Nobody gets grilled by buyers like fintech companies. The security reviews that financial services companies put their technology partners through are grueling. For good reason, of course, risk needs to be as close to zero as possible in finance.
At Conveyor we work with some of the most successful fintech, software, and AI companies out there. What we see is that these companies are great at getting secure, but need help proving it. Managing the intensity of ongoing customer security reviews, internally and directly with customers.
Carta, a long-time Conveyor customer, has done an excellent job building a customer trust program that helps them scale. Their security team automates most reviews, only jumps in when they really need to, and delivers extremely accurate and helpful information to their customers.
None of that is luck or headcount. It is a Customer Trust Program they built on purpose, in a sequence that works. This piece is about that sequence.
It is getting harder, and it is not your imagination
If you are feeling more pressure from security reviews than you did two years ago, you are reading it correctly. Three things are pushing at once.
Regulation fragmented. In August 2025 the FFIEC withdrew its Cybersecurity Assessment Tool and pointed institutions toward four frameworks instead of one (FFIEC). The sector lost its common baseline, so every buyer now asks differently. In Europe, DORA requires your customers to file a register of information on every technology provider they use — your legal entity identifier, data locations, subcontractors, ultimate parent (ESAs). That is a regulatory filing that depends on data only you have, and in the supervisory dry run only 6.5% of filings passed all the data quality checks (EBA). When your customer chases you a fourth time about your subprocessor list, this is why.
AI created a category of question nobody had a template for. FS-ISAC now structures AI vendor assessment across seven risk domains (FS-ISAC), and NYDFS expects added representations and warranties where a vendor deploys AI (NYDFS). Meanwhile 72% of financial institutions are only partially aware of which vendors use AI, and not one surveyed felt confident managing the risk (Ncontracts). Wild west, but also an opening to stand out.
Breaches keep landing on vendors. Attackers reached Marquis Software Solutions through a flaw in SonicWall, one of Marquis's own vendors, and exposed 823,548 people across roughly 80 financial institutions (American Banker). None of those 80 were breached. All of them had to notify customers anyway.
Your buyers are not worried about your firewall. They are worried about the company three steps behind you that they have never heard of.
You already did the hard part
Fintech companies have the strongest security posture of any industry measured (a median score of 90), with 55.6% rated A (SecurityScorecard). At the same time, 41.8% of the breaches that hit them came through third parties, and their exposure through their vendors' vendors runs at 11.9%, more than double the global average.
Buyers may assume you are secure, but they have to verify it, quickly and repeatedly and without taking your word for it. In our 2026 Customer Trust Benchmark, 87% of teams said security reviews are important or critical to closing business, and 54% called them flat-out critical.
Getting secure is an engineering project with an end date. Proving it is an operating function that runs forever and touches sales, legal, compliance, product and security all at once.
Most fintechs struggle to prove trust. They always get there. But if it takes you a few weeks to satisfy a buyer, that really hurts sales. If you can do it in a few hours, deals flow and sales loves you.
The companies that do this best have built a Customer Trust Program. Here are the main components of that program.
- An excellent source of truth for security knowledge.
- AI layered on top of knowledge to automate security reviews.
- Systems, powered by AI, that help your infosec and RFP teams process reviews.
- A version of that system exposed to the larger sales org and customers.
- Data and controls to optimize, manage, and report on the system.

This is essentially what Carta built. A powerful Customer Trust Program that proves trust at scale.
Step 1: Build an excellent source of security knowledge
This is the least exciting step and the one that decides whether your program works.
Most teams already have something they call a knowledge base. Usually it is a folder of completed questionnaires, a few Confluence pages, and a spreadsheet somebody maintained until they changed roles. That is a collection, not a source of truth, and the difference matters enormously once you put AI on top of it.
The distinction we would draw is curated, not collected. A collection accumulates. A curated knowledge base is deliberately maintained: every answer has an owner, a last-reviewed date, and a clear scope. Without that any AI built on it decays. Bad inputs mean bad output, and bad output erodes exactly the trust you were trying to build.
