Answer the security questionnaire with proof, not adjectives
Every enterprise deal has that row: "Do you regularly test for vulnerabilities?" Most founders answer with a promise. Notra gives you something better to attach — a manifest-pinned run with request/response exhibits on every finding, produced the same week the customer asked.
The row you can actually win
The question
'Do you perform regular security testing?' Answering yes without evidence is a promise. Attaching a dated, methodology-pinned report from a third party is an answer.
The evidence
Every Notra finding ships the exact HTTP request and response that proved it, and every run is manifest-pinned. The reviewer's engineer can verify your answer themselves.
The honest boundary
The report is evidence of testing, not an auditor's letter. Say that up front in the questionnaire and you build more trust than hiding it ever would.
What to attach, and how to phrase it
The verified report: scope, manifest-pinned settings, findings with their proof-of-exploit exhibits, and the plain-English fixes — including the ones you already shipped. Redact anything sensitive; the evidence survives redaction.
'Yes — our production application is tested by an independent automated audit (Notra); the attached report shows methodology, date, and evidence for each verified finding. Re-runs occur after significant changes.' True, specific, and checkable.
If the reviewer insists on a human engagement anyway, show them the honest comparison — and keep Notra running between the consultancy's visits. The two are complements, not rivals.
Keeping the answer fresh
Re-run on demand
The audit is a flat $149 credit. Re-run it after major changes so the report you attach is never stale.
Monitor for freshness
At $49/domain/month, Monitor re-scans daily and emails you on change — so next quarter's questionnaire has this quarter's evidence.
Agencies, multiply
Answering questionnaires for many clients? The Agency tier ($499, 25 domains, white-label) is built for exactly that arithmetic.
The sample verified report is the exact artifact your customer would receive — read it before you promise anything.
Common questions
Will a customer's security review accept a Notra report?
As evidence of proactive, third-party testing — usually yes, and the exhibits are what make it credible: manifest-pinned runs, proof-of-exploit on every finding, a methodology you can explain in a sentence. What it is not: a signed letter from a certified assessor. If the reviewer's checkbox demands that exact artifact, a manual engagement is the honest answer.
What if the questionnaire asks for a 'clean' report?
There is no such artifact, from anyone honest. What you can share is the run itself: surface mapped and probed, findings verified or explicitly not found, all timestamped and pinned. A real empty set with evidence beats a vague assurance letter every time.
How current is the evidence I attach?
As current as your last run. The audit is a one-time credit you can re-buy at the same $149 whenever you want fresh proof; for ongoing freshness, Monitor re-scans daily and emails you on every change.
Start with the free scorecard; the $149 audit produces the attachable report.
Related: the sample report you'd attach, the manual-pentest comparison for pushback conversations, and Agency if you answer questionnaires for clients rather than yourself.