Skip to content
CitesheetSend a questionnaire

Every answer quotes your policy. Or says it can't.

Citesheet fills your Excel questionnaire from your own documents. Each answer has a word-for-word quote. No proof, no answer.

First questionnaire free. Same-day turnaround.

gitlab_caiq_20.xlsx
A security questionnaire filled by Citesheet, with a citation for each answer
IDQuestionAnswerExplanation and source
LOG-03.1Are security-related events identified and monitored within applications and the underlying infrastructure?Answer: Yes

The company mandates capturing security-relevant events across product and infrastructure, and security logs are generated by applications and systems for monitoring and incident response.

BCR-01.2Are the policies and procedures reviewed and updated at least annually?Answer: Yes

Policies and procedures are required to be reviewed and approved on at least an annual basis.

HRS-11.2Are regular security awareness training updates provided?Answer: Yes

Regular security awareness training updates are provided through annual security awareness training and quarterly phishing simulations and training.

CCC-07.1Are detection measures implemented with proactive notification if changes deviate from established baselines?Answer: Partial

The policies document that security detection controls identify events outside of established security baselines, but they do not prove that proactive notifications are implemented for these deviations.

Needs review. Check: partial coverage. Evidence showing that proactive notifications are sent when changes deviate from established baselines.

DSP-17.1Are processes, procedures, and technical measures defined and implemented to protect sensitive data throughout its lifecycle?Answer: Yes

The provided documents confirm that processes, standards, and technical measures are established to protect sensitive data throughout its lifecycle, including data classification and software development lifecycle policies.

HRS-07.1Are employees required to sign an employment agreement before gaining access to organizational information systems, resources, and assets?Answer: —

No proof found

We found nothing in your documents to support an answer, so we left it empty.

What we measured

158 of 163filled answers matched the company's own answers
Test: 261-question CAIQ, filled from GitLab's public policies. Answers without proof stayed empty.
0invented quotes
Every quote is checked word for word by code against your document.
0changes to the rest of their file
Questions, layout and dropdowns are checked before the file goes back to you.

From the Excel you were sent to the Excel you send back

  1. Add your documents

    Your policies as PDF, Word or Markdown. They are the only source of answers.

  2. Add the questionnaire

    The Excel file you were sent, such as a CAIQ.

  3. Get it back filled

    Same file, same layout. Each answer has a quote and its document. You review the Needs review rows before you send it.

In the pilot, you send us the files and we run these steps with you.

Your file comes back as you sent it

We fill your Excel file. We don't rebuild it. Questions, layout and dropdowns stay as they were, and before it goes back to you we check that nothing outside the answer cells changed.

You get backYou send
Drag across the file, or focus the handle and use the arrow keys. Same questions, same layout. Only the answers are added.

Citesheet answers what your documents support. It flags the rest.

Each answer links to the exact words in your document. Code then checks those words exist in it, word for word. We never paraphrase and call it a quote. Pick a question to see where its answer comes from.

sec-training.mdfound word for word

…

Definitions

GitLab Team members: users with a gitlab.com email address

Contractors/TSPs and Consultants: Personnel who are external to GitLab who do not have a gitlab.com email address and are under a contract/agreement that involves handling, managing, storing, or transmitting GitLab data in support of GitLab's statutory, regulatory and contractual requirements.

Roles & Responsibilities

Standard

All GitLab Team members and contractors/TSPs are required to participate in GitLab's General Security Awareness Training, New Hire Training and on-going phishing simulations and training, or show evidence of equivalent training completion within the calendar year. Security Trainings that require participation include the following:

New Hire Security Training

New Hire Security Training is required to be completed by all GitLab Team Members and contractors/TSPs during their onboarding at GitLab. This security training provides new hires with the knowledge to identify cybersecurity threats, vulnerabilities, and attacks.

General Security Awareness Training (GSAT)

The GitLab security awareness training program provides ongoing training to GitLab team members that enhances knowledge and identification of cybersecurity threats, vulnerabilities, and attacks as well as satisfying external regulatory requirements. GitLab's handbook-first General Security Awareness Training is provided annually via Right Hand Cybersecurity, GitLab's third-party provider, and requires participation and completion by all GitLab Team Members and contractors/TSPs.