Teams know this. Keeping the knowledge base updated is the second-biggest frustration in customer trust work, named by 48% of teams in our benchmark. What is strange is how few do anything about it: 67% of heavy AI users call knowledge management a main pain point, but only 38% of them use AI to automate it.
For fintech there is a second requirement that most industries can get away with ignoring: every answer has to know which product it belongs to.
If you run a portfolio of financial products, the honest answer to "how is data encrypted at rest" is different for each one. A knowledge base that flattens them into one answer is not a time-saver. It is a source of confidently wrong statements that go out under your company's name to a regulated buyer.
Carta built theirs across product lines for exactly this reason: a single source of truth where each answer maps to the right product, control or certification. It is why their automation holds up as they add products, instead of degrading.
What good looks like at this stage:
- Approved answers, not past answers. There is a difference between "we said this once" and "this is true and someone signed off"
- Every entry scoped to a product, a control, or a certification
- A review cadence with a named owner, and a way to flag content that has gone stale
- Your policies, audit reports and certifications in the same system, not a separate drive
If a previous attempt at automating security reviews disappointed you, this step is almost always why. The model was fine. The inputs were not.
Step 2: Activate that knowledge by layering AI on top of it
With a curated source of truth in place, AI starts getting much better at answering questions.
Almost everyone is trying. 88% of teams either use AI for customer trust work today or plan to within a year, but only 46% use it across their whole workflow. The rest are still experimenting at the edges. The split tracks with pressure rather than company size — 62% of high-volume teams are advanced users, versus 23% of low-volume teams.
What separates AI that works from AI that disappoints is what it's pulling from. General-purpose tools (like ChatGPT, or Claude) index everything and guess when they are unsure, which is precisely the wrong behavior when the output is a statement about your security posture going to a regulated buyer.
Purpose-built systems, like Conveyor, restrict scope deliberately. The AI draws from approved answers for the right product line, and when it cannot find support for something, it says so and routes to a human instead of inventing a plausible sentence.
Carta gets 95% accuracy on customer security questionnaires this way. Their Senior GRC Analyst, Callie Dedinsky, put it in terms anyone who has done this work will recognize:
"We ran a 77-question spreadsheet through Conveyor. It answered 72 of them perfectly — what used to take days now takes 20 minutes."
You are not aiming for a system that answers everything. You want one that answers what it can support, flags what it cannot, and leaves your analyst five questions to think about instead of seventy-seven to type.
Security leaders evaluating this almost always raise the same reasonable concern: I do not want to rely only on AI answering the questions. There needs to be human oversight. Nobody in this market disagrees, and only 8% of teams return AI answers to customers without a human check. What changes is where the human spends their attention. Reviewing five flagged answers is oversight. Retyping seventy-two answers you have written before only feels like it.
What good looks like at this stage:
- Accuracy you can measure on real questionnaires, not a vendor's demo
- Explicit scope control — you decide what the AI can and cannot draw from
- Every answer traceable to the approved source it came from
- Low-confidence items flagged for review rather than filled in
This is also where those new AI questions start paying off. A system that can show where an answer came from can answer "how do you use AI, and on what data" without a three-week scramble.
Step 3: Turn that AI into systems that help your team process reviews
Accuracy is not a process. You can have a system that drafts excellent answers and still have a security review function that quietly loses deals, because the work around the answering is where the time actually goes.
The scale of that work is easy to underestimate. 60% of companies run customer security reviews with two people or fewer, each covering 80 to 100 sales reps and around 287 questionnaires a year, which eats about 30% of their time. Manually reviewing and validating responses is the single biggest frustration in the job, at 51%.
Very little of that is someone typing answers. It is the request sitting in an inbox for four days, the NDA, working out who owns the encryption question this quarter, the follow-up thread nobody is tracking. Callie described Carta's version before they fixed it:
"Before Conveyor, customers had to request security documents manually. We'd spend hours tracking NDAs, sending files, and re-answering the same 200-question spreadsheets."
The fix is a defined path that a review travels down, with a human involved at the points where judgment is actually required.
