Skip to content

Security and GRC in the age of AI

I ran security, GRC and IT at Decagon. This is where I write about it.

Decagon builds AI customer support for enterprise. I handled the enterprise-readiness side there: redlines, vendor reviews, audits, and the diligence that decides whether a young AI company gets to sell to a careful buyer.

Traditional GRC assumed controls and policies moved at human pace. That assumption is broken. This site documents how AI-native GRC operations actually work in production: coding agents, LLM-assisted audit prep, live deal flow, and contract negotiation.

By Ben Draffin · Director of Security, GRC and IT at Decagon

Start here

Redline volume tracks control maturity

On a recent stretch of enterprise deals I was working on, the volume of redlines we were making to contracts started dropping. Customer counsel hadn't gotten easier; our engineering team had shippe...

Stay updated

Email when I publish. Deal patterns and tradeoff tables from enterprise security work, usually about once a week.

You'll get a confirmation email first.

How I publish

I post when I have something worth sharing from deals, audits, or vendor work during my time at Decagon.

Recent writing

What I've published lately.

Full archive →