Substanto drafts answers to security questionnaires from your own documents. It is built on one rule: every answer is grounded in a source you can see, or it is not given. This page sets out how that rule, and the controls around it, address the main risks of using AI.
Substanto answers only from the trust documents and approved answers you provide. For every answer it stands behind, it shows the exact source line it came from. When your documents do not support an answer, it says so and abstains, rather than guessing. Nothing is invented.
Two further checks run on top of that: a verification pass re-reads the drafted answer against the cited evidence, and a bounding step reduces an answer to what the evidence actually supports and shows you what it removed. Each answer also carries four explicit checks, including when one is not established:
| Check | What it reports |
|---|---|
| Recency | Whether the cited source is current, or flagged as over 12 months old |
| Scope | Whether the answer stays within what the evidence covers, or was reduced to it |
| Applicability | Whether the control applies to your organisation |
| Ownership | Whether an owner is named in your documents, or is not established |
Substanto is a drafting and productivity aid, not an autonomous decision-maker. It never sends a questionnaire, certifies anything, or makes a decision about a person. You review, edit, and approve every answer before it is used. This human-in-the-loop step is the primary control, and it is built into the workflow rather than left to the user to remember: a drafted answer is a draft until you approve it.
Every answer is traceable to its source. You see the cited line, the four checks, and, for a reused answer, when it was written and that it was re-checked against your current documents. There is no hidden scoring that decides an outcome on your behalf; the tool surfaces the evidence and leaves the decision with you.
The design goal is not a high answer rate. It is that an answer, when given, is supported by your evidence, and that a gap is shown as a gap. We would rather abstain than be confidently wrong.
Questionnaire questions and uploaded documents are treated as untrusted input. The model is instructed to answer only from the provided evidence and not to follow any instructions embedded in a question or a document, which mitigates prompt-injection attempts. Answers are generated with deterministic settings (temperature 0) for consistency. The application runs behind a strict content-security policy and rate limiting.
Answers are drafted using Anthropic's Claude models, with Voyage AI embeddings for matching. Both process data under terms that prohibit training on your inputs. See the Subprocessors page for the current list.
Substanto is built and operated by Substanto Ltd, a UK company, currently run by its founder. We have not yet completed a formal Data Protection Impact Assessment, independent security testing, or a published external evaluation; these are on the roadmap and will be reflected here as they are done. We would rather tell you what is and is not yet in place than imply a governance apparatus we do not have. If your procurement process needs something specific, ask and we will tell you plainly where we stand.
Questions about how Substanto uses AI, or a security or data-protection request: hello@substanto.com (privacy: privacy@substanto.com).
Substanto Ltd. Registered in England and Wales, company number 17447004. Registered office: Unit 82a James Carter Road, Mildenhall, Bury St Edmunds, IP28 7DE.