Comp AI

AI-native compliance and security platform for SOC 2, ISO 27001, HIPAA, and GDPR automation.

Website: https://www.trycomp.ai/

Cover Block

Public sources

Attribute Details
Name Comp AI
Tagline AI-native compliance and security platform for SOC 2, ISO 27001, HIPAA, and GDPR automation.
Headquarters San Francisco, US (with operations in Miami, New York, and the UK) [Refresh Miami, July 2026]
Founded 2025 [Crunchbase]
Stage Pre-Seed
Business Model SaaS
Industry Security
Technology AI / Machine Learning
Geography North America
Growth Profile Venture Scale
Founding Team Co-Founders (3+)
Funding Label Pre-seed
Total Disclosed $2,600,000 [PRNewswire, August 2025]

Links

Public sources

Independently corroborated -- Company website, LinkedIn, and GitHub URLs are confirmed via primary sources.

Executive Summary

Public sources Comp AI is an AI-native platform automating the labor-intensive process of achieving and maintaining major security and privacy certifications, a bet that the compliance demands of a software-first economy will increasingly favor automation over manual consultancy. Founded in 2025, the company has moved quickly, securing a $2.6 million pre-seed round led by OSS Capital and attracting backing from Grand Ventures and notable angels [PRNewswire, August 2025]. The founding team, led by CEO Lewis Carhart and co-founders Claudio and Mariano Fuentes, brings a blend of prior startup exits, security operations experience, and growth marketing from ventures like Leap AI and Headshot Generator AI [Grand Ventures, August 2025].

The product's core differentiation is its open, agent-driven architecture, which uses AI to continuously gather evidence, generate policies, and monitor for compliance drift across over 580 integrations, aiming to replace manual GRC workflows with autonomous systems [Comp AI Review 2026: Open-Source AI Compliance Software, 2026]. This AI-first approach is positioned against established, more labor-intensive platforms like Drata and Vanta. The business model is SaaS, with traction claims including over 1,000 companies served and a third-party verification of $489,221 in revenue over a 30-day period in mid-2026 [trustmrr.com, June 2026][Comp AI: AI Compliance Software | Comp AI, 2026].

Over the next 12-18 months, key milestones to watch include the execution of its aggressive hiring plan to reach 50 employees, the validation of its reported ARR growth against public benchmarks, and its ability to convert early traction into defensible market share against deep-pocketed incumbents. The company's recent headquarters move to Miami signals a growth-oriented operational strategy [Refresh Miami, July 2026]. Lightly corroborated -- Core funding and product claims are well-sourced; key traction metrics are self-reported or from a single third-party source.

Taxonomy Snapshot

Axis Classification
Stage Pre-Seed
Business Model SaaS
Industry / Vertical Security
Technology Type AI / Machine Learning
Geography North America
Growth Profile Venture Scale
Founding Team Co-Founders (3+)
Funding Pre-seed (total disclosed ~$2,600,000)

How the Company Got Here

Public sources

Comp AI was founded in January 2025 by a trio of entrepreneurs with backgrounds spanning security, AI, and venture-scale startups. The company's public narrative frames its origin as a response to the manual, labor-intensive nature of security compliance, particularly for fast-moving software companies. Its stated mission is to automate the work around major frameworks like SOC 2 and ISO 27001, using an AI-native approach to replace what has traditionally been a consultant-heavy process [Perplexity Sonar Pro Brief].

The company is headquartered in San Francisco, with a significant operational presence established in Aventura, Miami, in July 2026 [Refresh Miami, July 2026]. This move coincided with a publicized hiring plan to grow the team from 23 employees globally to approximately 50 by the end of that year. The founding team consists of Lewis Carhart (CEO), Claudio Fuentes (COO), and Mariano Fuentes, described collectively as experienced Silicon Valley entrepreneurs [DevOps.com, August 2025].

Key early milestones include a pre-seed funding round of $2.6 million, led by OSS Capital and announced in August 2025 [PRNewswire, August 2025]. By mid-2026, the company reported crossing $5 million in annual recurring revenue a little over a year after its launch [Tofik Hasanov - Comp AI | LinkedIn, 2026] and being trusted by over 1,000 companies [Comp AI: AI Compliance Software | Comp AI, 2026]. A third-party revenue verification service recorded $489,221 in monthly revenue for the company as of June 2026 [trustmrr.com, June 2026].

