Guide

Onboarding Questionnaire - Sprinto

Overview

Sprinto is a compliance and security management platform that helps organizations automate audit preparation, risk management, and policy administration. During initial setup, you must complete an onboarding questionnaire to inform Sprinto about your technical infrastructure, data handling practices, and product details. This information allows Sprinto to tailor its assessment framework, generate relevant security controls, and populate compliance policies specific to your organization's risk profile. Completing this questionnaire accurately is essential for generating an accurate compliance roadmap and ensuring all applicable security policies are included in your audit scope.

Before you begin

  • Active account on app.sprinto.com with admin or setup permissions
  • Knowledge of which infrastructure providers your organization uses (e.g., AWS, Heroku, GitHub)
  • List of data types your product or service handles (e.g., personally identifiable information, cloud platform credentials)
  • Product name and official product URLs (main website, documentation, etc.)
  • Links to your Support page, Product Status page, and Terms of Service documents (or ability to add these later)

Step by step

1
Clickon

Begin the questionnaire by toggling the confirmation checkbox to acknowledge that you understand the scope of the onboarding process.

Step 1
2
ClickContinue

Click the 'Continue' button to proceed from the introduction screen to the infrastructure selection section.

Step 2
3
ClickM

Click the 'M' button (likely a menu or modal toggle) to open or expand the infrastructure selection options.

Step 3
4
ClickAWS

Click on 'AWS' to select Amazon Web Services as one of your organization's infrastructure providers.

Step 4
5
ClickSelect infrastructure

Click the 'Select infrastructure' button to open the dropdown menu for adding additional infrastructure platforms.

Step 5
6
ClickHeroku

Select 'Heroku' from the dropdown options to add it as a second infrastructure provider.

Step 6
7
ClickOthers

Click 'Others' from the dropdown to add a catch-all option for any infrastructure platforms not explicitly listed.

Step 7
8
ClickGithub

Click on 'Github' (GitHub) to select it as an infrastructure or version control provider your organization uses.

Step 8
9
ClickPersonal Identifiable Information... +2

Click the 'Personal Identifiable Information... +2' button to expand and select all data types within the Personal Identifiable Information category (this likely includes multiple sub-types such as names, email addresses, and payment information).

Step 9
10
ClickCloud Platforms (e.g.,... +1

Click the 'Cloud Platforms (e.g.,... +1' button to expand and select data types related to cloud platform credentials, API keys, and related sensitive information.

Step 10
11
ClickSave

Click 'Save' to persist your infrastructure and data type selections and proceed to the product details section.

Step 11
12
ClickYes, Looks good

Click 'Yes, Looks good' to confirm that your selected infrastructure and data types are accurate, signaling your readiness to provide product details.

Step 12
13
ClickAdd Details

Click 'Add Details' to open the form for entering your product name, URLs, and associated compliance documents.

Step 13
14
ClickName of the product

Click in the 'Name of the product' text field to activate it and prepare for input.

Step 14
15
TypeName of the product

Type your product or service name into the 'Name of the product' field (e.g., 'Acme Cloud Storage Platform').

Tip. Use the exact product name as it appears in your public marketing materials and compliance documents for consistency.
16
ClickEnter a valid URL

Click in the first 'Enter a valid URL' text field to add your product's main website URL.

Step 16
17
TypeEnter a valid URL

Type your product's primary website URL (e.g., https://www.acme-platform.com).

Tip. Ensure the URL begins with https:// and is publicly accessible. Sprinto may validate this URL, so it must be live and reachable.
18
ClickEnter a valid URL

Click in the second 'Enter a valid URL' text field to add your product documentation or API reference URL.

Step 18
19
TypeEnter a valid URL

Type the URL for your product documentation or technical API reference (e.g., https://docs.acme-platform.com).

Tip. Link to publicly available documentation so auditors and Sprinto can review your technical architecture and security features.
20
ClickEnter a valid URL

Click in the third 'Enter a valid URL' text field to add your security or architecture overview URL.

Step 20
21
TypeEnter a valid URL

Type the URL for your security, architecture, or trust information page (e.g., https://www.acme-platform.com/security).

22
ClickEnter a valid URL

Click in the fourth 'Enter a valid URL' text field to add another product-related URL (such as a roadmap, blog, or additional resource).

