2 Sources
[1]
Comp AI sets eyes on a continuously agentic future for security and compliance
Comp AI, a cybersecurity and compliance startup, announced that it has raised a $34 million Series A round on Thursday. The round was led by Roo Capital and Grand Ventures. The company was founded last January by Lewis Carhart (CEO), Claudio Fuentes (COO), and his brother, Mariano Fuentes (CTO).
[2]
Compliance automation startup Comp AI raises $34M to push into security
Compliance automation startup Comp AI raises $34M to push into security Compliance automation startup Comp AI today said it has raised $34 million in new funding to advance its software for preparing companies for security audits. Comp AI plans to spend the money on monitoring that keeps running
Share
Copy Link
Comp AI, a cybersecurity and compliance startup, raised $34 million in Series A funding led by Roo Capital and Grand Ventures. The Miami-based company uses AI agents to automate tedious security and compliance tasks like SOC 2 audits, policy drafting, and evidence collection while introducing continuous monitoring beyond traditional audit cycles.
Comp AI, a cybersecurity and compliance startup, announced it has raised $34 million in Series A funding led by Roo Capital and Grand Ventures
1
2
. The round brings the company's total funding to $37.5 million since its founding in January 20251
. Founded by Lewis Carhart as CEO, Claudio Fuentes as COO, and Mariano Fuentes as CTO, the company emerged from the founders' frustrating experience with SOC 2 compliance while scaling their previous startup, LeapAI1
. The Miami-based company, incorporated as Bubba AI Inc., now serves more than 1,000 companies including Dub Technologies Inc. and OpenCode2
.
Source: TechCrunch
Comp AI is building an agentic AI platform designed to automate tedious security and compliance tasks that traditionally consume significant engineering resources
1
. The AI-driven compliance automation platform uses AI agents to automate tasks including writing company security policies, collecting evidence for security audits, and running vendor security assessments1
2
. The software reads customer systems and documents for organizational context, then drafts policies and risk registers based on its findings2
. The platform's core is open source and supports frameworks including SOC 2 and ISO 27001, positioning itself as an alternative to established players like Vanta Inc., valued at $4.15 billion in a $150 million round last year, and Drata Inc.2
.
Source: SiliconANGLE
Despite the heavy automation, Comp AI emphasizes that its platform doesn't replace human workers or independent audit reviews
1
. Human oversight remains essential for onboarding AI agents to automate tasks, supporting controls, and maintaining the agentic workflow. "An agent might draft a policy, for example, but a person still reviews and approves it," Carhart explained1
. The founders stressed that as agents take on more consequential actions over time, the level of safeguards and human approval should increase accordingly1
. This balanced approach addresses growing concerns about AI adoption risks while maintaining the efficiency gains that make compliance automation valuable for software companies where security requirements are directly tied to revenue.Related Stories
Comp AI plans to use the Series A funding to expand beyond traditional audit preparation into continuous security and compliance monitoring
1
2
. The company already offers AI-powered penetration testing that proactively tests codebases and infrastructures for vulnerabilities1
. Carhart highlighted a critical gap in current compliance approaches: "Imagine a company completes its SOC 2 audit and two weeks later deploys a new AI agent that can access customer data, change permissions across an internal system, or introduce a new vulnerability through code deployment. The audit didn't become invalid; it simply wasn't designed to tell you in real time what changed afterward"1
. Claudio Fuentes noted that compliance has historically been "an approximation of security" because underlying work could only be done manually and on fixed schedules, but AI agents remove that limitation as attacks accelerate in the agentic era2
.Comp AI has demonstrated remarkable traction since its launch, with annual recurring revenue multiplying 15 times over the past year
2
. The company's rapid growth reflects broader market dynamics as companies experiment with AI and create demand for continuous security validation. Mariano Fuentes emphasized the evolving requirements: companies now need to show what an agent accessed, what it attempted to do, and whether it stayed within assigned boundaries1
. The startup plans to deploy the new capital across product expansion and hiring in product, engineering, sales, and customer success teams2
. The company's previous pre-seed round of $2.6 million in August 2025 was co-led by Grand Ventures and OSS Capital, with Sentry co-founder David Cramer among the angel investors, bringing total investment to $36.6 million2
. As Carhart stated, "Security software shouldn't just track the work. It should understand the business, perform the work, and act as risk changes"2
.Summarized by
Navi
1
Science and Research

2
Technology

3
Policy and Regulation
