A field report on the audit that stalls a startup’s biggest deals — six months of hand-written policies, screenshot evidence and questionnaire hell — and the ex-AWS engineer whose AI agents now do the work in weeks.
It arrives mid-deal, every time. The biggest customer of the year is finally at the table, the pricing is agreed, and then procurement clears its throat: before we sign, we’ll need your SOC 2. Or your ISO 27001. What follows has become a rite of passage for every software company that wants to sell to serious buyers — the six-month side-project nobody was hired for. Policies drafted from templates into a graveyard of Google Docs. Evidence collected by hand: screenshots from dozens of systems, uploaded one by one. A risk register in a spreadsheet, stale the week it is finished. Engineers pulled off the roadmap to feed an audit. And a security questionnaire that eats ten to twenty hours per customer, answered by copying answers out of the last one.
The absurd part is that most of these companies are already doing the things the certificate describes. A cloud-native business inherits encryption, access controls, logging and backups as a matter of course; the burden was never the controls, it was proving them — by hand, in artifacts, on a deadline. The direct costs are real enough — consultants, auditors, tooling — but the tax that stings is time: months of it, at precisely the moment the company is trying to grow. A first generation of compliance software promised to fix this and mostly built dashboards: the tracking improved, the work remained. And the work never actually ends, because the certificate is a photograph — point-in-time proof of a March that has usually drifted by June, rebuilt again every audit cycle.
This transmission is about an infrastructure engineer who spent two decades building the systems those frameworks describe — including four years inside AWS, helping its customers build properly on the cloud the auditors keep asking about — and who has now co-founded the platform where AI agents simply do the compliance work themselves. Readers will know the shape this series documents by now — decades of judgment, encoded into a system. This is the sixth time we have filed the story, and the first in which the system fills in the paperwork.
Anish — first names are policy here; he can introduce himself properly — is a Melbourne-based engineer with, by his own count, two decades across startups and Fortune 500s: cloud architecture, infrastructure, DevSecOps — the load-bearing layers auditors ask about and users never see. The formative posting was the most recent one. From 2020 to 2024 he was at AWS — first as a Cloud Architect, then as a Solutions Architect for SaaS companies — a job he describes simply as “helping customers get the best out of AWS.” It is also a vantage point: years spent inside the cloud provider, watching digital-first companies build well and then watching the same companies grind to a halt when the compliance question arrived.
In March 2024 he left to found Ciphrix with a fellow ex-AWS security leader — twenty-plus years in cybersecurity, with Accenture and Sun Microsystems before that — who took the CEO seat while Anish took CTO. Their founding observation, stated on the company’s own site, is the cleanest description of the category’s failure we have read: “Compliance tools improved visibility. The work stayed manual.” Dashboards replaced spreadsheets; integrations reduced uploads; and policies were still written from scratch, evidence still gathered by hand, audits still rebuilt every cycle. Their label for what comes after is GRC 3.0.
The insight underneath the company is an engineer’s insight, and it explains the CTO’s LinkedIn headline — “agent wrangler” — better than any job description. Compliance frameworks mostly describe good engineering. In a cloud-native company the proof already exists as data, sitting in the very systems he spent a career building; a screenshot is just an API call that gave up. So the fix is not a better dashboard for humans doing manual work. It is agents, wired into the stack, doing the work.
Ciphrix ships what it plainly calls an AI compliance team — “not just tracking tasks or assisting, actually doing them.” A Policy agent generates complete, audit-ready policies tailored to the company’s context — no generic templates, no blank page. A Risk agent scores and routes risks instead of letting a spreadsheet go stale. A Vendor agent and an Answer agent absorb the questionnaire hell from both directions — the ones you send and the ones you receive. Evidence collection runs continuously against the stack, and controls are written once and reused across frameworks: ISO 27001, SOC 2, HIPAA, GDPR and onward to the newer alphabet — ISO 42001, the EU AI Act — ten-plus frameworks on universal controls, designed, in their words, for modern tech stacks and cloud-native architectures.
The operating model is the deeper break. The company’s first principle — it literally numbers it Principle 0 — is “systems over documents”: continuous evidence over audit-time collection, reuse over duplicate work, execution over tracking. In their words, compliance “runs inside your system, not as a separate project,” and the audit becomes a validation of what already exists rather than a quarterly reconstruction. The ecosystem is invited in rather than fought: auditors log in directly, partners and MSPs run white-labelled programmes, and for a startup’s first certification the humans stay in the loop — in their own words, “we talk to auditors, close findings, get you certified.” The platform, fittingly, is itself ISO 27001 certified.
The receipts are specific. Typical time to certification is four to eight weeks; the company says it has delivered ISO 27001 in six weeks multiple times, for certified customers across three continents — teams in Australia, the United States and India. One CEO on the customer page: “We got ISO 27001 done in 4 weeks, without building a compliance team.” Another was stuck on privacy for months and, in his words, got through in weeks and “unblocked our enterprise deals” — which is the entire economic point. The company runs with the backing of the startup programmes of all three major clouds, and its pitch compresses to one line from its own overview: from a six-month burden to a six-week advantage.
Notice, for the sixth time in this series, the shape. In our last transmission we made a point of admiring a legal-AI startup that turned up ISO 27001 certified at pre-seed age, and called the certification its go-to-market. This month’s operators industrialise exactly that move — a security leader’s twenty years and an infrastructure engineer’s two decades, encoded into agents that make the trust legible on demand. The certificate was always trust in document form. What changed is that printing it no longer costs half a year.
Strip away the frameworks and the rules travel to any company that sells to buyers bigger than itself:
Treat the certificate as a sales asset, not a tax. It sits in the critical path of your largest deals. Price the delay in lost pipeline, not audit fees, and the case for automating it makes itself.
Evidence should be queried, not manufactured. If you build cloud-native, the proof of your controls already exists as data. A screenshot is an API call that gave up.
Certify continuously or you were compliant in the past tense. The point-in-time audit is a photograph, and drift is the default state of every system. The steady state beats the annual panic.
Write controls once; let frameworks borrow them. SOC 2, ISO, HIPAA and GDPR largely describe the same good engineering. Duplicate the work per framework and you will run four audits a year forever.
Buy work, not visibility. Dashboards that watch you do the work were the previous generation. The test for any automation is brutal and simple: after it runs, is the artifact done?
What changes when the paperwork does itself is mostly measured in what stops happening. The security questionnaire stops being an emergency. The policies arrive written, in the company’s own voice. The evidence collects itself while everyone sleeps. The engineers stay on the roadmap, the risk register stays warm, and the certificate lands while the deal that demanded it is still on the table.
There is also a neatness to who is doing this. Two operators who spent years inside the world’s biggest cloud, watching from the provider’s side as good companies built good systems and then stalled for half a year trying to prove it — now encoding that entire observation into software. The compliance industry spent a decade making the grind more visible. It took a pair of infrastructure people to make it disappear.
So if there is a questionnaire sitting in your inbox right now with a deal behind it — or if you would simply rather be certified before anyone asks — the agent team is at ciphrix.com, and their own overview states the trade plainly: a six-month burden, turned into a six-week advantage. The certificate was always supposed to be the receipt for how you already build. It was never supposed to take six months to print.
— END TRANSMISSION 05F
We publish roughly once a month. One email when it lands, if you ask for it.
Ask for the one email →