ActiScan
← All case studies

Case Study

Answering a vendor security questionnaire without scrambling

A dated authentication baseline and an AI-written summary, ready the same day the questionnaire arrived.

Illustrative scenario, not a specific verified customer — grounded in ActiScan's real capabilities and how MSPs typically use them. An MSP responding to a client's inbound vendor security questionnaire.

Same day

Time to produce evidence

8

Checks covered in the baseline

None

Manual write-up required

The situation

A client forwards a vendor security questionnaire from one of their own customers — the kind with a section asking about email authentication: is SPF published, is DMARC enforcing, is it actually monitored or just set once and forgotten. The client doesn't know the answers and asks the MSP to fill in that section, with a deadline of a few days.

Answering that kind of question from memory, or by manually re-checking DNS records under time pressure, is exactly the situation that produces a rushed, defensible-sounding but not actually verified answer.

What changed

The domain already has a scan history — SPF, DMARC, DKIM, BIMI, MTA-STS, and the rest, checked on a recurring schedule, not just once at onboarding. Pulling up the report gives a dated, specific answer to each part of the questionnaire: DMARC is published and at what policy, since when, and whether it's actually being monitored (it is — that's what the auto-rescan history shows).

For the section that wants prose instead of a table, the report's Written summary tab turns the same findings into plain-language paragraphs, generated on demand — something to paste directly into the questionnaire's narrative fields instead of writing it from scratch under deadline.

Where the questionnaire specifically asks about DMARC report processing, ActiScan's own report-authorization handling is part of the honest answer too: aggregate and failure reports are actively ingested and parsed, not just theoretically supported.

The outcome

The questionnaire gets answered the same day it arrived, with a specific, dated, exportable report behind every claim instead of a best guess. The MSP is careful about scope here, and so is ActiScan's own product: a grade is a real, dated authentication baseline, not a guarantee of compliance with any specific law, regulation, or the full questionnaire — where a question reaches beyond what DNS-level checks can answer, the MSP still reads the actual language and answers it directly, using the baseline as evidence for the parts it does cover.

The client gets their questionnaire back on time, and the MSP has a repeatable answer ready for the next one instead of starting from zero again.

Questions

Does an ActiScan report certify compliance with a specific regulation?

No — see our Terms for the exact disclaimer. A grade is a real, dated assessment of what our checks find at scan time, useful as evidence for the parts of a questionnaire it actually covers, not a substitute for reading the specific requirement in full.

How current is the data behind the report?

As current as the domain's own auto-rescan interval and its report-upload history – a domain scanned daily shows a daily-fresh baseline, not a stale one-time check.

Can I generate the written summary for a report that's a few weeks old?

The written summary is generated from a specific scan's own findings, so it reflects that scan's data – rescan first if you need the summary to reflect the current state, not last month's.

See it on your own domains

Run a free scan first, or start a trial to see the full workflow this case study describes.