Vouch - security questionnaire automation with cited RAG answers
The challenge
Security questionnaires take hours, but most answers already exist in internal policies. The hard part is preventing hallucinated or uncited answers.

What I built
Vouch auto-fills B2B security questionnaires (SOC 2 / ISO 27001) — 4 to 12 hours saved each — with one non-negotiable rule: every answer is cited back to the source paragraph, or rejected. The guarantee doesn't depend on a developer remembering to call it; it lives in the domain model, so a high-confidence answer without a citation literally cannot be built. Pure .NET RAG, no Python sidecar, evaluable in 30 seconds with no API key or database.
It is my preferred GenAI pattern: use the model, but make the code enforce the invariant that business risk cares about — hallucination becomes impossible by construction, not discouraged by convention.
Key engineering points
Pure .NET RAG pipeline without a Python sidecar.
Mandatory source citation before an answer can be accepted.
Questionnaire import and answer generation for SOC 2 / ISO 27001-style workflows.
Tests around the invariant: no source, no answer.
Similar technical risk?
I can help scope the risk, architecture and first deliverable.
A 30-minute first call is enough to see whether I am the right profile for the problem.
A similar challenge?
A system like this one to build? Let's talk.
I take on critical technical work — from scoping to production, no debt or lock-in once it's handed over. Fastest way to see if it fits: a 30-minute call.
I reply within 24h — often sooner.