Comp AI, a cybersecurity and compliance startup, raised $34 million in Series A funding led by Roo Capital and Grand Ventures. The Miami-based company uses AI agents to automate tedious security and compliance tasks like SOC 2 audits, policy drafting, and evidence collection while introducing continuous monitoring beyond traditional audit cycles.

Comp AI Secures $34 Million Series A Funding

Comp AI, a cybersecurity and compliance startup, announced it has raised $34 million in Series A funding led by Roo Capital and Grand Ventures

1

2

. The round brings the company's total funding to $37.5 million since its founding in January 2025

1

. Founded by Lewis Carhart as CEO, Claudio Fuentes as COO, and Mariano Fuentes as CTO, the company emerged from the founders' frustrating experience with SOC 2 compliance while scaling their previous startup, LeapAI

1

. The Miami-based company, incorporated as Bubba AI Inc., now serves more than 1,000 companies including Dub Technologies Inc. and OpenCode

2

.

Source: TechCrunch

Source: TechCrunch

Building an Agentic AI Platform for Compliance Automation

Comp AI is building an agentic AI platform designed to automate tedious security and compliance tasks that traditionally consume significant engineering resources

1

. The AI-driven compliance automation platform uses AI agents to automate tasks including writing company security policies, collecting evidence for security audits, and running vendor security assessments

1

2

. The software reads customer systems and documents for organizational context, then drafts policies and risk registers based on its findings

2

. The platform's core is open source and supports frameworks including SOC 2 and ISO 27001, positioning itself as an alternative to established players like Vanta Inc., valued at $4.15 billion in a $150 million round last year, and Drata Inc.

2

.

Source: SiliconANGLE

Source: SiliconANGLE

Humans Remain Central to the Agentic Workflow

Despite the heavy automation, Comp AI emphasizes that its platform doesn't replace human workers or independent audit reviews

1

. Human oversight remains essential for onboarding AI agents to automate tasks, supporting controls, and maintaining the agentic workflow. "An agent might draft a policy, for example, but a person still reviews and approves it," Carhart explained

1

. The founders stressed that as agents take on more consequential actions over time, the level of safeguards and human approval should increase accordingly

1

. This balanced approach addresses growing concerns about AI adoption risks while maintaining the efficiency gains that make compliance automation valuable for software companies where security requirements are directly tied to revenue.

Expanding Into Continuous Security and Compliance

Comp AI plans to use the Series A funding to expand beyond traditional audit preparation into continuous security and compliance monitoring

1

2

. The company already offers AI-powered penetration testing that proactively tests codebases and infrastructures for vulnerabilities

1

. Carhart highlighted a critical gap in current compliance approaches: "Imagine a company completes its SOC 2 audit and two weeks later deploys a new AI agent that can access customer data, change permissions across an internal system, or introduce a new vulnerability through code deployment. The audit didn't become invalid; it simply wasn't designed to tell you in real time what changed afterward"

1

. Claudio Fuentes noted that compliance has historically been "an approximation of security" because underlying work could only be done manually and on fixed schedules, but AI agents remove that limitation as attacks accelerate in the agentic era

2

.

Explosive Growth Signals Market Demand

Comp AI has demonstrated remarkable traction since its launch, with annual recurring revenue multiplying 15 times over the past year

2

. The company's rapid growth reflects broader market dynamics as companies experiment with AI and create demand for continuous security validation. Mariano Fuentes emphasized the evolving requirements: companies now need to show what an agent accessed, what it attempted to do, and whether it stayed within assigned boundaries

1

. The startup plans to deploy the new capital across product expansion and hiring in product, engineering, sales, and customer success teams

2

. The company's previous pre-seed round of $2.6 million in August 2025 was co-led by Grand Ventures and OSS Capital, with Sentry co-founder David Cramer among the angel investors, bringing total investment to $36.6 million

2

. As Carhart stated, "Security software shouldn't just track the work. It should understand the business, perform the work, and act as risk changes"

2

.

Today's Top Stories

© 2026 TheOutpost.AI All rights reserved