Skip to content

Security and GRC in the age of AI

I run security at Decagon. This is where I write about it.

Decagon builds AI customer support for enterprise. I handle security and GRC there — redlines, vendor reviews, audits, the usual. Customer names stay out when they need to.

Traditional GRC assumed controls and policies moved at human pace. That assumption is broken — this site documents how AI-native GRC operations actually work in production: coding agents, LLM-assisted audit prep, live deal flow, and contract negotiation.

By Ben Draffin · Director of Security at Decagon

Start here

Redline volume tracks control maturity

On a recent stretch of enterprise deals I was working on, the volume of redlines we were making to contracts started dropping. Customer counsel hadn't gotten easier; our engineering team had shippe...

Newsletter

Email when I publish. Usually about once a week.

You'll get a confirmation email first.

Publishing

I post when I have something worth sharing from deals, audits, or vendor work at Decagon. Drafts stay off the site until they're done.

Latest

Recent posts.

Full archive →