Customers ask for SOC 2, then ISO 27001, then TISAX® or NIS2, and every deal brings a security questionnaire. Teddy maps each new framework onto the controls you already have and answers security reviews from your live evidence.

SOC 2 opens the first enterprise deals. Then the next customer wants ISO 27001, an automotive buyer wants TISAX®, and each one sends 200 questions. Without a shared foundation, every request becomes a new project.
Each new framework is mapped onto the controls you already run.
The Questionnaire Agent drafts every answer from your evidence.
Your team reviews only new or changed answers.
Security copies last year’s answers, a customer now asks for ISO 27001 and TISAX® on top of SOC 2, and a chatbot can only guess. With Teddy, the second and third framework reuse what SOC 2 already proves, and the Questionnaire Agent answers from live evidence.
Teddy builds one control set from your first framework, adds each new one on top and answers security reviews from the same evidence.
Your first framework becomes the foundation: one control set, evidence collected from your systems, policies written from how you actually work.
ISO 27001, TISAX® or NIS2 map onto the controls you already have. You only build what is really missing.
Excel, Word or PDF. Every question is mapped to your controls and every framework you hold.
Answers come with their sources. Security sees what is new or changed, grouped by topic, not 214 rows.
Every approved answer is saved and kept current as your controls change, so the next questionnaire and the next framework go faster.
Sales asks in plain language and gets answers Security has already approved. New frameworks and new questions go to the right person with the draft ready.
Ask TeddyDo we have ISO 27001? Where is our data hosted? Sales gets approved answers instantly.
Agents do the workNew frameworks mapped, questionnaires drafted, evidence kept fresh.
Our team backs you upCompliance engineers take you through audits, certification bodies and customer calls.
Usually most of the technical controls. Teddy shows exactly which ones carry over and what is missing, such as the Statement of Applicability and the risk process.
Excel, Word and PDF. Teddy maps every question to your controls, whatever the layout.
Every answer is drafted from your live controls and evidence, with the source linked. Nothing is sent before Security approves it.
No. Teddy answers from the program you have today. When customers keep asking for a certificate or an audit report, Teddy takes you there too.
Bring one of your own questionnaires to the demo.
Security copies last year’s answers, and every new framework starts as a separate project.
The next framework is built on the controls you already have, and questionnaires are drafted immediately from your evidence.
Teddy was built by former CISOs and GRC managers who answered the same security questions for customer after customer. Answers should come from evidence, not from last year’s spreadsheet.
Meet the founders →