Skip to main content

A Respondent's Guide to the Cye Platform Questionnaire for Private Equity

How to access, fill out, and submit your security questionnaire.

Why This Questionnaire Matters

This questionnaire captures security details about an organization, internal policies, manual processes, and operational practices that automated assessments cannot reach. The responses feed directly into the Cye Platform's risk model.

  • Accuracy of risk metrics: Automated scanners cannot detect internal controls, manual processes, or offline security practices. Without this data, risk calculations may be based on incomplete information. Thorough responses ensure that existing security measures are credited correctly in Exposure and Maturity scores.

  • Audit-ready documentation: Once submitted, the questionnaire becomes a locked, read-only record of your answers and evidence, viewable at any time from the Cye Platform.


Questionnaire Access & Scope

  • Respondent Eligibility: Respondents must have an active Cye Platform account before an assessment can be assigned. Unregistered individuals cannot be selected.

  • Access: Once assigned, the respondent receives a secure email from the Cye Platform with a unique link leading directly to their questionnaire. Respondents can also open it from Assessments in the platform sidebar, which lists their questionnaires with the sent date, due date, and completion status.

  • Working as a Team: A questionnaire can be sent to several respondents at the same company, and all of them work on one shared copy. Everyone sees the same answers, and the latest saved answer is the one that counts. Any respondent can submit the questionnaire, extend its due date, and assign questions to colleagues.


Filling Out the Questionnaire

  • Questions are organized by security domain to ensure a structured review of organizational controls.

  • Optional Questions: Optional questions are marked (optional) next to the question text. Questions without that mark are mandatory.

  • Question Types & Clearing an Answer: Questions are Yes/No, free text, or file upload. A Yes/No answer can be cleared: click the selected option again and the question returns to unanswered.

  • Filter Your Question List: Filter tabs narrow the view to Unanswered questions, Mandatory questions, or My questions (the ones assigned to you).

  • Delegating Questionnaire Tasks:

    • Invited respondents: Primary recipients invited by the parent company or CYE can delegate work by assigning colleagues as Collaborators.

      • Eligibility: All assigned users must be registered under the same subsidiary or portfolio company.

      • Management: Only primary invited respondents can reassign owners or remove collaborators. Removing a collaborator revokes their access to the questionnaire immediately.

    • How to assign:

      • Single question: Select the assign icon on a question card and pick the colleague from the list. The assignment applies immediately, and the person appears on the question. To remove someone, select the X next to their name.

      • Multiple questions: Select Assign at the top left of the questionnaire, mark the target checkboxes next to the relevant questions, and select Assign to... to choose a colleague. Select Done to apply. To clear existing assignments from selected questions, select Remove all from these questions.

    • Assigned users are notified in-app and by email, with a link that opens their "My Questions" view.

    • Collaborators Scope: Collaborators can view the entire questionnaire, answer questions, and attach evidence. They cannot submit the questionnaire, extend the due date, or assign other users.

    • Editing assignments: Only respondents invited by the parent or the Cye team can reassign or remove a collaborator. Removing a collaborator revokes their access to the questionnaire.

  • Evidence Collection : Some questions require supporting documentation, such as policy files or certifications, to validate security claims. Documents are uploaded directly to the relevant question.

    • Each question accepts up to 30 files, 50 MB per file.

    • Accepted types: PDF, Word (.doc, .docx), Excel (.xls, .xlsx), CSV, images (.png, .jpg, .jpeg), and ZIP.

    • A ZIP counts as one file. To attach more than 30 items, bundle them into a single ZIP.

  • Progress Tracking

    • Overall Progress Bar - Top Right: Displays the aggregate number of answered questions across the entire questionnaire.

    • Domain Indicators: Display the answer count for each security domain, showing a checkmark once a domain is fully completed.

  • Saving Progress: Progress is saved automatically. Respondents can exit and return to the questionnaire at any time — all work is preserved between sessions.

    • A save indicator in the page header shows Saving, Saved, or Couldn't save with a Retry option that re-sends any unsaved answers.

    • Submission stays blocked while an answer is still saving or failed to save, and leaving the page with unsaved answers triggers a warning.


Due Dates, Reminders & Extensions


Every questionnaire has a due date set by the sender. The platform sends reminders automatically, and the invited respondents can extend the date when they need more time.

  • Automatic Reminders: Reminder emails go out one week before, three days before, and on the due date. Every invited respondent receives them.

  • Extending the Due Date: Only respondents invited by the parent or the Cye team can extend the due date. Collaborators cannot. The new date must be later than the current one, and a reason is required.

    • To extend, select the clock icon next to the due date in the questionnaire header .

    • The extension takes effect immediately. No approval is needed.

  • Extension limit: Due dates can be extended by up to one week beyond the original date, unless your organization configures a different limit. Once reached, the Extend button is disabled with the tooltip "Due date already extended to the maximum."

  • After an Extension: Reminders recalculate to the new date, and the new due date and reason appear on the sender's dashboard.

  • Missing the Due Date: A passed due date never locks the questionnaire. Answering can continue, and invited respondents can still extend within the limit and submit. The questionnaire is marked as expired on the sender's dashboard.


Submitting the Questionnaire

  • Validation: All mandatory fields must be completed before the system permits submission. Optional questions can be left blank.

  • Submit: Selecting Submit locks all answers.


From Submission to Risk Model


Once the questionnaire is submitted, the data is reviewed by the Cye Delivery Team and incorporated into the Cye Platform:

  • Export Generation: Upon submission, the system automatically generates a structured data export containing all responses and associated supporting evidence for the Cye Delivery team.

  • Processing: Answers are converted into standardized security data, including Findings, Processes, and Technologies, within the Cye Platform. These entities feed directly into the organization's Exposure, Maturity, and Cost of Breach calculations.

  • Outcome Visibility: The generated entities appear inside the Cye Platform under Operations. Findings populate the Findings page, while Processes and Technologies populate the Assets page.

Did this answer your question?