Deal desk for security reviews

Security reviews, unblocked.

Avrir turns questionnaires, evidence requests and security blockers into trusted answers your team can actually send to buyers.

buyer requestsapproved response
XLSX, DOCX, PDF in
Answers written back to the original file
Every answer cites
Or it is marked as an inference
No evidence, no answer
Gaps become “Insufficient evidence”
Humans approve
Nothing reaches a buyer on its own
01 — What it does

Three outcomes, one workflow.

Avrir does more than fill in a spreadsheet. It works out what has to be true for the deal to get through security review.

01

Answer questionnaires

Upload XLSX, DOCX or PDF questionnaires. Avrir retrieves the relevant internal evidence, drafts answers with citations, and flags the ones that need a human before anything is exported in the original format.

02

Build evidence packets

Turn policies, audit reports, architecture documents and controls into buyer-ready packets. Each artifact keeps its source, revision and locator, and stale documents are held back.

03

Unblock deals

Find the requirements you cannot meet today, state the actual gap, and propose remediation: interim controls, phased rollouts, commitments a person can accept or reject.

02 — How it works

Between sales, security and the buyer.

Avrir sits in the path your team already follows. Requests come in, work gets routed, a person signs off, and the response goes out in the format the buyer asked for.

  1. 01
    Buyer request
    Questionnaire, RFP section, evidence request
  2. 02
    Avrir
    Routes each question, retrieves evidence, drafts
  3. 03
    Answers · Evidence · Blockers
    Cited, with gaps named
  4. 04
    Human review
    Approve, edit or mark insufficient
  5. 05
    Buyer-ready response
    Original format or deal room
03 — Evidence first

Every claim points back to its source.

Citations are internal references, not text a model made up. Each one resolves to a document, a revision and a location. Where nothing supports a claim, Avrir says so and asks a person.

  • Review status is visible on every answer.
  • Unsupported claims are flagged, not invented.
  • Stale or superseded sources are held back.
  • People decide what gets sent to buyers.
Generated answer3 sources · not yet approved

Q4.12 · How is customer data protected?

Customer data is encrypted at rest with AES-256 and in transit with TLS 1.2 or higher. Encryption keys are managed in a cloud KMS and rotated every 12 months. Customer-managed keys (BYOK) are not currently supported.

Why review: the last sentence has no direct source. No document mentions customer-managed keys.
Needs reviewA reviewer approves, edits or marks it insufficient.
  • Information Security Policy v3.2§4.1 · p.6

    “All customer data is encrypted at rest using AES-256.”

  • Architecture Overview§2.3 · p.4

    “External connections are terminated with TLS 1.2 or higher.”

  • Key Management Standard§2.1 · p.3

    “Encryption keys are rotated at least every 12 months.”

04 — Deal blockers

Find out what it takes to get through.

Some requirements cannot be met today. Avrir names the gap, traces where it came from, and drafts realistic ways forward. Your team chooses one, and the decision is recorded with a name and a date.

  • — Unmet requirements move through a visible lifecycle.
  • — Remediation is proposed by AI and decided by a person.
  • — Red is reserved for a confirmed blocker.
Unmet requirementPotential deal riskBuyer concernConfirmed blocker
R-14Confirmed blocker

SAML SSO required before production rollout

Gap: Relaywise supports email sign-in and passkeys. SAML is not supported, and no document commits to a date.

Proposed remediation
Phased rollout

OIDC pilot in November, SAML general availability by 15 Dec 2026.

Proposed remediation
Interim control

Enforce passkeys and an IP allowlist for the buyer's admin accounts until SAML ships.

Try it: accept a proposal. Stage changes are human decisions.
05 — Deal room

A shared room instead of email threads.

Once the answers are approved, share an allowlisted set of documents. Buyers read what you chose to share and ask questions against it. Your team sees what they ask, and spots new blockers early.

What the buyer seesBuyer view
Shared documents · 8
  • Information Security PolicyPDF
  • SOC 2 Type II reportPDF
  • Architecture overviewPDF

Do you support customer-managed keys?

Not covered by the shared documents

No answer was generated. The security team has your question and will reply here.

What your team seesobserved
Last visit
2h ago
Visitors
4
Questions
7 asked · 1 held
Documents
5 opened
Insufficient evidenceBQ-7

Customer-managed keys are not covered by shared documents.

Reply with verified information, or open a new requirement.

06 — Why Avrir

A chatbot can answer a question. Avrir helps close the deal.

A generic retrieval tool returns text. A deal needs more than that, so Avrir models the things a security review is actually made of.

Evidence
Documents with revisions, freshness and ownership.
Citations
Validated references, checked against the workspace.
Review status
What was generated, what was approved, and by whom.
Questionnaire structure
Sheets, cells and sections, so answers go back where they belong.
Unmet requirements
Gaps tracked from first mention to resolution.
Buyer-facing output
Original formats, evidence packets and a deal room.
07 — The name

Avrir means “to open.”

It is a Romansh word. We built Avrir around one idea: trust should open business, not block it.

Get the next review through.

Bring a real questionnaire and your current documents. See which answers are supported, and what is actually in the way.

Join the early access