Bengaluru, India
Try it live
Work
/Case study: Compliance Autopilot
CybersecuritySaaSAI ProductsDesktop ApplicationsContent DesignB2B

Ofofo Compliance Autopilot: The AI That Never Leaves the Building

Mohammed Zabeeh·July 23, 2026·15 min read
Ofofo Compliance Autopilot: The AI That Never Leaves the Building

A compliance product across 3 lives: a manual SaaS built on the insight that companies were not buying security so much as buying their way to compliance, a cloud trial that proved AI could do the drafting, and the on-premises desktop application it became once the research showed why the evidence could never leave the building.

30 days to 30 mins
Questionnaire turnaround
97%, 100% reviewed
Answer accuracy
32,160
Hours saved for clients
$271K
ARR in 4 months
Client
Ofofo
Role
Product Designer
Timeline
2024 to 2026
Type
Enterprise

How this was worked out

The method behind the numbers above, including the parts that were never measured.
Baseline
Auquan's annual security questionnaire: 30+ days circulating between departments and their previous vendor. Reported by Auquan's team and the platform vCISO.
Hypothesis
AI drafts answers from a client's own evidence, teams edit rather than rewrite, turnaround falls from weeks to under an hour. Threshold: none set in advance.
Variables
Changed: AI drafting from the client's own evidence, then where that evidence lives: cloud upload, own sub-processors, own machines · Measured: Turnaround, accuracy, vCISO hours, whether clients would supply evidence at all
Control group
None. Auquan before and after, against its own previous year.
A/B test
None. 3 versions shipped in sequence, not a split.
Prototype comparison
Chat only with in-chat forms against tables plus a knowledge graph with chat assisting. 14 participants (administrators, managers, security teams, small-company owners), all saw both, counterbalanced, 60% ship rule set beforehand. The second won at 71%.
What changed
Stopped asking clients to send evidence anywhere. Sent the product to it: cloud linking through their own sub-processors, app on their machines.
How measured
Trial: 8 clients, real questionnaires, moderated video sessions with screen share, notes and recordings. Accuracy scored by the reviewing CISO, not the system. LattIQ hours from the platform database. NPS 83 from 27 respondents over 6 months.
Result
30+ days to about 30 minutes. Accuracy 86% in the cloud trial, 97% on premise at Auquan across 178 questions, 100% after review. LattIQ reached ISO 27001:2022 on 4 vCISO hours.
What didn't survive
5 of 8 trial clients liked the output and would not upload evidence: 3 blocked by regulation, 1 by internal policy, 1 with no rule. Refusal, not accuracy, redirected the product. A bundled local model was dropped after auditors named lag their first complaint, and controls-first reports were rejected for findings-first.
Limits, and next
Platform-wide figures are Ofofo's instrumentation, not mine, and 32,160 hours saved covers every product since 2022, not this one. No threshold agreed beforehand. Next: whether stating provenance before content reduces reviewer edits per answer.

Principles leaned on

  • A permanent banner: data stays on this machine, never scrolling awayVisibility of system status
  • 4 named modes, Scan, Ask, Fix, Questionnaire, not inferred intentAvoiding mode errors
  • Every reply names where it looked before what it foundSource credibility, and primacy

The Problem

Before a company can sell software to a bank, it must survive the bank's security review: a spreadsheet of several hundred rows asking how data is encrypted, who can reach production, how access is reviewed. Someone answers every row, then the next customer sends a different spreadsheet asking the same things in different words. The cost is not subtle. Sales teams lose around a fifth of their time to security activity, around 40 per cent of theirs to assessing vendors, and deals slip 6 to 8 weeks with lower win rates. As one CISO put it in research, "The security review process is broken."
This product tried to fix it 3 times over 2 years, and the first version used no AI at all, though the obvious answer in 2025 was to point a at it.

