· via TechCrunch
Comp AI raises $34M Series A for AI agents that handle security and compliance
Comp AI has raised a $34 million Series A led by Roo Capital and Grand Ventures to build AI agents that draft security policies, gather audit evidence and monitor compliance continuously.

Comp AI raises $34 million for agentic compliance
Comp AI, a startup building AI agents for security and compliance work, has raised a $34 million Series A, TechCrunch reports. Roo Capital and Grand Ventures led the round, which takes the company to $37.5 million in total funding since it was founded in January.
Built on a pain point from a previous startup
The company was started by Lewis Carhart as CEO, Claudio Fuentes as COO and Mariano Fuentes as CTO. According to TechCrunch, the Fuentes brothers had spent close to a decade building startups together when they met Carhart and brought him into LeapAI, a workflow platform where Claudio served as CEO, Carhart ran growth and Mariano worked as a senior full-stack engineer. LeapAI operated for roughly two years and grew past a million users before the team shut it down, having concluded the product never found a use case strong enough to justify further investment. This time Carhart took the top job, because the idea for Comp AI was his.
The failed venture still taught them two things: how to build with large language models, and how gruelling SOC 2 compliance becomes when an enterprise sales cycle depends on it. Claudio Fuentes described the process to TechCrunch as obscure and slow, consuming months of manual work at the exact moment the team needed to concentrate on shipping product. Comp AI exists to remove that friction.
Agents that draft, monitor and test
The platform puts AI agents to work writing security policies, collecting evidence for audits and continuously checking whether a company still satisfies its compliance controls. It also offers AI-driven penetration testing, which Carhart described to TechCrunch as scanning codebases and infrastructure for vulnerabilities before attackers find them.
Comp AI frames this as automation rather than substitution. Independent audits remain necessary, and people stay in the loop: staff help onboard the agents, support individual controls and keep the workflows running. An agent can draft a policy, but a person reviews and approves it, and Carhart argued that the level of safeguarding and human sign-off should rise as agents take on more consequential actions.
The commercial hook, he told TechCrunch, is that security and compliance sit directly on the revenue path for software companies. Buyers routinely ask for a SOC 2 report before closing a deal, so the surrounding work effectively gates sales.
The case for continuous compliance
Carhart's wider argument is that point-in-time audits no longer match the pace of change inside software companies. A business can pass its SOC 2 audit and, two weeks later, deploy an AI agent that reads customer data, changes permissions across internal systems or introduces a vulnerability through new code. The audit still stands; what it cannot do is tell the company, in real time, what shifted afterwards.
Mariano Fuentes added that as AI adoption spreads, organisations will need to account for an agent's data access, its attempted actions and whether it kept to its assigned limits. Comp AI is approaching this from permissions and accountability first, with the goal of a security layer that monitors and validates such risks continuously as systems evolve.
Why it matters
The round is fresh evidence that investors see durable demand for agentic tooling in security and compliance, a category where Vanta and Drata built large businesses on workflow automation. Comp AI is betting the next stage is autonomy: agents that keep compliance current between audits instead of teams scrambling once a year. If point-in-time audits increasingly diverge from the speed of AI deployment, continuous agent-driven monitoring may stop being a convenience and become table stakes. The company's insistence on human review also offers a template for how automation could be governed as agents take on higher-stakes work elsewhere. For startups selling to enterprises, anything that shortens the SOC 2 timeline translates fairly directly into faster deals.
- #ai-agents
- #compliance
- #cybersecurity
- #funding
- #startups