SecurityPal makes use of AI, consultants in Nepal to reply safety qs quicker

Metro Loud
11 Min Read

Need smarter insights in your inbox? Join our weekly newsletters to get solely what issues to enterprise AI, information, and safety leaders. Subscribe Now


When a tech vendor desires to promote into a big enterprise — or when that enterprise desires to purchase software program from a tech vendor or AI mannequin supplier — all sides could also be required by the opposite to show they may deal with shared information responsibly within the type of obligatory surveys and questionnaires.

Rules reminiscent of GDPR, the soon-to-be effected EU AI Act and a patchwork of U.S. state legal guidelines make these proofs extra advanced annually.

As a consequence, a tech vendor attempting to promote to a big enterprise will normally be requested to finish safety questionnaires that may stall offers for weeks and price six figures in workers time.

San-Francisco-based SecurityPal was based in March 2020 by CEO Pukar Hamal to deal with all that paperwork largely mechanically on behalf of the seller, utilizing the seller’s distinctive product data and inner information.


The AI Influence Sequence Returns to San Francisco – August 5

The following part of AI is right here – are you prepared? Be part of leaders from Block, GSK, and SAP for an unique have a look at how autonomous brokers are reshaping enterprise workflows – from real-time decision-making to end-to-end automation.

Safe your spot now – area is restricted: https://bit.ly/3GuuPLF


SecurityPal combines an AI engine with a 240-person analyst workforce in Kathmandu, Nepal, to draft, confirm and package deal the solutions distributors and consumers want.

“It’s like Palantir for safety opinions — skilled people and AI working collectively to speed up enterprise safety assessments,” Hamal stated on a current unique video name with VentureBeat.

Hamal labels the class “safety assurance”: a workflow that sits between conventional compliance software program and the sales-ops stack.

The corporate simply introduced a fleet of updates in its Q2 weblog submit this week, together with smarter fallback responses from its AI Copilot, a completely brandable White Label Package deal for Belief Facilities, and a brand new Customized HTML Block for embedding wealthy media in assurance profile, all geared towards making its AI interactions extra skilled and informative, even when information is restricted.

The agency has additionally added Salesforce Auto-Approval, which allows real-time, criteria-based approvals utilizing reside Salesforce information; International Search throughout the complete SecurityPal platform; and shortly, a Customized Duties characteristic that ought to let prospects handle workflows with customized fields and varieties.

“We’re on a mission to speed up GDP development by fixing advanced safety assurance challenges for consumers and sellers,” Hamal added, additional providing that, “my thesis after we raised cash was that there will likely be $10 trillion firms, and we’re watching market caps within the a whole lot of billions or extra. That calls for a radically completely different capital technique.”

How the service works

SecurityPal ingests a buyer’s current controls — insurance policies, cloud configurations, attestations — and maps them to a proprietary corpus of roughly 2.5 million beforehand answered safety questions it has assembled from prospects and filtered internet information.

The corporate makes use of a mixture of cutting-edge third-party AI fashions, amongst them, these from OpenAI, Google’s Gemini household, and open-source options.

However Hamal emphasised that the true worth lies in how these fashions are utilized, explaining: “AI alone isn’t sufficient. With AI, you get pace, however you sacrifice high quality, judgment, and context.”

To deal with this, SecurityPal integrates AI with skilled human analysts in a tightly interlaced workflow, guaranteeing accuracy and nuance in each safety assessment. Whereas the fashions are broadly out there, the corporate’s proprietary information, deep buyer relationships, and human-in-the-loop design kind a important moat that makes their resolution excess of simply automation.

The AI engine takes the primary move; human analysts carry out a second move and remaining QA to catch hallucinations or lacking context. Hamal likens the impact to having an examination key upfront: “It’s nearly like SecurityPal is aware of the solutions to the check earlier than the check reveals up.”

As a result of the platform maintains a dwelling mannequin of every buyer’s posture, new questionnaires not often require guide digging.

“Our common SLA [service-level agreement] time is 24 hours, however actually, our prospects are happening to same-day turnaround,” Hamal says.

The corporate says vendor prospects can flip round most safety questionnaires from potential consumers as much as 87 occasions quicker than they may with guide workflows.

Second, by letting its platform deal with third-party-risk opinions begin to end, consumers report as a lot as 125 occasions quicker vendor assessments.

Third, the aggregated assurance information the system collects turns into a reside dashboard that chief information-security and income officers can mine for board-level perception quite than spreadsheet trivia.

AI plus individuals, not AI as a substitute of individuals

Hamal is fast to emphasize that SecurityPal’s analysts stay central to the product.

“AI alone isn’t sufficient…you want skilled people layered on prime of the know-how,” he informed VentureBeat, describing the inner workflow as a “centaur” mannequin the place machine and human passes alternate all through the pipeline.

The human layer additionally feeds a network-effect moat. Every new engagement expands the corpus of accepted solutions, which the AI reuses (with contemporary proof) for different prospects.

SecurityPal claims protection of “a lot of the Fortune 1000” query units, giving it early information of rising considerations—for instance, the shift from cloud fundamentals to LLM-specific controls famous in current federal questionnaires.

Traction and enterprise mannequin

SecurityPal bootstrapped to roughly $1 million in annual recurring income earlier than David Sacks’ Craft Ventures pre-empted the corporate’s first funding spherical; the $21 million seed deal was signed on a literal serviette, with no slide deck concerned.

The client roster now contains OpenAI, Airtable, Figma, Snap, a top-three U.S. airline and a top-five U.S. well being insurer, amongst different Fortune-class accounts.

SecurityPal doesn’t disclose pricing publicly, but it surely sells the service as an annual subscription whose price undercuts the inner headcount many firms dedicate to the duty.

Internally, Hamal operates on two continents. Income, product and go-to-market groups sit in San Francisco and New York, whereas the analyst group varieties the kernel of what he calls “Silicon Peaks” — a tech hub 100 miles from Mount Everest that faucets Nepal’s deep pool of STEM graduates.

Why consumers care

For distributors, quicker questionnaire turnarounds shorten gross sales cycles and cut back the chance of stalled offers.

For consumers, automated opinions make it possible to judge each provider as a substitute of sampling a dangerous few.

The end result, Hamal argues, is alignment between income and safety groups which have traditionally been at odds: “There are only a few instruments which are the favourite software of the CRO and the CISO. We’re it.”

Aggressive panorama

Begin-ups reminiscent of Vanta, Drata and Secureframe additionally goal compliance ache factors, however they deal with proof assortment and audit preparation.

SecurityPal’s differentiator is doing the precise writing and response work—one thing Hamal believes will show more durable for pure-software rivals to automate as a result of it nonetheless requires judgment and area experience.

The Kathmandu middle of excellence offers SecurityPal a price base low sufficient to maintain people within the loop whereas staying price-competitive.

What’s subsequent?

SecurityPal’s near-term objective is to assist 5,000 international enterprises tame their most advanced assurance challenges inside 5 years.

Long term, Hamal sees the service as infrastructure for an economic system the place each important transaction carries a safety or privateness attestation.

“It’s referred to as SecurityPal, but it surely’s far more than simply about safety,” he stated, including “I look to Salesforce—it’s far more than simply gross sales. Identical for us. It’s all about satisfying necessities and accelerating offers.”

If that forecast is right, the corporate’s mixture of AI scale and human nuance may turn into an ordinary a part of enterprise procurement, whether or not or not anybody notices the “vibe coding” origin story alongside the way in which.


Share This Article