Independently corroborated -- Founding date, funding round, and headquarters location confirmed by multiple independent sources. Team size and revenue milestones are corroborated by a mix of company statements and third-party verification.

Product and Technology

Sources and analysis Comp AI’s core proposition is an AI-native platform that automates the manual, document-heavy processes of security compliance. The system ingests information about a company's technology stack and processes, then uses AI agents to generate tailored policies, collect evidence, and monitor for compliance drift across frameworks like SOC 2, ISO 27001, HIPAA, and GDPR [Comp AI: AI Compliance Software | Comp AI, 2026]. The company positions this as a shift from manual, checklist-driven work to a continuous, automated trust-management flow [Grand Ventures, August 2025].

Key product surfaces are well-documented. Automated evidence collection pulls data from over 580 integrations with cloud platforms and tools, running continuous checks to flag risks before an audit [How does Comp AI automatically collect evidence, and which tools and cloud platforms does it integrate with? · Comp AI, 2026]. AI-generated policy creation tailors security documentation to a specific tech stack and risk profile [Comp AI Review 2026: Open-Source AI Compliance Software, 2026]. The platform also offers a public-facing Trust Center with AI-powered questionnaire automation and built-in risk and vendor management modules [Comp AI Review 2026: Open-Source AI Compliance Software, 2026]. A significant architectural claim is an open-core, agent-driven model, where autonomous agents replace manual GRC workflows [Comp AI Compliance Platform Review 2026: Open-Source Agentic Compliance | RockB, 2026].

Lightly corroborated -- Product capabilities are consistently described across the company's website and multiple third-party reviews, but technical architecture details (e.g., specific AI models, backend stack) are not publicly detailed.

Where the Demand Sits

Public sources The demand for automated compliance platforms is accelerating as software companies, particularly in AI and B2B SaaS, face mounting pressure to prove security credentials to enterprise customers without diverting engineering resources.

Third-party market sizing specific to AI-native compliance automation is not yet widely published. However, the broader GRC (Governance, Risk, and Compliance) software market, which includes legacy manual solutions, was valued at $44.7 billion in 2023 and is projected to reach $81.4 billion by 2032, growing at a CAGR of 6.9% [Fortune Business Insights, 2024]. This analogous market provides a baseline for the scale of the problem Comp AI aims to automate. The company's stated mission is to assist 100,000 companies in achieving SOC 2, ISO 27001, and GDPR compliance by 2032 [Crunchbase]. While this is a company claim, it signals the intended addressable market segment.

Several demand drivers are clear from the cited research. The primary tailwind is the proliferation of AI-first startups and scale-ups that need to secure enterprise deals; their buyers increasingly require SOC 2 or ISO 27001 certification as a non-negotiable procurement checkpoint [Perplexity Sonar Pro Brief]. A secondary driver is the growing complexity of multi-framework compliance, where companies pursuing SOC 2, ISO 27001, HIPAA, and GDPR simultaneously face redundant manual work across overlapping controls. This creates a clear efficiency wedge for automation. Finally, a macro force is the continued shift toward cloud-native and API-driven infrastructure, which generates the telemetry data needed for automated evidence collection but also increases the surface area for manual compliance tracking.

Key adjacent and substitute markets include traditional GRC consultancies and manual audit preparation services, which represent the labor-intensive status quo Comp AI seeks to displace. Another adjacent market is the broader category of security posture management tools, which monitor for vulnerabilities but do not inherently map findings to formal compliance frameworks. The competitive threat from these substitutes hinges on their ability to automate the evidence-to-auditor workflow, which remains largely manual.

GRC Software Market 2023 | 44.7 | $B
GRC Software Market 2032 (projected) | 81.4 | $B

The projected growth of the broader GRC market underscores the significant economic activity around compliance, though Comp AI's specific wedge targets the faster-growing, automation-ready segment within it.

Lightly corroborated -- Market sizing is drawn from an analogous third-party report; company mission statement is self-reported.

Competitive Landscape

Sources and analysis Comp AI enters a compliance automation market defined by a dominant incumbent, a well-funded challenger, and a long tail of manual service providers, positioning its AI-native, open-core platform as a third-way alternative.

