sent.

    Record the answer, its evidence and the date. A later record is a new piece of evidence.

  5. Let the client decide.

    A Trust Passport supports the review. The client decides whether it answers the request.

Review any assistant-written answer against the evidence before sharing it. A question from a client is not permission to change settings or share unrelated information.

What the Trust Passport answers.

What the device record covers.

Evidence about assessed Macs

Encryption, endpoint protection, application patch status, screen lock, and installed browser extensions and AI tools.

Separate evidence required

Google Workspace accounts and multi-factor authentication (MFA) have their own record. Backups, training completion, incident plans, policies, code, suppliers and people need separate evidence.

Read the coverage details

On a typical questionnaire the passport answers, with dates, the questions about your Macs: disk encryption on every listed Mac; endpoint protection that watches behaviour, and since when; the patch status of your applications; screen lock and password on wake; the browser extensions and AI tools installed. This device record does not cover accounts and MFA. Connected Google Workspace has its own account record, within the connected organisation. Backups, training completion and the incident plan also need separate evidence. Policies, code, suppliers and people need their own evidence.

cybee brings together device protection, hardening and the record of those controls. Protection observes and responds to suspicious activity. Hardening changes configuration to reduce exposure. The record then explains the observed state and its history. Each has a different job.

Read the Trust Passport guide

Provable security: protection, hardening, and a dated record that proves both to whoever asks.

The device scope is supported Macs. The record is not a certification, an audit opinion or a guarantee that a recipient will accept it.

Stronger security.
Proof built in.

Protection for your devices. A record of the work.

Start in your Chat, CLI, IDE or TerminalmacOS
curl -sSf https://get.cybee.dev | sh
Read the installation guide

Copying the command does not install anything.