Key Takeaways

  • GitHub automatically answers 92% of inbound security questionnaires using Vanta's AI tooling, leaving humans to handle final review.
  • AI evidence evaluation instantly flags bad audit submissions, catching missing timestamps or accidental cat photos before an auditor sees them.
  • LLMs compress the front-end prep work for compliance audits, but automated background monitoring remains necessary for ongoing trust.
  • Startups can keep security, compliance, and IT unified under one person for much longer instead of hiring three separate teams.

Automating the 92% Grunt Work

Vendor security reviews are a notorious drag on enterprise sales cycles. A prospective customer sends an 80-page spreadsheet asking about encryption standards, access logs, and disaster recovery. A sales engineer or security lead spends four days copying answers from older spreadsheets, tweaking phrasing, and hunting down attachments.

Christina Cacioppo, founder and CEO of Vanta, shared with John Collison how fast that dynamic shifted once language models stepped in. “To that, actually, GitHub gets 92% of all of the questionnaires they receive answered through Vanta,” Cacioppo noted. “You're not at 100, but you're like, 'It's GitHub. They have AI tools. They have Copilot. It's a lot.' We are absolutely seeing this.”

When autonomous workflows pre-fill nine out of ten technical answers with accurate references to internal policies, the human job changes completely. Nobody writes answers from scratch. The security lead acts purely as an editor, verifying edge cases and signing off on the finished document in minutes.

Pre-Audit Scrubbing vs Continuous Tracking

Passing an audit used to mean months of manual file collection. Teams dumped screenshots and spreadsheets into shared folders, hoping the auditor would accept them. Now, agentic workflows evaluate that evidence before any human auditor opens it.

“We now do AI evidence eval,” Cacioppo said. “It's like, 'Oh, you're going to provide this piece of evidence.' We can just tell you, is it going to work for this auditor? Did you upload a cap picture? Did you upload a screenshot without a timestamp on it?”

Yet chat interfaces only solve the intake problem. Cacioppo made a clear distinction between the initial document preparation and ongoing verification: “We think about it as they have lowered the initial audit prep in a way inside, outside Vanta... But the continuous monitoring piece. That you're not going to get out of at least LLM chat.”

Prompting an LLM can draft your security policies or format your SOC 2 responses. It cannot verify whether an engineer left an S3 bucket public at 2 a.m. last night. That still requires continuous, automated integrations pulling telemetry directly from your cloud provider.

The Three-in-One GRC Operator

In early-stage technology companies, specialized back-office roles are consolidating. In the past, scaling past 50 employees meant hiring a dedicated IT admin, then a compliance manager, then an internal security lead. Today, automated tooling lets one operator do all three jobs simultaneously.

“You have the security-compliant IT collapse into one role,” Cacioppo explained. “You can keep them unified for longer.”

Collison summarized the shift: “You're saying that AI will eat up a lot of the hourly labor part of compliance and leave people doing the strategy work.”

When questionnaire completion and evidence checks run on autopilot, a single technical operations hire can manage the entire GRC stack well into a company's Series B.

What to Do With This

Stop routing enterprise vendor questionnaires to your engineering leads. Set up an automated questionnaire repository this week, load your existing security policies, and require your team to review generated answers rather than writing responses manually.