Comp AI Raises $34M to Turn Compliance Checks Into Continuous Security Work
The startup is betting that security work should continue after a compliance audit, while independent review and human approval remain in the loop.
Listen to this story
The audio brief
Story brief
3 key pointsComp AI’s $34M Series A, led by Roo Capital and Grand Ventures, funds a move from audit preparation into ongoing security monitoring, control validation, and AI-assisted penetration testing. The company is targeting the gap between point-in-time SOC 2 and ISO 27001 assessments and risks created by later system changes, including newly deployed agents. Its open-source core and reported 1,000-plus customers provide...
- 01
The September 17 financing brings Comp AI’s total funding to $36.6M, including a $2.6M pre-seed round in August 2025.
- 02
The roadmap expands beyond policy drafting and evidence collection into control monitoring, application testing, and infrastructure validation.
- 03
Comp AI’s AI penetration testing is positioned as supplemental; the company says it does not replace independent audits.
Comp AI has raised a $34 million Series A to fund a bet that a compliance audit should be the start of security work, not its endpoint. The startup says its agents can prepare policies and audit evidence, then keep monitoring controls as a company’s systems change. It also says independent audits and human approval remain part of the process.
Roo Capital and Grand Ventures led the financing, announced September 17. Comp AI said the round brings its total investor funding to $36.6 million, including a $2.6 million pre-seed round in August 2025. It plans to use the new capital for product, engineering, sales and customer-success hiring.
A fixed assessment versus changing systems
Comp AI’s premise is that a completed audit may not describe the risk that emerges after a company changes its systems. Chief executive Lewis Carhart gave the example of a company deploying an AI agent after its SOC 2 audit that can access customer data, change internal permissions or introduce a vulnerability through code deployment. He said the audit would not become invalid, but it was not designed to show those changes in real time.
The founders say the manual work of completing SOC 2 while scaling their previous startup, LeapAI, helped reveal the problem they are now targeting. Comp AI says its software reads customer systems and documents to build organizational context, then drafts policies and risk registers, gathers evidence, monitors controls and conducts vendor security assessments. Its open-source core supports SOC 2 and ISO 27001.
Automation stops short of the sign-off
The company also offers AI-powered penetration testing intended to probe codebases and infrastructure for vulnerabilities. That raises the practical stakes beyond document preparation, but Comp AI says it does not replace an independent audit. Its stated model keeps people involved in onboarding the AI, supporting controls and maintaining workflows; a person reviews and approves a policy drafted by an agent.
Early adoption, and an untested expansion
Comp AI says more than 1,000 companies use its platform, including Dub Technologies and OpenCode, and that its annual recurring revenue grew 15-fold over the past year. Those customer and revenue figures are company-reported. Whether its planned monitoring and testing tools deliver the continuous coverage it envisions remains unresolved.
Sources
- techcrunch.comComp AI sets eyes on a continuously agentic future for security and compliance | TechCrunch
- siliconangle.comCompliance automation startup Comp AI raises $34M to push into security - SiliconANGLE
Loading discussion...
Reader comments
Newest comments first. Replies stay oldest first.