Step 22
23
TypeEnter a valid URL

Type an additional URL relevant to your product (e.g., https://blog.acme-platform.com or https://roadmap.acme-platform.com).

24
ClickEnter a valid URL

Click in the fifth 'Enter a valid URL' text field to add your final product URL.

Step 24
25
TypeEnter a valid URL

Type the URL for your final product resource (this may be a secondary reference or compliance-related page).

26
ClickSelect

Click the first 'Select' button to open a dropdown menu for classifying the first document/URL you are about to add.

Step 26
27
TypeSearch

Type 'Support' in the search field to filter document types and locate the Support document classification option.

28
ClickSupport

Click on 'Support' from the filtered results to select it as the document type for your support page URL.

Step 28
29
ClickAdd

Click the 'Add' button to confirm and add your Support document URL to the profile.

Step 29
30
ClickEnter a valid URL

Click in the 'Enter a valid URL' text field to input your Support page URL.

Step 30
31
TypeEnter a valid URL

Type the full URL to your Support or Help Center page (e.g., https://support.acme-platform.com).

Tip. Link to a page where customers can report security issues or access support contact information.
32
ClickSelect

Click the second 'Select' button to open the dropdown menu for the second document type (Product Status).

Step 32
33
TypeSearch

Type 'Product status' in the search field to locate and filter for the Product Status document classification.

34
ClickProduct status

Click on 'Product status' from the search results to select it as the document type for your service status page.

Step 34
35
ClickAdd

Click the 'Add' button to add your Product Status document to the profile.

Step 35
36
ClickSelect

Click the third 'Select' button to open the dropdown for the final document type (Terms of Service).

Step 36
37
TypeSearch

Type 'Terms of service' in the search field to locate the Terms of Service document classification.

38
ClickTerms of service

Click on 'Terms of service' from the filtered results to select it as your Terms of Service document type.

Step 38
39
ClickEnter a valid URL

Click in the 'Enter a valid URL' text field to input the URL for your Terms of Service document.

Step 39
40
TypeEnter a valid URL

Type the full URL to your Terms of Service page (e.g., https://www.acme-platform.com/terms).

Tip. Ensure your Terms of Service document is publicly accessible and includes relevant security, data handling, and liability clauses.
41
ClickTerms of service

Click the 'Terms of service' button to confirm the document type selection for your Terms of Service URL.

Step 41
42
TypeSearch

Type 'Terms of service' in the search field again to ensure the correct document classification is selected for final confirmation.

43
ClickTerms of service

Click on 'Terms of service' from the search results to finalize the document type assignment.

Step 43
44
ClickSave Changes

Click 'Save Changes' to persist all product details, URLs, and document classifications to your Sprinto profile.

Warning. Ensure all URLs are valid and accessible before saving. Invalid URLs may cause validation errors or prevent Sprinto from cross-referencing your documents during compliance assessments.
Step 44
45
ClickContinue

Click 'Continue' to advance to the next phase of onboarding, where Sprinto will generate compliance recommendations.

Step 45
46
ClickAdd 76 risks

Click 'Add 76 risks' to import Sprinto's recommended risk assessment framework tailored to your infrastructure and data handling practices.

Tip. This action populates a comprehensive list of security risks relevant to AWS, Heroku, GitHub, and your data types. You can review and customize these risks later.
Step 46
47
ClickAdd 36 policies

Click 'Add 36 policies' to import Sprinto's pre-configured compliance policies and security controls aligned with your organization's risk profile.

Tip. These policies are customized based on your selected infrastructure and data types. Review and adjust them to match your organization's specific security requirements and compliance obligations.
Step 47
48
ClickShow my next steps

Click 'Show my next steps' to view your personalized onboarding roadmap and proceed with implementing recommended security controls and compliance measures in Sprinto.

Tip. This step concludes the questionnaire workflow and transitions you to the implementation phase, where you can assign risks, policies, and controls to teams.
Step 48

Confirm it worked

  1. 1After completing all questionnaire fields, you see a 'Save Changes' confirmation and a 'Continue' button becomes available
  2. 2The system displays options to 'Add 76 risks' and 'Add 36 policies', indicating your organization's compliance profile has been configured
  3. 3A 'Show my next steps' button appears, signaling the questionnaire workflow is complete and you may proceed to implementation steps
  4. 4Your selected infrastructure providers, data types, and product details are reflected in your Sprinto organization profile

Common issues

Keep reading