Launching ResponseHub
Six months of building an AI-powered security questionnaire platform, and it's finally live.
After six months of building, I’m excited to share that ResponseHub is live.
ResponseHub is an AI-powered platform that helps companies complete security questionnaires in hours instead of days. If you’ve ever worked in B2B SaaS, you know the pain: a prospective customer sends over a spreadsheet with hundreds of questions about your security practices, data handling, and compliance certifications. Someone senior - usually the CTO or VP of Engineering - has to drop everything and spend days filling it out. It’s repetitive, high-stakes, and it directly blocks revenue.
That’s the problem ResponseHub solves.
How it works
You upload your security policies, SOC 2 reports, and other documentation. ResponseHub processes them and builds a knowledge base grounded in your own words. When a questionnaire comes in, you upload the Excel file and the AI generates answers by searching across your documents using a RAG pipeline - retrieval augmented generation built on Postgres with pgvector and powered by Claude.
The key differentiator is citations. Every generated answer references the exact source document, page number, section, and sentence it was drawn from. You’re not trusting a black box - you can verify every answer against your own policies.
What’s in the box
The core workflow is straightforward: upload documents, upload a questionnaire, review the AI-generated answers, and export the completed file. But there’s a lot of depth under the surface.
Smart questionnaire parsing - Security questionnaires arrive in every format imaginable. Multiple tabs, cover sheets, merged cells, ambiguous column headers. The parser handles all of it and extracts the actual questions regardless of how the spreadsheet is structured.
Confidence scoring - Each answer gets a confidence rating so you know where to focus your review time. High confidence answers grounded in multiple sources can often be approved quickly. Low confidence answers get flagged for manual attention.
Self-improving knowledge base - Every completed questionnaire feeds back into the knowledge base. The system learns your preferred answers over time, so accuracy improves with use.
Browser extension - Not every questionnaire arrives as a spreadsheet. Many come through portals like OneTrust or Archer. The Chrome extension sits alongside these portals, extracts the questions directly from the page, generates answers, and auto-fills them back into the form fields.
The build
The app is a Ruby on Rails application running on Postgres with the pgvector extension for semantic search. Document processing uses AWS Textract for OCR and text extraction. Answer generation runs through AWS Bedrock with Claude. The whole thing is deployed with Kamal.
Building the RAG pipeline in Rails was a deliberate choice. Postgres with pgvector gives you vector search without adding another database to your stack, and the Ruby ecosystem has solid gems for the supporting pieces - neighbor for vector operations, pragmatic_segmenter for document chunking, pg_search for keyword retrieval alongside semantic search.
The browser extension was the hardest part to get right. Every security portal has a different DOM structure, and many use heavy JavaScript frameworks that make form interaction non-trivial. Getting reliable auto-fill across OneTrust and Archer took more iteration than I expected.
What’s next
ResponseHub is available now at responsehub.ai with a free trial. The pricing is credit-based - you pay per AI-generated answer rather than per seat, which means your whole team can use it without the cost scaling with headcount.
I’m particularly interested in how managed security service providers use it. There’s a dedicated MSSP tier where providers can manage multiple clients from a single account, each with isolated workspaces and their own knowledge bases.