Shrav Mehta of Secureframe on Building AI in Production

Shrav Mehta, founder and CEO of Secureframe, on using AI to cut the manual work of security and compliance — from long-running agents and continuous penetration testing to keeping sensitive systems protected with clear permission boundaries.

Sep 11, 2026

Shrav Mehta of Secureframe on Building AI in Production

Shrav Mehta of Secureframe on Building AI in Production

Helping companies use AI to reduce manual security and compliance work while protecting sensitive data and controlling what these systems can access.

In this AI Frontier Network Q&A, we spoke with Shrav Mehta, founder and CEO of Secureframe, about where AI is genuinely reducing the manual work of security and compliance — and how his team keeps sensitive systems and data protected as autonomous agents take on more of that work.

Please introduce yourself and tell us what you are currently building, deploying, or responsible for.

I'm Shrav Mehta, founder and CEO of Secureframe. I started the company in 2020 after seeing security teams spend weeks gathering evidence for audits, answering repetitive customer security questionnaires, and manually tracking whether employees, devices, and systems met required controls. We built Secureframe to automate that work as much as possible, and AI has continually become a bigger part of how we do that.

Right now, I'm spending a lot of time figuring out where AI can actually make a difference, both in our products and inside Secureframe. We're using it across areas like security questionnaires, evidence review, risk, and remediation, and recently launched a hosted MCP Server that lets customers connect AI assistants like Claude and Cursor to their Secureframe environment. I'm also using these tools pretty heavily myself across security, sales, marketing, and internal operations because you learn much more by putting them against real problems.

What kind of AI systems, workflows, or use cases are you closest to right now?

I'm most interested in AI that can keep working toward a goal instead of answering one question and stopping. We've been experimenting with that internally across security, paid acquisition, SEO, and other parts of the business. You can give the system the relevant data, tell it what you are trying to accomplish, and let it keep investigating. The human role increasingly becomes making sure you give the LLM the right goal and stepping in when the workflow breaks down or permission boundaries need to change.

Security is one area where this gets really interesting. Speakers at the Secureframe National Cybersecurity Summit made this point well. One example that stuck with me was AI analysis turning up more than a dozen new vulnerabilities in a codebase that had already been through decades of professional review and bug bounties. It's not that human reviewers were bad at their jobs. The search space was just too large to brute-force before. That's made me think a lot about continuous AI code review, since software never really stops changing.

What real problem are you solving, for whom, and under what constraints?

The broader problem we're solving is that security and privacy compliance work still requires too much manual effort. Companies have to collect evidence, maintain documentation, monitor their environments, answer customer questions, prepare for audits, and keep doing that work as their business changes. For smaller teams especially, that can mean hiring more people or relying on multiple outside providers just to keep up.

Defense contractors are a good example of where this problem becomes particularly difficult. They don't just need to prove compliance with CMMC (Cybersecurity Maturity Model Certification) requirements. They need to operate a compliant environment every day, from managing government cloud environments and protecting Controlled Unclassified Information (CUI) to maintaining configurations and collecting evidence. Most compliance software can tell you what's out of place, but it doesn't actually do the work of fixing it. With Secureframe Defense, we're starting to productize that operational layer itself. Defense Navigator guides contractors through CMMC implementation, and we auto-generate documentation and continuously monitor the environment so the work keeps happening in the background instead of piling up before an audit.

The constraint is that this involves sensitive systems and data, so AI needs clear boundaries around what it can access and do. Secureframe's AI capabilities are designed around permission controls and limited data access, and workflows to keep people involved in reviewing what the system produces. The goal is to take more repetitive operational work off people's plates without giving AI unrestricted control over sensitive environments.

Where have you seen measurable operational impact from AI so far, and where has the reality fallen short of expectations?

We're seeing some of the clearest impact when AI is applied to work that traditionally takes teams weeks or months. With Secureframe Defense, AI helps generate documentation like System Security Plans and policies from a company's actual environment, alongside automation for infrastructure setup, evidence collection, and continuous monitoring. One defense contractor reported saving at least 500 hours preparing for NIST 800-171 and CMMC.

We've seen the impact in our own operations too. We used AI to analyze our paid acquisition data and identify opportunities to improve how we measured and optimized campaigns. Through that broader effort, we cut acquisition costs by about 50% and increased lead output about three times. What we've learned is that AI works best when the goal is clear and it has the right data to work with. You still need to define what success looks like and give it sensible boundaries.

What have you learned about making AI work inside real organizations, products, or operating environments?

The biggest thing is that you have to use it. I meet executives who have already decided what AI can or cannot do, sometimes based on tools they used a year ago. The technology is moving too quickly for that. What I'd insist on is testing the latest models on real problems in your business and seeing where they can genuinely help.

I've found the most interesting applications are the ones taking on tasks that are tedious, dangerous, or just not realistic for a person to do well. That's more about cutting down the volume of manual work, than removing people. If an AI system can scan a huge codebase in seconds and flag potential vulnerabilities, that's work no human could do at that speed regardless of headcount. The same goes for things like manually testing production systems for weaknesses, which carries real risk if it's done carelessly. Either way, it gives a security team another way to find issues and spend more time on the analysis and decisions that follow.

The same applies to ongoing IT and security management. There is a lot of recurring work involved in monitoring environments, maintaining configurations, and keeping things up to date. Agents can help with some of that work within defined boundaries, which can make these environments easier and less expensive to manage. People set the goals, bring the context and judgment, decide what the system should have access to, and establish the guardrails that let it operate effectively.

What is one prediction you have about how production AI will evolve in practice over the next 12 to 24 months?

We're moving away from stateless agents, ones that answer a question and reset, toward long-running agents that can work on a goal for consecutive hours or even days. They check their own progress, adjust as they go, and keep going until they either accomplish it or need someone to step in.

Security is a good example. Several of the former government officials who spoke at our National Cybersecurity Summit made this point well. A once-a-year pen test only tells you what was wrong on the day it ran, and we've already seen autonomous testing agents outperform human researchers on live bug bounty programs, finding more valid vulnerabilities than any person on the platform. AI will make penetration testing continuous instead, with an agent examining code and infrastructure on an ongoing basis, investigating vulnerabilities and simulating attack paths as the environment actually changes. That gives security teams a much more current picture of their exposure and creates the ability to examine far more code paths and attack scenarios at scale.

This inevitably raises the bar for software companies. As AI gets better at building, operating, and maintaining software, customers will increasingly evaluate products based on how deeply AI improves the work the product supports. For SaaS companies, that could mean faster workflows, more intelligent recommendations, continuous monitoring, and software that can take on increasingly complex tasks. If you're a SaaS vendor and you're not making that case yet, that's the gap to close, because it's quickly becoming the baseline customers expect.

People featured

Copyright © 2026 AI Frontier Network | Privacy Policy | Terms of Use