{"_id":"@accountmade/questionnaire-parser","_rev":"2-db9a7a9e2b14af3800b5cf89c9272301","name":"@accountmade/questionnaire-parser","dist-tags":{"latest":"0.1.1"},"versions":{"0.1.0":{"name":"@accountmade/questionnaire-parser","version":"0.1.0","keywords":["security questionnaire","SIG","CAIQ","VSA","VSAQ","vendor security","parser","xlsx","docx"],"author":{"url":"https://accountmade.com","name":"AccountMade"},"license":"MIT","_id":"@accountmade/questionnaire-parser@0.1.0","maintainers":[{"name":"theplainworks","email":"hello+dev@theplain.works"}],"homepage":"https://github.com/accountmade/questionnaire-parser#readme","bugs":{"url":"https://github.com/accountmade/questionnaire-parser/issues"},"bin":{"qparse":"dist/cli.js"},"dist":{"shasum":"7a39d3e8e8bbc10577b1e4da48a157f70136aa90","tarball":"https://registry.npmjs.org/@accountmade/questionnaire-parser/-/questionnaire-parser-0.1.0.tgz","fileCount":17,"integrity":"sha512-dWzbwsibDC1P1nLMPjVlefrtTzh9Sl0PnCLF9M7Y1ZnoDpGOStAqa06ZmyKWErxZAn7mZhLlsfztacQUBKp+cg==","signatures":[{"sig":"MEUCIFjPq0est3JWHVs0Mw8P5pO/CIa7Ic1yOTZmqzifYvaBAiEAxQA4f6k8pDXEWT87kduw4qnixHf29e1CVvNINv9ir4I=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@accountmade%2fquestionnaire-parser@0.1.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":32029},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=18"},"gitHead":"dc4dc240d5e725c87e1751a17dffab311bd0b64a","scripts":{"test":"tsx --test test/*.test.ts","build":"tsc","prepublishOnly":"npm run build"},"_npmUser":{"name":"theplainworks","email":"hello+dev@theplain.works"},"repository":{"url":"git+https://github.com/accountmade/questionnaire-parser.git","type":"git"},"_npmVersion":"10.8.2","description":"Parse a SIG / CAIQ / VSA / VSAQ security questionnaire (xlsx, docx, pdf, csv) into structured JSON. Ingest + normalize + framework detection only — no answers, no auto-fill.","directories":{},"_nodeVersion":"20.20.2","dependencies":{"exceljs":"^4.4.0","mammoth":"^1.7.2","pdfjs-dist":"^4.7.76"},"publishConfig":{"access":"public","provenance":true},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.0","typescript":"^5.5.0","@types/node":"^20.14.0"},"_npmOperationalInternal":{"tmp":"tmp/questionnaire-parser_0.1.0_1783595129828_0.8269899629148161","host":"s3://npm-registry-packages-npm-production"}},"0.1.1":{"name":"@accountmade/questionnaire-parser","version":"0.1.1","description":"Parse a SIG / CAIQ / VSA / VSAQ security questionnaire (xlsx, docx, pdf, csv) into structured JSON. Ingest + normalize + framework detection only — no answers, no auto-fill.","type":"module","license":"MIT","author":{"name":"AccountMade","url":"https://accountmade.com"},"repository":{"type":"git","url":"git+https://github.com/accountmade/questionnaire-parser.git"},"homepage":"https://github.com/accountmade/questionnaire-parser#readme","bugs":{"url":"https://github.com/accountmade/questionnaire-parser/issues"},"publishConfig":{"access":"public","provenance":true},"keywords":["security questionnaire","SIG","CAIQ","VSA","VSAQ","vendor security","parser","xlsx","docx"],"bin":{"qparse":"dist/cli.js"},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=18"},"scripts":{"build":"tsc","test":"tsx --test test/*.test.ts","prepublishOnly":"npm run build"},"dependencies":{"exceljs":"^4.4.0","mammoth":"^1.7.2","pdfjs-dist":"^4.7.76"},"devDependencies":{"@types/node":"^20.14.0","tsx":"^4.19.0","typescript":"^5.5.0"},"_id":"@accountmade/questionnaire-parser@0.1.1","gitHead":"fd89dad81e2eb593f57fc37f21d537ced87a69e0","_nodeVersion":"20.20.2","_npmVersion":"10.8.2","dist":{"integrity":"sha512-PXWJP75Nf1/Y3FcpvYH7c0ZypxpC2AAwg8P+4+IUHwwTZ/qAs2byzdeNu8Ut7RRSzoRS8lyNhah6rz/3CVw7QQ==","shasum":"e61b6333b76ae3563393466cfd6dee836b12fd1a","tarball":"https://registry.npmjs.org/@accountmade/questionnaire-parser/-/questionnaire-parser-0.1.1.tgz","fileCount":17,"unpackedSize":32029,"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@accountmade%2fquestionnaire-parser@0.1.