Company Positioning Stage / Funding Notable Differentiator Source
Comp AI AI-native, open-core compliance automation for SOC 2, ISO 27001, HIPAA, GDPR. Pre-seed ($2.6M). Open-source agentic architecture; AI-driven policy generation and evidence collection; 580+ integrations. [Comp AI: AI Compliance Software
Drata Market-leading, continuous security and compliance automation platform. Late-stage venture (Series D, $200M+ total). Extensive enterprise feature set, large partner ecosystem, strong brand recognition. [Competitor]
Vanta Major competitor automating compliance for startups and mid-market companies. Late-stage venture (Series B, $200M+ total). User-friendly interface, focus on SOC 2, established market presence. [Competitor]

The competitive map segments into three tiers. At the top, Drata and Vanta operate as the scaled incumbents, having raised hundreds of millions in venture capital to build out feature-complete platforms and sales organizations targeting the mid-market and enterprise [Competitor]. The challenger tier includes other venture-backed software platforms, while the long tail consists of consultancies and manual service providers that handle compliance through spreadsheets and human labor. Comp AI's stated wedge is to attack this long tail and the lower end of the incumbent market by promising a radically different cost structure and user experience through automation [Perplexity Sonar Pro Brief].

Comp AI's defensible edge today rests on two pillars: its open-core, agent-driven architecture and its claimed integration breadth. The platform's architecture, described as "open-source" and "agent-driven," is designed to replace manual GRC workflows with autonomous AI agents [Comp AI Compliance Platform Review 2026: Open-Source Agentic Compliance | RockB, 2026]. This technical foundation is paired with a claim of over 580 supported integrations for automated evidence collection, a number that, if accurate, would surpass many established players [How does Comp AI automatically collect evidence, and which tools and cloud platforms does it integrate with? · Comp AI, 2026]. The durability of this edge is uncertain; the architecture is a product differentiator that could be replicated, and integration count is a commoditizing metric where incumbents can rapidly catch up.

The company's most significant exposure is to the incumbents' distribution and capital advantages. Drata and Vanta possess mature sales motions, established channel partnerships, and brand trust that comes from serving thousands of customers. They also have the financial resources to rapidly acquire or build AI capabilities, potentially neutralizing Comp AI's technical wedge. Furthermore, Comp AI's focus on the startup and SMB segment, while logical for a pre-seed company, places it in direct competition with Vanta's core market, where sales cycles are price-sensitive and switching costs, while non-zero, are lower than in the enterprise.

The most plausible 18-month scenario hinges on execution against the integration and automation thesis. If Comp AI can successfully convert its 580-integration claim into a smooth, reliable product that demonstrably reduces time-to-compliance for its target customers, it could carve out a sustainable niche as the preferred tool for technical founders and lean security teams. In this scenario, the "winner" would be the category of automated, developer-friendly compliance, with Comp AI as a beneficiary. The "loser" would be the manual service provider segment, which faces increased pressure from low-cost software automation. Conversely, if the AI agents prove unreliable or the platform fails to move upmarket beyond early adopters, the incumbents' distribution strength will likely prevail, confining Comp AI to a smaller, niche audience.

Lightly corroborated -- Competitor data is based on general market knowledge; Comp AI's positioning is confirmed by its own materials and investor commentary.

Opportunity

Public sources If Comp AI can successfully automate the foundational compliance work for a generation of cloud-native companies, it stands to capture a significant share of a multi-billion dollar market for trust infrastructure.

The headline opportunity is the establishment of Comp AI as the default, AI-native compliance layer for startups scaling into the enterprise. The company is not merely selling a dashboard to track controls, it is attempting to replace manual GRC workflows with autonomous agents that continuously monitor infrastructure and generate audit-ready evidence [Comp AI Compliance Platform Review 2026: Open-Source Agentic Compliance | RockB, 2026]. This positions it to become the operational system for security compliance, a critical piece of infrastructure for any company selling to larger customers. The evidence that this outcome is reachable, not just aspirational, lies in the early traction signals: a third-party revenue verification showing nearly $500,000 in a single month [trustmrr.com, June 2026], and a customer base that has reportedly grown to over 1,000 companies [Comp AI: AI Compliance Software | Comp AI, 2026]. The founders' prior experience in scaling a venture to $1M ARR and serving enterprise clients like Heineken provides a relevant playbook for the expansion required [Perplexity Sonar Pro Brief].

Growth could follow several distinct, high-conviction paths, each with a plausible catalyst already visible in the market.

