Skip to main content Scroll Top
Recent Post
Subscribe to our newsletter and get your daily dose of The Tech Insider straight to your inbox:

    Hidden fields
    Popular Posts
    Comp AI Raises $34M to Build Continuous AI-Powered Security and Compliance

    As companies deploy more AI agents across their operations, traditional security and compliance processes may struggle to keep pace.

    Cybersecurity startup Comp AI believes the answer is to make compliance itself more continuous and agentic.

    The company has raised $34 million in Series A funding, led by Roo Capital and Grand Ventures, bringing its total funding to $37.5 million.

    Comp AI is developing a platform where AI agents automate repetitive security and compliance work while humans remain responsible for oversight and approval.

    A Painful SOC 2 Process Inspired the Startup

    Comp AI was founded by Lewis Carhart, Claudio Fuentes, and Mariano Fuentes.

    Before launching the company, the founders worked together on LeapAI, an AI workflow platform that eventually attracted more than one million users.

    Despite that growth, they shut the startup down after concluding that it lacked a sufficiently sticky use case to justify further investment.

    But the experience gave them two valuable lessons: how to build products around large language models and how frustrating enterprise compliance could become.

    While trying to move LeapAI toward larger customers, the team encountered the lengthy SOC 2 compliance process.

    Completing security requirements manually consumed months of work and pulled attention away from product development.

    That pain point eventually became the foundation for Comp AI.

    AI Agents Take On Compliance Work

    Comp AI uses AI agents to automate tasks that traditionally require substantial manual effort.

    The platform can help companies draft security policies, gather evidence needed for audits, and continuously monitor whether required compliance controls are being maintained.

    This matters because security certifications can directly affect revenue.

    Enterprise customers frequently ask software vendors to demonstrate compliance with standards such as SOC 2 before approving contracts.

    For startups, delays in producing that evidence can therefore become delays in closing deals.

    Comp AI’s goal is to automate much of the operational work surrounding those requirements.

    Humans Still Remain in the Loop

    The company emphasizes that its AI agents aren’t intended to eliminate independent auditors or human security professionals.

    An agent might prepare a security policy, for example, but a person still reviews and approves it.

    Human workers also help configure the platform, support controls, and supervise agentic workflows.

    The founders argue that human oversight should actually become stronger as agents receive permission to perform increasingly consequential actions.

    That approach reflects an important principle for enterprise AI: greater autonomy should be accompanied by stronger safeguards and accountability.

    Security Can’t Stop When the Audit Ends

    Comp AI’s larger argument is that periodic compliance checks aren’t enough for an increasingly agentic enterprise.

    Imagine a company successfully completing its SOC 2 audit.

    Two weeks later, it deploys an AI agent capable of accessing customer information, modifying internal permissions, or pushing new code.

    The previous audit isn’t suddenly meaningless, but it cannot automatically explain what changed after the assessment.

    That’s why Comp AI sees the future of compliance as continuous rather than periodic.

    Organizations increasingly need visibility into what an AI agent accessed, what actions it attempted, which permissions it used, and whether it remained inside established boundaries.

    Comp AI is beginning with permissions and accountability while working toward a broader security layer capable of continuously monitoring these risks.

    AI-Powered Penetration Testing Is Part of the Plan

    The company is also developing AI-powered penetration testing.

    Its platform can proactively examine codebases and infrastructure for potential vulnerabilities, expanding its role beyond compliance automation into active security testing.

    Comp AI plans to use its new Series A capital to continue expanding these capabilities.

    Compliance Is Entering the Agentic Era

    The rapid adoption of enterprise AI is creating an unusual challenge.

    Companies are using autonomous systems to move faster, but those same systems can change applications, permissions, data access, and security conditions much faster than traditional annual or periodic audits can capture.

    That could create demand for a new generation of security platforms capable of monitoring AI systems continuously.

    In an agentic enterprise, compliance may no longer be something companies prove once a year. It could become an always-on process — with AI agents helping monitor other AI agents while humans remain responsible for the final decisions.

    Related Posts

    Add Comment

    More news