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQDQMzfhAw0pNw7uGTEa86H1rRcZJFbodUabDgsmMSx2CQIhAIgQYXPI9RyCOnp0nadqefcNjTZAet2kqa5C5S4aHJ7y"}]},"_npmUser":{"name":"theplainworks","email":"hello+dev@theplain.works"},"directories":{},"maintainers":[{"name":"theplainworks","email":"hello+dev@theplain.works"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/questionnaire-parser_0.1.1_1783596457314_0.3423301187502208"},"_hasShrinkwrap":false}},"time":{"created":"2026-07-09T11:05:29.669Z","modified":"2026-07-09T11:27:37.751Z","0.1.0":"2026-07-09T11:05:29.963Z","0.1.1":"2026-07-09T11:27:37.446Z"},"bugs":{"url":"https://github.com/accountmade/questionnaire-parser/issues"},"author":{"name":"AccountMade","url":"https://accountmade.com"},"license":"MIT","homepage":"https://github.com/accountmade/questionnaire-parser#readme","keywords":["security questionnaire","SIG","CAIQ","VSA","VSAQ","vendor security","parser","xlsx","docx"],"repository":{"type":"git","url":"git+https://github.com/accountmade/questionnaire-parser.git"},"description":"Parse a SIG / CAIQ / VSA / VSAQ security questionnaire (xlsx, docx, pdf, csv) into structured JSON. Ingest + normalize + framework detection only — no answers, no auto-fill.","maintainers":[{"name":"theplainworks","email":"hello+dev@theplain.works"}],"readme":"# questionnaire-parser\n\nParse a security questionnaire — **SIG, CAIQ, VSA, VSAQ, or a bespoke one** — from\n`.xlsx`, `.docx`, `.pdf`, or `.csv` into structured JSON: a normalized list of\nquestions plus the detected framework(s), with evidence and confidence.\n\n**Ingest and normalize only.** This library extracts and classifies questions. It\ndoes **not** answer them, auto-fill responses, rank answers, or ship an answer\nlibrary — by design. It's the parsing primitive, nothing more.\n\n```bash\nnpm install questionnaire-parser\n```\n\n## CLI\n\n```bash\nnpx qparse ./SIG-Core-2025.xlsx --pretty\nnpx qparse ./caiq.xlsx --questions-only > questions.json\n```\n\n## Library\n\n```ts\nimport { parseFile } from \"questionnaire-parser\";\n\nconst result = await parseFile(\"./caiq-v4.xlsx\");\n\nresult.meta.questionCount;        // 261\nresult.primaryFramework?.name;    // \"CAIQ v4 (CSA Cloud Controls Matrix)\"\nresult.primaryFramework?.confidence; // \"high\"\nresult.questions[0];              // { id: \"IAM-14\", text: \"Is MFA enforced…\", section: \"Identity & Access Management\" }\n```\n\nParse an in-memory buffer (e.g. a browser upload passed to a server) instead:\n\n```ts\nimport { parseBuffer } from \"questionnaire-parser\";\nconst result = await parseBuffer(buffer, \"xlsx\", \"upload.xlsx\");\n```\n\nOr run the pure core directly on rows/text you've already extracted:\n\n```ts\nimport { extractFromRows, detectFrameworks, pickPrimary } from \"questionnaire-parser\";\n\nconst questions = extractFromRows(rows, \"Sheet1\");\nconst frameworks = detectFrameworks(questions, rawText, sheetNames);\nconst primary = pickPrimary(frameworks); // null when bespoke/ambiguous\n```\n\n## Output shape\n\n```jsonc\n{\n  \"questions\": [\n    { \"id\": \"IAM-14\", \"text\": \"Is MFA enforced for privileged access?\", \"section\": \"Identity & Access Management\" }\n  ],\n  \"frameworks\": [\n    {\n      \"framework\": \"caiq\",\n      \"name\": \"CAIQ v4 (CSA Cloud Controls Matrix)\",\n      \"confidence\": \"high\",\n      \"evidence\": [\"43 control IDs match the CAIQ v4 grammar\", \"title/header text: \\\"caiq\\\"\"],\n      \"matchedIdCount\": 43,\n      \"source\": \"CSA Cloud Controls Matrix / CAIQ v4 (cloudsecurityalliance.org)\",\n      \"score\": 133\n    }\n  ],\n  \"primaryFramework\": { \"framework\": \"caiq\", \"...\": \"...\" },\n  \"meta\": { \"file\": \"caiq-v4.xlsx\", \"format\": \"xlsx\", \"questionCount\": 261 }\n}\n```\n\n## How detection works\n\nOne generic scorer runs over a table of **framework fingerprints** (control-ID\ngrammar, header/tab strings, approximate size). There is no per-framework code\nbranch — adding a framework is a data entry, not a new code path. ID grammar and\nheader text dominate; question count is only a weak tiebreaker. SOC 2 and ISO 27001\nare treated as cross-maps (they often appear *inside* another questionnaire) and are\ndown-weighted for primary selection.\n\nSupported fingerprints: CAIQ (CSA CCM), SIG (Shared Assessments), SOC 2, ISO 27001,\nGoogle VSAQ, Vendor Security Alliance (VSA).\n\n## Development\n\n```bash\nnpm install\nnpm test      # runs the core tests (node:test via tsx)\nnpm run build # emits dist/ (ESM + types)\n```\n\n## License\n\nMIT. Framework names and control-ID grammars are referenced for interoperability\nand belong to their respective publishers (CSA, Shared Assessments, AICPA, ISO,\nNIST, Google).\n","readmeFilename":"README.md"}