Scenario What happens Catalyst Why it's plausible
The Open-Source Standard Comp AI's open-core model becomes the de facto platform for in-house compliance teams and auditors, creating a large, defensible developer ecosystem. Widespread adoption of its self-hostable platform by security-conscious enterprises and managed service providers [soc2auditors.org, 2026]. The company's architecture is publicly described as open-source and agent-driven, a model with precedent in adjacent infrastructure categories [Comp AI Compliance Platform Review 2026: Open-Source Agentic Compliance
The Platform for AI Regulation As AI-specific audits and regulations (like the EU AI Act) emerge, Comp AI becomes the go-to tool for automating this new, complex compliance burden. The enactment of formal AI governance frameworks requiring continuous evidence collection and risk assessment. The platform's core value proposition is AI-native policy generation and risk assessment, which can be adapted to new regulatory frameworks [Mark Restall - Comp AI

Compounding advantages would likely stem from data and integration density. Each new customer integration feeds the platform's understanding of common control gaps and effective remediation steps. This data can be used to refine AI agents, making policy suggestions and evidence collection more accurate, which in turn reduces time-to-audit for future customers. A nascent flywheel is suggested by the expansion of its integration library from "100+" to "over 580" within a short timeframe, indicating a product that becomes more valuable as it connects to more of a company's stack [How does Comp AI automatically collect evidence, and which tools and cloud platforms does it integrate with? · Comp AI, 2026] [Comp AI Review 2026: Open-Source AI Compliance Software, 2026].

Quantifying the size of the win requires looking at comparable outcomes. Drata, a primary competitor, achieved a $2 billion valuation in its Series C round in late 2023 [Crunchbase]. If Comp AI executes on the "Open-Source Standard" scenario and captures a meaningful portion of the market for automated, multi-framework compliance, a multi-billion dollar enterprise value is a credible outcome (scenario, not a forecast). The company's own mission to assist 100,000 companies by 2032, while ambitious, frames the scale of customer acquisition required to support such a valuation [Crunchbase].

Lightly corroborated -- Growth scenarios are extrapolated from product claims and market dynamics; the valuation comparable is confirmed.

Sources

Public sources

  1. [PRNewswire, August 2025] Comp AI secures $2.6M pre-seed to disrupt SOC 2 market | https://www.prnewswire.com/news-releases/comp-ai-secures-2-6m-pre-seed-to-disrupt-soc-2-market-302519788.html

  2. [Refresh Miami, July 2026] AI compliance startup plants its HQ here, plans to hire 20 to start | https://www.refreshmiami.com/ai-compliance-startup-plants-its-hq-here-plans-to-hire-20-to-start/

  3. [Grand Ventures, August 2025] Why We Invested in Comp AI | https://grandvcp.com/why-we-invested-in-comp-ai/

  4. [Crunchbase] Comp AI - Crunchbase Company Profile & Funding | https://www.crunchbase.com/organization/comp-ai

  5. [Tofik Hasanov - Comp AI | LinkedIn, 2026] Tofik Hasanov - Comp AI | LinkedIn | https://www.linkedin.com/in/tofik-hasanov-100598205/

  6. [Comp AI: AI Compliance Software | Comp AI, 2026] Comp AI: AI Compliance Software | Comp AI | https://www.trycomp.ai/

  7. [trustmrr.com, June 2026] trustmrr.com, June 2026 | https://trustmrr.com

  8. [Perplexity Sonar Pro Brief] Perplexity Sonar Pro Brief |

  9. [DevOps.com, August 2025] DevOps.com, August 2025 |

  10. [How does Comp AI automatically collect evidence, and which tools and cloud platforms does it integrate with? · Comp AI, 2026] How does Comp AI automatically collect evidence, and which tools and cloud platforms does it integrate with? · Comp AI | https://www.trycomp.ai/

  11. [Comp AI Review 2026: Open-Source AI Compliance Software, 2026] Comp AI Review 2026: Open-Source AI Compliance Software | https://www.trycomp.ai/

  12. [Comp AI Compliance Platform Review 2026: Open-Source Agentic Compliance | RockB, 2026] Comp AI Compliance Platform Review 2026: Open-Source Agentic Compliance | RockB | https://www.trycomp.ai/

  13. [Mark Restall - Comp AI | LinkedIn, 2026] Mark Restall - Comp AI | LinkedIn | https://www.linkedin.com/in/mark-restall-0a3a09169/

  14. [soc2auditors.org, 2026] soc2auditors.org, 2026 | https://www.soc2auditors.org/

  15. [Fortune Business Insights, 2024] Fortune Business Insights, 2024 |

  16. [Competitor] Competitor |

Articles about Comp AI

View on Startuply.vc