Loading...

Comp AI Raises $34M Series A for Agentic Compliance Automation

Key takeaways

  • Comp AI raised $34M Series A from Roo Capital and Grand Ventures to automate security and compliance work using AI agents.
  • The startup was founded by Lewis Carhart, Claudio Fuentes, and Mariano Fuentes, who identified SOC 2 compliance as a tedious manual process while scaling LeapAI to over 1 million users.
  • The platform deploys AI agents to write policies and gather audit evidence, with humans reviewing and approving all consequential actions, and oversight escalating for higher-risk changes.
  • Comp AI addresses the monitoring gap that emerges when companies deploy new AI agents between scheduled security audits, leaving post-deployment changes unaccounted for.

Comp AI, a startup building artificial-intelligence-powered tools for security and compliance work, closed a $34 million Series A funding round led by Roo Capital and Grand Ventures on Thursday. The round reflects a growing market for platforms that help companies manage the security burden created by rapid AI adoption.

The startup is one of a new wave of compliance automation companies including Vanta and Drata, emerging as software firms increasingly need to prove they meet security and compliance standards to close enterprise deals. For many software companies, as CEO Lewis Carhart noted, security documentation directly determines whether customers will sign contracts. “What Comp AI automates is much of the work companies traditionally have to do around that process,” he said.

With $37.5 million in funding to date, Comp AI aims to expand the capabilities of its agentic platform—meaning it deploys artificial-intelligence agents to handle repetitive compliance tasks that previously required manual human effort. The company was founded in January 2025 by Carhart, Claudio Fuentes (COO), and Mariano Fuentes (CTA).

From LeapAI’s Failure to a SOC 2 Solution

The workflow platform that reached 1 million users

The founding team’s journey to Comp AI began with another startup called LeapAI. Claudio and Mariano Fuentes had been building products together for nearly a decade before they met Carhart, whom they invited to join their effort. At LeapAI, Claudio served as CEO and co-founder, Carhart headed growth efforts, and Mariano worked as a senior full-stack engineer.

The team built LeapAI into a workflow platform that accumulated more than a million users over roughly two years. Despite the user base, the three founders ultimately decided to shut the company down. They concluded that the platform lacked “a sticky enough use case to warrant continued investment.” The decision forced a reckoning: what had they learned that could become a business?

Where the tedium became the business

The shutdown taught them a critical lesson. Scaling LeapAI to enterprise clients meant dealing with SOC 2 compliance—the security certification that enterprise software buyers demand before closing deals. “It’s a very obscure process,” Claudio recalled. “It took us a couple of months of doing things by hand, and the whole time it meant taking our eyes off building the product.”

That month-long diversion from product work identified the actual gap. Security and compliance processes, particularly SOC 2 audits, consumed engineering time without generating revenue directly. But they also blocked revenue: companies could not sell without the certification. The Comp AI idea emerged from that pain point.

For this new venture, Carhart took the CEO role because the concept was his. The three set out to build a platform that would automate the tedious work of collecting audit evidence, writing security policies, and maintaining compliance controls—all tasks that consumed weeks of manual work at LeapAI.

Comp AI Raises $34M Series A for Agentic Compliance Automation

How the Platform Works

Comp AI’s core function is deploying artificial-intelligence agents to handle security and compliance work that software teams typically perform manually. The agents can write company security policies, gather documentation needed for audits, and continuously monitor whether the company maintains compliance with required controls.

The platform also offers AI-powered penetration testing, where the system “proactively tests codebases and infrastructures for vulnerabilities,” according to Carhart. This combination of policy automation, audit support, and continuous testing aims to compress the timeline and cost of staying compliant.

Critically, the platform does not replace independent auditors. Third-party auditors still conduct the actual SOC 2 review and sign off on findings. Comp AI handles the busy work that precedes and follows the audit, not the audit itself.