Act One: From Marketplace to Compliance

Ofofo began as a cybersecurity marketplace, and watching buyers surfaced a deeper question: nobody wanted security for its own sake, they wanted to be , because compliance stood between them and their deals. The marketplace was serving the symptom, so compliance work moved into a product of its own, deliberately manual through 2024 while the shape of the problem got settled. The foundation was one observation: most of a questionnaire has already been answered somewhere, in a policy, last quarter's questionnaire, a certificate in a folder. The problem is not writing answers but finding the ones you already have, so the first thing built was an evidence library.
Answering a questionnaire meant matching its columns to that library and filling what it could. Late in this version an opt-in "Answer with AI" drafted the answers the library could not supply, one button in an otherwise manual flow that worked well enough to reframe the whole product.
The other half asked whether a company was actually . , built on the , moved along a ladder, Unvalidated, then Deficient, then Completed, reaching the top only once evidence was attached and verified. That principle, no status without the evidence underneath it, started here, two years before an AI drafted anything. It went to pilots, not a launch, and the library, the reuse and the ladder survived unchanged.

Act Two: The Cloud Trial, and Where Clients Stopped

The second version asked what happened if AI carried the whole flow. An invite-only web app went to a small set of clients on real work: hand-approved signups, metered usage, a trial not a launch. Upload your evidence, then hand over a questionnaire to answer against it, or map it against a framework so each control in or came back implemented, partial or not implemented, with a confidence score. The automation worked. Clients got answers in minutes that had taken weeks, good enough to edit rather than rewrite. The blocker was elsewhere: to answer well the system needs a company's policies, audit history and architecture notes, the exact bundle a security team exists to keep from leaving the building. The research was awkward: clients liked the output and would not feed it the input. Some were blocked by regulation, data-residency rules and the shaping where data could sit, requirements on top. Some by their own policy against cloud compliance tools. A few had no rule and still said no. Demand was proven and trust was not. The objection was never to the automation, it was to the address.

Act Three: On Premise

So the product went to the evidence. The third version is : a desktop application on the client's own machine that keeps the documents, the , the answers and the model itself local.
In the 8-client trial, the most common question at the start of every conversation was a version of "where does this go", and the onboarding modal was not enough: the anxiety returns with every upload. So the guarantee sits permanently in the frame, the most important interface in the product, and never scrolls away. The setup beneath follows the order the worry occurs in: connect what to scan, choose which model thinks, the evidence. The model step gets specific, a model on the client's own hardware or a cloud one on their , nothing hidden and nothing chosen for them.

Designing for Chat

The layout splits the window, the agent on the left and whatever you are checking on the right, so conversation and evidence stay on screen together. Naming the agent's 4 modes did more than any visual treatment could: Scan reads connected clouds, Ask answers questions, Fix proposes the commands that close a gap, Questionnaire answers a vendor spreadsheet. The fashionable pattern is to hide modes and infer intent, which is wrong for users whose job is professional suspicion. They want to know which machine they just started.
The hardest part was not visual. When the interface is a conversation, the thing to design is language: how to ask for a file without sounding like a form, how to say an answer came from the client's own evidence rather than the model's general knowledge. Every reply declares its provenance before its content, naming where it looked, the client's own and their latest scan, before what it found. The reverse order tested badly: sourcing tacked on at the end reads as the model's opinion, and nobody sends a model's opinion to a bank. The output is the least glamorous and most important detail, a completed spreadsheet in the shape it arrived, saved locally, because what the customer wants is the file, filled in.

Trust and the Human Loop

Automation was never enough, because whoever signs a questionnaire is personally accountable for it. A 97 per cent accurate answer sounds excellent until you are the one signing, at which point the interesting number is the other three per cent.
So review is first-class, not a courtesy. Anything consequential lands in a queue tagged for , sorted by severity, with the agent pausing rather than proceeding. Ofofo runs a network of , and the goal was that the vCISO uses the AI too, arriving at a prepared queue with reasoning and evidence attached instead of auditing the machine's homework. That is what turns 97 per cent into 100.

