Help center

Short answers to the questions we hear most. Need something not covered here? Email us.

Getting started

What does PolicyAlign actually do?

You upload your existing policy documents — handbooks, IT policies, memos. PolicyAlign reads them and maps what's written against the NIST Cybersecurity Framework — then re-checks the results through the other frameworks that apply to you (HIPAA, AI governance, student-data privacy) and the questionnaires you're asked to fill out — showing where you're covered, partially covered, or missing. It's a starting point to review, not a certification or legal determination.

Are the results always right?

They're AI drafts based on what your documents say — a starting point to review and edit, not a final answer. Always verify findings and questionnaire answers against your actual practices before relying on or submitting them. You own the result.

Answering security questionnaires

Do I have to format my questionnaire a certain way?

No — upload it however it came (Excel, Word, CSV, PDF) or paste the questions. PolicyAlign reads the questions out automatically, whatever the layout.

Do I pick which framework it's for?

No — each question is matched to whatever in your documents is relevant. An access-control question pulls your access policy; a backup question pulls your backup doc. You don't tell it what kind of questionnaire it is.

Will it submit answers for me?

No — it drafts each answer with the source document cited, then you review and confirm. You own the final submission.

What if my documents don't cover a question?

It's marked “Not met” with no invented evidence — that's a real gap to address, not something we paper over.

Where do my answered questionnaires go?

Each run is saved under the assessment it was answered against, so you can reopen it later from that assessment's “Answer a questionnaire” page. The questionnaire file you upload is never stored — only the answers drawn from your own documents.