VMTech
Discuss a project

Comp AI secures $34 million Series A for agentic compliance

Comp AI secures $34 million Series A for agentic compliance

Comp AI, a cybersecurity and compliance startup, has raised a $34 million Series A led by Roo Capital and Grand Ventures. The company says it is building an agentic platform to automate security and compliance tasks, including drafting policies, collecting audit evidence and continuously monitoring whether controls are being met.

The round takes Comp AI's total funding to $37.5 million. The company was founded last January by CEO Lewis Carhart, COO Claudio Fuentes and CTO Mariano Fuentes, who previously worked together on the workflow platform LeapAI.

From a difficult SOC 2 process to a compliance product

LeapAI grew to more than one million users during its roughly two-year run, but its founders shut it down after concluding that it lacked a sufficiently sticky use case for further investment. The team said the experience gave it practical knowledge of building with large language models and reinforced the importance of focusing on a specific problem.

That problem was the manual work around SOC 2 compliance as LeapAI sought to serve larger enterprise customers. Claudio Fuentes said the process took months of manual effort and diverted attention from product development. Comp AI was created to automate much of the work companies conventionally perform to satisfy security requirements connected to customer deals.

Continuous controls as AI systems change

Comp AI positions its software as support for meeting and maintaining security requirements, not as a replacement for independent audit review. The founders also say it does not remove people from the process. Workers help onboard the AI, support controls and maintain the workflow, while a person reviews and approves a policy drafted by an agent.

The platform also offers AI-powered penetration testing, which Carhart described as proactively testing codebases and infrastructure for vulnerabilities. The Series A is intended to support product expansion.

The company's argument for continuous monitoring is tied to how quickly an organisation's risk posture can change after a point-in-time audit. Carhart described a scenario in which a company completes a SOC 2 audit and then deploys an AI agent with access to customer data, permission-changing capabilities or a route to introduce a vulnerability through code deployment. The audit is not invalid, he said, but it was not designed to report such subsequent changes in real time.

Permissions and accountability

Mariano Fuentes said organisations adopting more AI also need to demonstrate what an agent accessed, what it attempted to do and whether it remained within its assigned boundaries. Comp AI is starting with permissions and accountability as it works toward a security layer intended to monitor and validate those risks more continuously.

For businesses, the practical implication is to treat AI deployment as an ongoing control-management task: retain human approval for consequential actions, track permissions and activity, and ensure evidence can be produced as systems change.

#cybersecurity#compliance#aiagents#soc2
Open analytics
On the site 0 views
min read 3 17.09.2026
Instagram

Comp AI secures $34 million Series A for agentic compliance

Open the post on Instagram ↗