Proving Compliance

The questionnaire is the sharp end, but the same evidence answers whether a company is at all. Controls are browsable across a catalogue of over 1,400, each drilling into the cloud resources that failed it, and the principle from Act One holds at scale: every number opens into the controls that produced it, and every control into the evidence that decided it.
That checkability rests on a built as documents are indexed, linking a document to its passages, those passages to the they describe, and those to the controls they satisfy. It ships in two views, a flat 2D one for tracing which document holds up a control and a 3D one for shape, where a sparse region is a useful signal, because in compliance the gap is usually the finding.

Outcomes, and Where Each One Comes From

Every headline number here traces to something measured:
  • 30 days to about 30 minutes, 97% accuracy and 100% after review. Auquan, one of two named clients, 178 questions in one run against their previous turnaround, on one hour of CISO time. Accuracy was scored by their reviewing CISO, not by the system reporting on itself.
  • 4 hours of CISO time. LattIQ, reaching ISO 27001:2022 certification in under a week with 34 policies drafted. This is the number that tests the human-in-the-loop design: if the review burden had not fallen, the design would have failed regardless of accuracy.
  • 32,160 hours saved, 67 vCISOs, 83 (27 respondents, 6 months), $271K in 4 months. Platform-wide figures from Ofofo's product and revenue tracking, not my instrumentation.
  • The move on premises. Not a metric but the largest design decision here, from the Act Two trial. Refusal reasons were categorised rather than counted as one, which is what showed the objection was to the address and not to the automation.

Milestones

2024
From marketplace to compliance
Compliance work moved off the buyer dashboard into a manual standalone SaaS: an evidence library, questionnaire reuse, and Resilience Models on the Secure Controls Framework.
Early 2025
The control ladder and one AI step
A per-control Unvalidated to Deficient to Completed ladder reached the top only on verified evidence, and one opt-in Answer with AI step drafted what the library could not supply.
Late 2025
The cloud trial
An invite only web application put full automation in front of real clients, proving it saved weeks and showing they stopped at the upload.
Early 2026
The on premise decision
The product moved to the client's machines: a desktop application with local storage, local document processing and an optional local model, cloud models only on their own key.
Mid 2026
4 modes and the review queue
The agent settled into Scan, Ask, Fix and Questionnaire, and consequential actions went to a review queue where a vCISO signs off, taking accuracy from 97 per cent to 100.
Mid 2026
Cutting the last cloud ties
The last dependencies on the hosted platform went, including file sync and billing, so what began as a cloud product with a desktop client ended as a desktop product, the opposite of the direction software usually travels.

Lessons

  1. Where the data lives can be the design decision The objection was architectural, so no interface work would have solved it, and the permanent banner is not a feature but the whole argument.
  2. When the interface is a conversation, the design work is language Getting the order wrong, sourcing after content instead of before, cost more trust than any layout choice could.
  3. Design the reviewer in, not as a gate Treating the vCISO as a user rather than an obstacle made the trust story work: same accountability, a fraction of the hours.
  4. A number you cannot interrogate is worse than no number In a category built on being believed, an unexplained figure invites exactly the doubt you were trying to remove.

FAQ

Because the cloud version is what produced the finding. Clients using it on real questionnaires proved the automation saved weeks and showed exactly where they stopped, which was at the upload. Without the trial we would have been guessing about both.

The application installs on the client's own machine and everything material stays there: documents parsed locally, the search index local, answers written to a local dataroom, and the reasoning model able to run on their own hardware. If they prefer a cloud model they supply their own key, so the relationship is theirs, not ours.

The conventions I did not know I was relying on. No back button, no reload, no shareable link, a window frame with its own rules, and a layout that holds two things at once because there is no page to navigate away to. Beyond that the interface was largely a chat, so most of the design work turned into content design.

Design Skills

Product StrategyUX ResearchContent DesignInformation ArchitectureInteraction DesignDesign Systems

Tech Stack & Tools

FigmaFigJamDesign Systems

Got a problem shaped like this one?

I am open to senior and lead product design roles, and to the odd piece of client work. Fastest way to a real conversation is to pick a time.