How I Built an AI Agent That Completes Enterprise Security RFIs in Hours, Not Weeks

About this session

Enterprise sales still die in spreadsheets and Word docs. Security questionnaires, DPAs, and AI addendum questions can take days per deal, and every “Yes, we use AI” answer triggers legal review.

I’m a GRC lead at a global ad-tech company. I didn’t wait for a perfect internal tool. I built an RFI agent in Cursor: project rules that encode our workflow, a knowledge-base CSV of approved answers, Python automation that fills .docx templates and marks new text for human review, and a GitLab mirror so the team can reuse it on VPN.

In this session I’ll walk through the architecture (what the agent does vs. what humans must approve), a live-style walkthrough on a real questionnaire pattern, and the guardrails that keep us from hallucinating into customer contracts. You’ll leave with a checklist to replicate this in any function that answers the same questions repeatedly through security, privacy, procurement, or customer success.

Speaker

Key takeaways

  • How to structure knowledge base + rules + scripts so AI fills gaps instead of rewriting truth
  • What never to automate (SLAs, pricing, controller/processor calls)
  • Visual diff patterns so Legal/Security review stays fast

Related sessions