Iris is a strong shortlist candidate for revenue and security teams with high RFP and questionnaire volume that want first drafts in minutes and a system that actively surfaces stale content. The knowledge-ledger framing is a genuine differentiator if it holds up in practice: most teams’ real failure mode is drift between source-of-truth answers, not raw generation speed. Diligence should test how well the ledger detects inconsistency on your content and how governance gates final submissions.
Is Iris right for your team?
Iris (heyiris.ai) is an AI platform for RFP, RFI, and security questionnaire response built around a "knowledge ledger" that keeps institutional answers current and consistent.
Knowledge-ledger framing targets content drift, not just drafting speed.
Research inputs reviewed for this profile.
Structured integration coverage represented in this profile.
Features, workflow steps, and newer capabilities represented in this profile.
Where Iris is strongest
These scores reflect the materials reviewed for this page. Use them to plan your demo, not as a product rating.
Published support for intake, routing, review, approval, and reuse.
Published SSO, roles, audit, and rollout controls.
Published support for drafting, checking, and approving answers.
Pricing and rollout at a glance
Quote-based subscription
Confirm tiers, seat model, and usage limits directly with Iris.
Expect knowledge ingestion, ledger validation, and approval-gate configuration.
Confirm who owns source cleanup, reviewer setup, and integrations.
Branded template exports.
Ask how the knowledge ledger exports at contract end.
What Iris does
Iris is an AI response platform that generates RFP, RFI, RFQ, and security questionnaire answers from organizational knowledge. Public materials describe knowledge-base ingestion (drag-and-drop, integrations, web scraping), AI response generation with inline citations and confidence scores, collaborative workflow with task assignment, and branded template exports.
The defining concept is the "knowledge ledger": Iris proactively identifies outdated and inconsistent information across connected systems so that when information updates in one place, it updates everywhere. This positions Iris as much around content freshness and governance as around drafting speed.
Who should use Iris?
Use cases
Where Iris is most useful.
Generate sourced first drafts for proposals and information requests from institutional knowledge.
Auto-fill security questionnaires with confidence scoring and human approval for sensitive answers.
Use the knowledge ledger to detect outdated or conflicting answers across connected systems.
Teams and users
The people most likely to use the product during questionnaires, RFPs, assessments, and customer security reviews.
Runs RFP projects, assigns sections, and reviews generated drafts.
Approves questionnaire answers and maintains the knowledge ledger.
How Iris handles a questionnaire
Ingest knowledge
Teams add documents and connect systems; web scraping and integrations build the ledger.
Generate drafts
Iris drafts answers with citations and confidence for RFPs and questionnaires.
Review and govern
Reviewers approve answers; the ledger flags stale or conflicting content for cleanup.
Features to test in a demo
Knowledge ledger
A living, connected knowledge system that flags outdated and inconsistent answers and propagates updates.
- Targets content drift, the most common cause of inaccurate questionnaire answers.
AI response generation
Generates first drafts in minutes with inline citations and confidence scores, customizable by tone.
- Collaborative workflow supports task assignment and branded exports.
Integrations and customer examples
Integrations
Connections to source documents, review tools, customer portals, and sales systems.
Knowledge ingestion.
Knowledge ingestion.
Knowledge ingestion.
Knowledge ingestion.
Collaboration and notifications.
APIs and AI tooling
Features to ask about if APIs or AI tooling matter to your team.
Proactively surfacing stale or conflicting answers addresses the most common cause of bad questionnaire responses.
Human approval for submissions and knowledge-base additions keeps automation safe for security content.
Compare Iris with alternatives
Buyer checklist
What to test in an Iris demo
Prove the ledger, sourcing, and governance with your content.
Seed two conflicting answers and confirm the ledger surfaces them.
Verify that drafts expose sources and confidence for reviewer trust.
Confirm that final submissions and new knowledge require human approval.
Claims to verify before purchase
Validate freshness, governance, and enterprise readiness.
Confirm how reliably stale/conflicting content is detected on your data.
Confirm tiers, seat model, and usage limits directly.
Confirm SSO, RBAC, audit logs, data handling (Iris references SOC 2 Type 2, GDPR).
What isn’t publicly documented
Confirm these items directly during procurement.
Verify with vendor
Verify with vendor
Verify with vendor
Verify with vendor
Verify with vendor
Verify with vendor
Verify with vendor
Company information
Iris (legal name IRIS AI TECHNOLOGIES, INC.) is a privately held, venture-backed AI response company founded in 2023 and headquartered in New York, led by founder and CEO Ben Hills. Company-profile details should be treated as point-in-time context.
Company snapshot
Questions to ask Iris
Ask these questions in the Iris demo, then test the answers with your own content and approval process.
- Does the product answer customer requests, send vendor assessments, or both?
Iris mainly helps your team answer customer questionnaires and share security material. It is not a full third-party risk management system for assessing suppliers.
- Can every AI-drafted answer be traced to its source?
Iris says drafted answers use source material. In the demo, open several citations and test what happens when sources conflict or go out of date.
- Which questionnaire files and customer portals can it handle?
Iris documents file and customer portal support. Test a real spreadsheet, PDF, and difficult portal before buying.
- Which standard and custom questionnaires does it support?
Iris does not clearly document SIG, CAIQ, HECVAT, or VSA support. Ask whether each is built in, available as a template, or handled as a custom import.
- Does it include buyer-side vendor risk assessment?
Iris is not primarily a buyer-side vendor risk product. If you need to score suppliers before sending assessments, evaluate that separately.
- Can its trust center prevent repeat questionnaires?
Iris does not list a trust center as a core feature. If customer self-service matters, compare it with products that include one.
- How does review, approval, answer ownership, and audit history work?
Iris documents review and approval controls. In the demo, test a low-confidence answer, expert assignment, final approval, and the audit record.
- Does it connect to the systems your team already uses?
Iris lists 5 integrations across document storage, knowledge bases, and collaboration. Examples include Google Drive, SharePoint, Confluence, Notion, and Slack. Confirm what each connection can do, whether API work is required, and which plans include it.
- How are reused answers updated when policies, reports, or products change?
Iris documents controls for maintaining source content. Ask who updates policies, SOC 2 reports, subprocessors, and product details—and whether those changes reach every reused answer.
FAQ
What is the Iris knowledge ledger?
Iris frames its knowledge base as a living "ledger" that proactively flags outdated and inconsistent answers and propagates updates across connected systems.
Does Iris handle security questionnaires?
Yes. Iris automates security questionnaire responses alongside RFP/RFI/RFQ, with confidence scoring and human approval for sensitive answers.