Comp AI raises $34M Series A for agentic security compliance
Comp AI raised $34M Series A to build agentic compliance automation. What operators need to know about the AI compliance funding wave and competitive landscape.
What Happened
Comp AI, a cybersecurity and compliance startup founded in January 2025, announced a $34 million Series A round on September 17, 2026, led by Roo Capital and Grand Ventures. The round brings the company's total funding to $37.5 million.
The company was founded by Lewis Carhart (CEO), Claudio Fuentes (COO), and Mariano Fuentes (CTO). The trio previously built LeapAI, a workflow platform that grew to over one million users over roughly two years before they shut it down, citing a lack of a "sticky enough use case to warrant continued investment." That experience, however, taught them two things: how to build with LLMs and how painful the SOC 2 compliance process was when scaling to enterprise clients.
Comp AI's platform uses AI agents to automate tedious compliance work — drafting security policies, collecting evidence for audits, and continuously monitoring whether a company meets its compliance controls. The company also offers AI-powered penetration testing that proactively tests codebases and infrastructure for vulnerabilities.
Crucially, the founders emphasized that the platform does not replace independent audit review or human workers. "An agent might draft a policy, for example, but a person still reviews and approves it," Carhart told TechCrunch. "As agents take on more consequential actions over time, we believe the level of safeguards and human approval should increase accordingly."
Why It Matters
The AI compliance automation space is accelerating. Just six days before Comp AI's announcement, HelmGuard raised $7.3 million in seed funding for a nearly identical proposition — replacing compliance paperwork with AI agents. Two funding rounds in the same narrow niche within a single week signals that investors see a real, urgent problem.
The problem is real: traditional compliance audits are point-in-time snapshots. A company can complete a SOC 2 audit and two weeks later deploy a new AI agent that accesses customer data, changes internal permissions, or introduces vulnerabilities through code deployment. The audit doesn't become invalid — it simply wasn't designed to tell you what changed in real time.
But Comp AI is entering a market with well-funded incumbents. Vanta and Drata have dominated compliance automation for years, and both have been investing in AI features. Comp AI's pitch — continuous, agentic monitoring of what AI agents access and whether they stay within permission boundaries — is a genuine differentiator, but it's one that incumbents will likely move to address quickly.
For operators, the key question is whether compliance tooling becomes a feature of broader security platforms or remains a standalone category. If it's the former, companies like Comp AI face an acquisition-or-marginalization path. If it's the latter, the continuous monitoring angle could carve out a defensible niche.
Who Is Affected
Startups pursuing SOC 2 or similar certifications now have another vendor to evaluate, but the practical impact depends on whether Comp AI's agentic monitoring delivers materially better outcomes than Vanta or Drata's existing AI features. Enterprise security teams deploying AI agents internally should pay attention to the continuous monitoring pitch — the gap between annual audits and real-time agent oversight is a genuine risk vector. Investors watching this space should note that two rounds in one week is either a sign of a breakout category or a sign of overcrowding.
Strategic Implications
For AI startup founders: If you're building in compliance automation, the window to differentiate is closing. Vanta and Drata have distribution advantages and capital. Comp AI's $34M gives them runway, but the real moat would be owning the "agent monitoring" layer — tracking what AI agents access, what they attempt to do, and whether they stay in-bounds. That's a problem incumbents haven't fully solved.
For developers/operators building with AI APIs: Expect procurement teams to start asking about continuous compliance, not just annual audits. If you're deploying agents that touch customer data or modify permissions, start instrumenting logging and permission boundaries now — before a buyer's security review forces you to.
For non-technical business owners evaluating AI tools: A SOC 2 report is necessary but increasingly insufficient. Ask vendors specifically how they monitor AI agent behavior in real time, what agents can access in your environment, and whether their compliance is continuous or point-in-time. The audit you reviewed may already be stale.
What to Watch Next
Watch whether Vanta or Drata announce continuous agent monitoring features in the next quarter — that would signal whether Comp AI's differentiator is defensible or easily copied. Also monitor whether HelmGuard's seed-stage approach (lighter, more focused) competes more effectively than Comp AI's broader platform play.
Frequently Asked Questions
Q: What does Comp AI do?
A: Comp AI builds an agentic platform that automates security and compliance work — drafting policies, collecting audit evidence, continuously monitoring compliance controls, and running AI-powered penetration testing. It does not replace independent audit review or human oversight.
Q: How is Comp AI different from Vanta or Drata?
A: Comp AI's primary differentiator is continuous, agentic monitoring — tracking what AI agents access and whether they stay within permission boundaries in real time, rather than relying on point-in-time audit snapshots. Vanta and Drata have broader market presence and distribution but have not fully addressed the agent-monitoring gap.
Q: How much has Comp AI raised?
A: Comp AI has raised $37.5 million in total funding, including a $34 million Series A led by Roo Capital and Grand Ventures, announced on September 17, 2026.