Humans Still Make the Final Call

A key distinction in Comp AI’s design is its approach to agent supervision. An AI agent might draft a security policy, but a human still reviews and approves it before it takes effect. The team believes that as agents take on more consequential actions over time—changes to access controls, modifications to system permissions—the level of human oversight and approval should increase accordingly, not decrease.

This design reflects a broader emerging principle in AI security: autonomous agents require graduated safeguards. Where an agent suggests a new internal policy, human review might be light. Where an agent alters user data permissions, human approval becomes mandatory and more rigorous.

Mariano emphasized that as companies adopt more AI, they need visibility into what each agent accessed, what it attempted to do, and whether it operated within assigned boundaries. Comp AI is tackling this by starting with permissions and accountability layers. “We’re building toward a security layer that can monitor and validate those kinds of risk more continuously as these systems evolve,” he said.

Why Continuous Monitoring Matters Now

The audit gap in the agentic era

A critical problem emerges as companies deploy artificial-intelligence systems at accelerating rates. Imagine a company completes its SOC 2 audit and two weeks later deploys a new AI agent that can access customer data, modify permissions across internal systems, or introduce vulnerabilities through code changes. The audit is now incomplete. It did not account for the new agent. The certification is technically still valid, but it no longer covers the company’s actual security posture.

“The audit didn’t become invalid; it simply wasn’t designed to tell you in real time what changed afterward,” Carhart said. Traditional SOC 2 audits capture a snapshot at a point in time. They do not track what happens between audits. In an era where companies deploy new AI agents monthly or weekly, the gap between audit date and current reality grows rapidly.

Comp AI’s answer is continuous monitoring. Rather than waiting for the next annual or biannual audit, the platform monitors security controls in real time. It alerts companies when new deployments, permission changes, or access patterns fall outside compliance boundaries. This shifts security from a scheduled event to an always-on process.

Carhart framed the opportunity this way: “For a lot of software companies, security and compliance are directly tied to revenue.” An enterprise customer demands a SOC 2 report. Without it, there is no contract. As AI adoption accelerates, the friction between audit events and actual system changes creates risk. Platforms that monitor compliance continuously rather than periodically become necessary infrastructure for companies selling to enterprise buyers.

What Comes Next

The $34 million Series A capital will support product expansion and market growth. Comp AI is entering a crowded field of compliance automation startups, but it is positioned around a specific problem: the security and compliance workflows that emerge when companies build and deploy AI agents at scale.

The founding team’s background—having built and scaled LeapAI to over 1 million users, then confronted the compliance burden firsthand—gives them credibility on the problem they are solving. They learned what sticky product-market fit looks like, and they learned the specific pain that regulatory and compliance work inflicts on growing software teams. Comp AI is betting that as enterprises adopt artificial-intelligence agents widely, the demand for continuous compliance monitoring will grow from niche need to standard requirement.

Frequently Asked Questions

What does Comp AI's platform do?

Comp AI deploys artificial-intelligence agents to automate security and compliance tasks including writing company security policies, collecting audit evidence, continuously monitoring compliance controls, and conducting AI-powered penetration testing. However, independent auditors still conduct official SOC 2 audits, and human workers review and approve all agent actions.

Why did the founders start Comp AI?

Lewis Carhart, Claudio Fuentes, and Mariano Fuentes previously worked together at LeapAI, a workflow platform that grew to over 1 million users but shut down due to lack of product-market fit. While scaling LeapAI to enterprise clients, they experienced how tedious SOC 2 compliance was, requiring several months of manual work that distracted from product development. That pain point inspired Comp AI.

Why does continuous monitoring matter for compliance?

Traditional SOC 2 audits capture a single point in time and don't account for changes afterward. If a company deploys a new AI agent two weeks after an audit, that agent's access to customer data or system permissions isn't covered by the audit. Comp AI's continuous monitoring approach tracks compliance changes in real time, alerting companies when new deployments or permission changes fall outside compliance boundaries.

Written by
Grace Whitmore

Grace Whitmore writes about personal finance and beginner investing education — building a first portfolio, emergency funds, and the most common mistakes new investors make.