How Whistic is building an AI-powered risk operations platform with Andela & Anthropic

SNAPSHOT
Customer: Whistic
Industry: Risk management / Cybersecurity
Use case: AI-powered software development and vendor risk assessment automation
Tools: Claude Sonnet 5.5, Claude Opus 5.5, Claude Fable 5.1, Claude Code, AWS Bedrock, Claude Projects
What was built: An AI-enabled operating model that uses Claude across Whistic’s product and engineering lifecycle, from summarizing security documentation and vendor assessments to software development, testing, and workflow automation.
Early impact:
- 10x engineering productivity per engineer, based on Whistic’s before and after assessment — shortening the cycle from one week to half a day.
- 100% adoption across engineering, with the full team using Claude-based workflows
- Faster product development, with coding moving from the longest part of the development lifecycle to the shortest
- Expanded product capabilities, helping Whistic evolve beyond assessments toward a broader risk operations platform
Problem: scaling vendor risk operations without scaling manual work
Whistic is an AI-first risk operations platform that helps companies assess vendors, monitor third-party risk, test controls, and manage customer security reviews. AI is already central to how Whistic builds its product, and the company is a sophisticated user of Claude across its product and engineering organization, using a range of Claude products and models across its workflows and quickly adopting new releases.
That process depends on large amounts of information: security questionnaires, SOC 2 reports, security profiles, customer requirements, supporting documentation, and the evidence behind individual assessment responses.
Reviewing and synthesizing that information takes time. Assessments require teams to understand detailed security documentation, determine whether specific controls are in place, and trace conclusions back to the source material. As Whistic looked to expand its platform, the challenge was how to handle more of that work without adding the same amount of manual effort.
Trust made that challenge more complicated. In vendor risk management, an answer is not useful simply because it is fast. Customers need confidence that assessment findings are accurate and can be verified against the underlying evidence.
At the same time, Whistic needed to continue increasing its product velocity with a lean engineering organization, getting significantly more leverage from every engineer while continuing to expand the product.
The opportunity was to rethink both sides of the equation: how risk assessment work gets done inside the platform and how quickly the engineering team can build the technology behind it.
Solution: building an AI-powered operating model with Claude
Whistic began evaluating generative AI in 2023, testing multiple models before selecting Anthropic. Because Whistic’s SaaS environment runs on AWS, accessing Claude through Amazon Bedrock gave the team a way to bring AI into its product while maintaining the controls its security-conscious customers expected.
The first use case was focused: using Claude to summarize vendor information and security documents such as SOC 2 reports. From there, Whistic expanded Claude into search and then into agentic workflows designed to automate more of the vendor assessment process, including sending questionnaires, reviewing responses, and supporting assessments.
“We are able to output a lot more functionality at a faster pace. We're seeing about a 10x per-engineer productivity improvement.”
— Karl Ford, Whistic
AI adoption expanded in parallel across Engineering. After an initial three-month evaluation led by Whistic’s architects, Claude was rolled out across the engineering organization. Today, Claude supports requirements gathering, technical design, development, testing, and internal knowledge sharing.
Andela engineers are embedded directly within that team. Several have worked with Whistic for years, developing deep product knowledge while continuously building new AI skills alongside Whistic’s full-time engineers.
The Whistic’s Claude Code development playbook
- Start with customer context: Claude Projects help Whistic synthesize customer feedback from customer success conversations, calls, and internal channels to identify recurring needs and inform product priorities.
- Bring AI into requirements and design: The team uses Claude to help organize requirements, reason through designs, and translate product priorities into development work before implementation begins.
- Accelerate implementation with Claude Code: Claude Code supports development once requirements and technical approaches are defined. Coding, once the longest portion of Whistic’s development lifecycle, has become one of the shortest.
- Extend AI into review and testing: AI-assisted code review and testing help the team move from implementation through validation faster while engineers remain responsible for the quality of what ships.
- Build trust through evidence and guardrails: For vendor assessments, Whistic designed workflows that surface the source behind AI-generated findings so users can verify where an answer came from. Guardrails remain part of the system even as model accuracy has improved.
- Make continuous learning part of the operating model: Whistic holds an AI knowledge-sharing session every two weeks, helping engineers exchange techniques and stay current as models and development practices evolve.
Impact: 10x productivity per engineer and a faster path from idea to product
The clearest impact for Whistic has been the compression of the software development lifecycle. Work that once consumed the largest share of development time can now happen much faster, allowing the team to spend more time refining requirements, making technical decisions, testing, and determining what should be built next.
The shift has allowed a smaller engineering organization to deliver more functionality at a faster pace than Whistic's previous team. Claude Projects are used across customer success, technical support, RevOps, sales, and marketing, creating shared access to product and customer context throughout the organization.
The results:
- 10x engineering productivity per engineer, based on Whistic’s before and after assessment — shortening the cycle from one week to half a day.
- 100% adoption across engineering, with the full team using Claude-based workflows
- Faster product development, with coding moving from the longest part of the development lifecycle to the shortest
- Expanded product capabilities, helping Whistic evolve beyond assessments toward a broader risk operations platform
For Whistic, the next phase is increasingly agentic: using Claude not only to help people perform individual tasks, but to automate larger portions of workflows while maintaining the evidence, guardrails, and human oversight required in security and risk management.
“You’ve got to go all in, stay current, train your organization, and create a culture around it. It can’t live in silos. The whole company has to be bought in.”
— Karl Ford, Whistic
Whistic’s experience also demonstrates the value of an engineering team that can evolve alongside the technology. Andela engineers embedded with Whistic have remained part of the organization for years, building deep product knowledge while adopting the same AI-first practices as Whistic’s internal team.
“Whistic shows what happens when AI adoption becomes part of the operating model, not just another engineering tool. By providing Claude to experienced engineers who understand the product and continually build new skills, the team has been able to dramatically compress development cycles while expanding what a lean engineering organization can deliver. That foundation is now helping Whistic extend AI beyond development and into the risk workflows at the core of its platform.”
— Kennith Jackson, SVP, AI Solutions, Andela



.png)