Breaking
AI & MLDeveloping Story

Comp AI raises $34M for agentic compliance

Startup bets AI agents will handle security audits and policies, with humans still holding approval power.

··1 hour ago·6 min read
man using black laptop computer
Photo by X on Unsplash

Security and compliance work has long been the tax that startups pay for selling to bigger customers. Comp AI, a cybersecurity and compliance startup, announced on Thursday that it has raised a $34 million Series A round led by Roo Capital and Grand Ventures, according to reporting from TechCrunch. The company says it is building an agentic platform to tackle tedious security and compliance work, with AI agents helping write company security policies or collect evidence for security audits.

The pitch lands in the middle of a broad conversation about new security risks introduced by AI agents, a conversation that has already produced a wave of AI security and compliance companies. What Comp AI is arguing, essentially, is that the same technology creating those risks should be pointed at the administrative work of proving a company is safe in the first place.

Three founders, one failed startup

Comp AI was founded last January by Lewis Carhart (CEO), Claudio Fuentes (COO), and his brother, Mariano Fuentes (CTO). Claudio and Mariano had been building startups together for nearly a decade before they met Carhart a few years ago and invited him to join LeapAI, a workflow platform they were building.

At LeapAI, Claudio was the CEO and co-founder, Carhart served as head of growth, and Mariano was a senior full-stack engineer. The startup ran for about two years and grew to more than a million users, but the team eventually decided to shut it down after not finding a “sticky enough use case to warrant continued investment.”

That experience taught them a lot, they recalled. They learned how to build with LLMs and the importance of finding a specific use case for a product. They also learned how tedious the SOC 2 compliance process was, especially as they tried to scale the platform to work with bigger enterprise clients.

“It’s a very obscure process,” Claudio said. “It took us a couple of months of doing things by hand, and the whole time it meant taking our eyes off building the product.”

That frustration became the startup idea. This time, Carhart would take the lead as CEO because it was his idea, the trio said.

What the agents actually do

The platform continuously monitors whether a company is meeting compliance controls, and its agents help draft policies and gather audit evidence. The software helps companies meet and maintain those security requirements, but does not replace actual independent audit review, according to Carhart. It also does not replace humans, the trio said — human workers help onboard the AI, support controls, and maintain the agentic workflow.

“An agent might draft a policy, for example, but a person still reviews and approves it,” Carhart said. “As agents take on more consequential actions over time, we believe the level of safeguards and human approval should increase accordingly.”

— Lewis Carhart, CEO of Comp AI

The company also offers AI-powered penetration testing, “where the platform proactively tests codebases and infrastructures for vulnerabilities,” Carhart said. The team hopes the Series A capital will help with product expansion. It has raised $37.5 million in funding to date.

Why a SOC 2 report expires in practice

For a lot of software companies, security and compliance are directly tied to revenue — a customer might ask a startup for a SOC 2 report before closing a deal. That makes the paperwork load a sales problem as much as a security one. Carhart said the rapid adoption and experimentation companies are doing with AI is creating a need for continuous, and perhaps autonomous, security and compliance platforms.

“Imagine a company completes its SOC 2 audit and two weeks later deploys a new AI agent that can access customer data, change permissions across an internal system, or introduce a new vulnerability through code deployment,” he said. “The audit didn’t become invalid; it simply wasn’t designed to tell you in real time what changed afterward.”

— Lewis Carhart, CEO of Comp AI

The gap Carhart describes is temporal rather than technical. A point-in-time audit can be accurate on the day it is issued and still tell a buyer almost nothing about what has changed since. Continuous monitoring is the proposed answer: watch the controls, watch the agents, and flag drift as it happens rather than at the next review cycle.

Permissions first, accountability second

As companies adopt more AI, Mariano said, they also need to show what an agent accessed, what it tried to do, and whether it stayed within the boundaries given.

Comp AI is tackling this by starting with permissions and accountability, he continued. “We’re building toward a security layer that can monitor and validate those kinds of risk more continuously as these systems evolve.”

That ordering matters. Before an agent can be trusted to draft a policy or collect evidence, the platform needs a record of what that agent was permitted to touch and what it actually did. The company’s framing puts humans in the approval chain at the points where an agent would take a consequential action, and leaves the drafting and collection work to automation.

The money and the market

The round was led by Roo Capital and Grand Ventures. Comp AI says it is part of the next generation of cybersecurity startups emerging to help companies run more efficiently in the agentic era — a group that already includes established players like Vanta and Drata, per the reporting.

  • $34 million — size of the Series A round
  • $37.5 million — total funding raised to date
  • January — month the company was founded, last January
  • More than a million users — scale reached by the founders’ previous startup, LeapAI, over about two years
  • A couple of months — time the founders spent handling SOC 2 work by hand at LeapAI

What the platform does not claim

Comp AI’s own description draws clear lines around what the software replaces. It does not stand in for an independent audit review. It does not remove people from the loop — staff onboard the AI, support controls, and maintain the agentic workflow. An agent can draft a policy; a person reviews and approves it.

The founders’ stated view is that safeguards should scale with the consequences of an agent’s actions. As agents take on more consequential actions over time, they said, the level of safeguards and human approval should increase accordingly. That is a design principle rather than a product guarantee, and it reflects the founders’ own experience running a workflow platform that grew large before they shut it down.

What buyers should watch

For companies on the buying side of security reviews, the pitch raises a practical question: if AI agents are now being granted access to customer data and internal permissions, who is keeping the record of what they did with it? Comp AI’s answer is continuous monitoring plus human approval at consequential steps, with agents handling the drafting and evidence collection that used to consume engineering time.

For the founders, the bet is that the compliance market will move from periodic proof to ongoing observation. The Series A gives them capital to expand the product, and the company’s own framing suggests the security layer for agent behavior is still being built out as those systems evolve.

The stakes for readers are straightforward. Companies adopting AI agents are accumulating a category of access that traditional audits were never designed to track in real time. A SOC 2 report issued before an agent was deployed may still be valid, but as Carhart put it, it simply was not designed to tell you what changed afterward. Whether continuous, agent-driven compliance becomes the norm or remains a niche offering is an open question — but the funding suggests investors are willing to find out.

#compliance#ai agents#cybersecurity#startups#soc 2

Sources

Iliyas

Founder & Editor, Xploitwire

This article was written and reviewed against the sources listed above before publication, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories