ThePlus Tech

Stop rebuilding trust answers from scratch.

For teams whose enterprise deals are stalled on security questionnaires, evidence requests, or AI-governance work.

Sprint termsfixed
Price
£1,500 · first three pilots
Scope
Fixed
Duration
5 working days
Delivery
Manual outcome first
Commitment
None beyond the sprint
StopIf the sprint cannot find a valuable, controllable quick win, it stops there and says so. No platform pitch, no manufactured roadmap.

The expensive pattern

The answer exists. The evidence is scattered.

Every questionnaire starts from zero

Answers live across old spreadsheets, tickets, policies, and individual memory.

Repeats every deal

Evidence is detached from the claim

Teams can answer the question but cannot quickly prove the control behind it.

Fails on scrutiny

Sales waits on security

A trust request becomes an invisible queue between revenue, engineering, HR, and compliance.

Delays revenue

What the questionnaire is actually asking

SIG, CAIQ and a buyer’s own spreadsheet word it differently. The question families underneath are the same, and each lands on a control you either can or cannot evidence.

Formats5 common
SIG Lite / SIG CoreShared Assessments’ Standardized Information Gathering questionnaire.
CAIQCloud Security Alliance’s Consensus Assessments Initiative Questionnaire.
The buyer’s ownA spreadsheet or procurement portal, usually derived from one of the above.
SOC 2 or ISO/IEC 27001 requestA report or certificate is asked for, and the questionnaire covers the gap without one.
AI-governance addendumQuestions citing the NIST AI RMF, ISO/IEC 42001 or the EU AI Act.
LimitThe sprint does not produce a SOC 2 report, an ISO certificate or a penetration test. Only an accredited auditor or tester can. Where a buyer requires one that does not exist, the missing-controls report names the gap instead of wording around it.

Access control and offboarding

SSO and MFA enforcement settings, a dated access review, the record of the last leaver’s access removal.

Identity

Change management and secure development

Branch protection rules, pull-request approval history, a deploy log that names who shipped what.

Audit · Human Approval

Logging, monitoring and incident response

Log retention settings, the alert rules that exist, the record of the last incident or exercise.

Observability · Audit

Data handling, retention and sub-processors

A data-flow map, retention configuration, the current sub-processor list and where data resides.

Policy

AI model use and human oversight

A model inventory, a statement of whether customer data trains anything, the gate where a person signs off.

Policy · Human Approval

Third-party assurance

The report, certificate or penetration test itself, a bridge letter for the period it does not cover, or a named gap with a date.

Evidence

What you receive

A decision pack, not discovery theatre. One repeated workflow inspected, and the evidence needed to decide what should be automated and what must stay human-controlled.

£1,500First three pilots · fixed scope
  • Workflow and evidence-source mapThe people, systems, handoffs, evidence sources, and approval points a trust answer passes through today.
  • Reusable answer bankThe answers you keep rebuilding, written once, with the control each one rests on.
  • Missing-controls reportWhere a claim has no evidence behind it, named before a buyer finds it.
  • Exportable response packThe questionnaire response in a form you can send, reuse, and defend under scrutiny.
  • 30-day automation roadmapThe smallest implementation worth testing, with success measures and stop conditions.

How the five days run

Sequence5 working days
IntakeOne workflow, its owners, systems, deadlines, and known constraints.
Evidence reviewExisting answers, policies, records, tools, and handoffs are mapped.
Opportunity analysisAutomation candidates are scored against value, risk, and feasibility.
Decision sessionFindings presented, assumptions challenged, next move agreed.

Your evidence does not become training material

The sprint defines data boundaries, access, approvals, retention and evidence handling before any automation is proposed. Identity, policy, audit and observability are requirements, not an upgrade tier.