What good looks like at this stage:
- One front door. Requests arrive one way, not through five different people's email
- Automatic intake. The questionnaire gets parsed, matched and pre-answered before a human opens it
- Named ownership. Sales, legal, compliance, product and security each know which questions are theirs and what the turnaround expectation is
- A real escalation path. When something genuinely needs an engineer, there is a route to one that does not depend on who you happen to know
- Notifications where people already work. Carta wired theirs into Slack and Salesforce, so completion and access events reach the deal team without anyone checking a separate tool
An SLA is the test of whether any of this is real. 65% of teams have a formal SLA for returning questionnaires. Only 33% hit it more than 90% of the time. A commitment sales can actually plan against is rarer than it looks.
Step 4: Let customers and sales serve themselves
Everything up to this point makes you faster at answering questions. This step is where you shift from reactive to proactive by deflecting requests before they even hit your team.
When Carta opened a trust center (self-serve access to audit reports, policies and FAQs, with NDA handling built in) their inbound security questionnaires dropped by 40%. Not 40% answered faster. 40% that never became a questionnaire at all.
This is also where the regulatory pressure from earlier turns into an advantage. A reviewer assembling a DORA register needs your entity details, data locations and subcontractor list in a form they can use. Someone working out whether you use AI needs a disclosure they can read without asking. Publish that material and you stop being the vendor they have to chase. You become the easy one in a portfolio of 300.
Trust Centers have become table stakes, and it's an easy conclusion to think they are all built the same. They are not. The benchmark data makes the gap obvious: 71% of teams have a Trust Center, but only 44% make it the required first step for a customer request. The other 27% have a portal that exists while requests still land back in the team's inbox.
What good looks like at this stage:
- Connected to your CRM, so it knows who is visiting and gives them proper access
- Agentic, with a helpful agent built in, not a chat bot
- Meets the new 2026 FedRAMP requirements
- Built for humans and machines
- Treated as the required first step internally, not an optional link sales sometimes sends
One word of caution. A trust center built on top of a weak knowledge base does not save you time, it broadcasts your inconsistencies to prospects at scale. This step is fourth on the list for a reason.

Step 5: Optimize, manage, report and improve
The first four steps build the machine. This one is how it survives budget season.
Customer trust work has a chronic measurement problem. It is obviously valuable to everyone doing it and nearly invisible to everyone above it, because the wins are things that did not happen: the deal that did not stall, the questionnaire that never arrived.
The benchmark shows how wide that gap runs. 63% of teams report questionnaire volume to leadership. Only 40% report the revenue that work influenced, and at mid-market companies it drops to 22%. Volume tells leadership how busy you are. Revenue tells them what you are worth.
So instrument it. The arithmetic is not complicated: analyst hours, plus coordination overhead, plus the cost of deal delay. We walk through a worked version of this, and for most teams it lands north of half a million dollars a year before counting a single delayed deal. Most teams have never put a number on it, and once you do, the conversation with your CFO changes shape.
Worth tracking from the start:
That fourth one is underrated. What gets opened tells you what buyers are worried about, which tells you what to publish next.
David MacFarlane, Carta's CISO, described what that visibility gave him:
"Conveyor handles the repetitive work so we can focus on higher-value projects. It's smoothed out our sales cycle, sped up deals, and given us better visibility into customer impact and revenue generated."
That last clause is the difference between a security function that reports on tickets closed and one that can point at revenue. Alteryx, an analytics company running the same play, got first-ever visibility into more than $500M in security-influenced revenue (Alteryx).
Nows the time to start
Carta supports more than 50,000 customers across 160 countries with sensitive financial data. Here’s what they achieved by investing in Customer Trust and Conveyor.
- 40% fewer inbound security questionnaires.
- 83% less time spent on customer security reviews.
- 95% AI accuracy on the ones that still arrive.
Their investment in customer trust has accelerated growth, in a big way.
"Conveyor helps us grow without adding headcount, the kind of AI partner every security team wants." — Callie Dedinsky, Carta
2027 will only bring new regulation, new AI concerns, and new breaches. The time is now to invest in customer trust and set yourself up for unrestricted growth.
Benchmark figures throughout are from the 2026 Conveyor Customer Trust Benchmark, a survey of 52 B2B software and technology companies.
-p-1600.avif)

.png)