Exceptions during the active campaign will be made for GitLab team members on extended leave.

Phishing Training

The GitLab Phishing Training Program is designed to educate and evaluate GitLab's ability to detect and prevent phishing attempts. Ongoing phishing simulations and trainings are conducted once per quarter via Right Hand Cybersecurity, GitLab's third-party provider, and requires participation and completion by all assigned GitLab Team Members and contractors/TSPs.

Remember: If you see something, say something, and always report suspicious emails via PhishArm.

Secure Coding Training

The GitLab Secure Coding Training is a required training completed by a sub-group of GitLab Team Members and contractors/TSPs in the Engineering Department. This training contains descriptions and Secure Coding Guidelines from OWASP (Open Web Application Security Project) addressing security vulnerabilities commonly identified in the GitLab codebase. This training is intended to help developers identify potential security vulnerabilities early, with the goal of reducing the number of vulnerabilities released over time.

Exceptions during the active campaign will be made for GitLab team members on extended leave.

Other Security Trainings

…

Real rows from GitLab's public policies. If the words are not in the document, the answer does not ship.

No proof, no answer.

When your documents say nothing, the row stays empty and says so. When they only half-prove it, the row says what to check. Nothing is guessed.

HRS-07.1

Are employees required to sign an employment agreement before gaining access to organizational information systems, resources, and assets?

—No proof found

We found nothing in your documents to support an answer, so we left it empty. It goes on your gap list.

Needs review · CCC-07.1

Are detection measures implemented with proactive notification if changes deviate from established baselines?

Check: partial coverage. Evidence showing that proactive notifications are sent when changes deviate from established baselines.

Partial evidence, two documents that disagree, or a sensitive topic such as legal commitments. Each row says why.

A gap list of what's missing

Unanswered questions in one place, so you know which policy to write next. In the pilot, we send it to you by hand.

  • BCR-08.1Is cloud data periodically backed up?
  • DCS-06.1Are physical and logical assets cataloged and tracked…?
  • LOG-06.1Is a reliable time source used across systems…?

You decide: edit or approve any answer. A re-run never overwrites what you changed.

How we handle your documents

What happens to the policies and questionnaires you send us.

  • Used only for your questionnaires

    Your documents answer your questionnaires. Nothing else.

  • Google Gemini, paid tier

    The AI step runs on Google's paid Gemini API. Not used for training.

  • Encrypted in transit and at rest

    Connections use HTTPS. Stored files and answers are encrypted.

  • Deleted on request

    Tell us, and your documents and answers are removed.

  • NDA on request

    We'll sign yours before you send anything.

A founder-led pilot

Citesheet is early, so you work directly with the person who built it. Send one real questionnaire and judge it on that.

  • First questionnaire free

    Send a real one and judge it on that.

  • Same-day turnaround

    The filled file, the quotes and the flagged rows come back the same day.

  • Then pilot pricing

    No fixed prices yet. Talk to us. Send a message.

Questions we expect

Can it make up an answer?

It can draft one, but a quote is required, and code checks that the quote exists word for word in your document. If there is no proof, the row says “No proof found.”

What if my policies are incomplete or disagree with each other?

Partial evidence and conflicting documents are marked Needs review, with a “Check:” line saying why. You review those rows. Missing proof goes on the gap list.

Do I still need to review the answers?

Yes, for flagged rows and anything sensitive, such as legal commitments or breaches. You can edit or approve each answer, and a re-run never overwrites what you changed.

Will it break my Excel file?

No. Your questions, layout and dropdowns come back unchanged. We verify that before you download.

Where do my documents go?

They are used only for your questionnaires. The AI step is Google Gemini on the paid tier, which is not used for training. Data is encrypted in transit and at rest, deleted on request, and we sign an NDA on request.

What does it cost?

Your first questionnaire is free, with same-day turnaround. After that it is pilot pricing. Talk to us.

Send one questionnaire. See the proof.

First questionnaire free. Same-day turnaround. Tell us where to send it back and we'll reply with next steps.

Send your first questionnaire free

Takes about 15 seconds. Or email hello@citesheet.com.

Need an NDA first? Ask, and we'll sign before you send anything.

Send us your questionnaire

Three fields, about 15 seconds. We reply with how to send the file.

  • First one free
  • Back the same day
  • NDA on request