Comp AI Raises $34M Series A for Agentic Security and Compliance Platform
Comp AI raised $34M in Series A funding led by Roo Capital and Grand Ventures to expand its agentic security and compliance platform.
The round brings Comp AI’s total funding to $37.5 million. The startup was founded last January by Lewis Carhart, who serves as CEO, Claudio Fuentes, COO, and his brother Mariano Fuentes, CTO. Claudio and Mariano had been building startups together for nearly a decade, met Carhart a few years ago and invited him to join LeapAI, a workflow platform they were building. Claudio was CEO and co-founder, Carhart was head of growth and Mariano was a senior full-stack engineer.
LeapAI ran for about two years and grew to more than a million users, but the founders decided to shut it down after not finding a “sticky enough use case to warrant continued investment,” they recalled. The experience taught them how to build with large language models and the importance of finding a specific use case for a product, they said. It also showed them how tedious the SOC 2 compliance process could be, especially as they tried to scale the platform to work with larger enterprise clients.
“It’s a very obscure process,” Claudio said, according to TechCrunch. “It took us a couple of months of doing things by hand, and the whole time it meant taking our eyes off building the product.”
Comp AI was created from that lesson. Carhart took the lead as CEO because the idea was his, the trio said. The company describes its platform as agentic: AI agents can help draft company security policies or collect evidence for security audits, while the software continuously monitors compliance controls. Human workers still onboard the AI, support controls and maintain the agentic workflow.
“An agent might draft a policy, for example, but a person still reviews and approves it,” Carhart told TechCrunch. “As agents take on more consequential actions over time, we believe the level of safeguards and human approval should increase accordingly.”
Carhart said security and compliance are directly tied to revenue for many software companies, citing a customer that might ask a startup for a SOC 2 report before closing a deal. Comp AI automates much of the work companies traditionally do around that process, he said, but it does not replace actual independent audit review or humans.
The company also offers AI-powered penetration testing, which Carhart described as a platform that proactively tests codebases and infrastructures for vulnerabilities. Comp AI hopes the Series A capital will help with product expansion.
The funding comes as companies adopt more AI agents and face questions about the security risks those systems introduce, alongside a wave of AI security and compliance companies such as Vanta and Drata. Carhart pointed to a scenario in which a company completes a SOC 2 audit and two weeks later deploys a new AI agent that can access customer data, change permissions across an internal system or introduce a new vulnerability through code deployment. “The audit didn’t become invalid; it simply wasn’t designed to tell you in real time what changed afterward,” he said.
Mariano said companies adopting more AI also need to show what an agent accessed, what it tried to do and whether it stayed within the boundaries given. Comp AI is starting with permissions and accountability, he said. “We’re building toward a security layer that can monitor and validate those kinds of risk more continuously as these systems evolve.”