Complete the go-live security questionnaire

How to answer the information security questionnaire well, and how to fix common submission errors.

The information security questionnaire is part of the go-live checklist in the Fiskil Console. It gathers evidence that appropriate controls are in place to safeguard any customer data you'll handle in production. Fiskil's compliance team reviews your answers, policies, and evidence before approving production access.

How to answer it well

  • Answer for your current production environment, not your target architecture. The review treats your submission as a point-in-time snapshot of the controls actually in place. Aspirational answers based on infrastructure you plan to build will slow the review down. Your production environment should be stood up, and your production integration ready, before access to live customer data can be granted.
  • Provide real evidence for upload questions. Where the questionnaire asks for evidence — storage region, TLS configuration, encryption at rest, audit logging, MFA — attach material from the environment that will actually serve production traffic.
  • Mark genuinely inapplicable controls as N/A with a short justification. Some controls don't apply as written to every organisation — for a solo-founder company, that might include separation of duties, peer code review, or background checks on staff. Rather than answering "yes" inaccurately, mark these not applicable and briefly explain why, noting any compensating control you have in place.
  • Put remediation plans in the comments. If a control is applicable but not yet fully implemented, say so honestly and describe your remediation plan in the comment field rather than in the answer itself.

Unsure before you submit?

If you'd rather check your approach than iterate through review cycles, contact support before submitting — questions can be passed to the compliance team.

Common submission errors

403 Forbidden when clicking Submit

A 403 error on submission can be caused by a backend security filter that incorrectly flags certain text answers as potential injection attacks — even when the content is legitimate. Symptoms:

  • A 403 Forbidden response immediately on clicking Submit.
  • The error occurs consistently across browsers (Chrome, Safari, incognito) and networks.
  • The submission fails at the information security section even though your documents uploaded successfully.

This isn't caused by your documents or answers, and you can't fix it by rewording alone — it requires a change on Fiskil's side.

To resolve it: contact support with your Team ID and a description of the issue. The team will review your submission and apply the fix needed to enable it; you can then retry and it should succeed.

What happens after you submit

The compliance team reviews your policy information and evidence. Once the checklist is complete and approved — including a review with Fiskil's compliance and sales teams — production access is granted. See Move from sandbox to production for the rest of the go-live steps.