Comp AI, a Miami-based startup that uses artificial intelligence to automate security compliance work, said it closed a $34 million Series A led by Roo Capital and Grand Ventures. The company, which helps businesses navigate the maze of SOC 2, ISO 27001 and HIPAA requirements, said it has signed up more than 1,000 customers since launching roughly 20 months ago. It declined to share its valuation.
The funding brings Comp AI's total haul to over $36 million. The company raised $2.6 million in a pre-seed round co-led by OSS Capital and Grand Ventures, with checks from angels including Sentry co-founder David Cramer and Ben's Bites creator Ben Tossell, according to TechCrunch.
The pace of customer growth is striking in a crowded field. Vanta, the category leader, reached an estimated $300 million in annual recurring revenue as of early this year and carries a $4.15 billion valuation from a July 2025 funding round, according to research firm Sacra. Drata, another incumbent, has raised hundreds of millions. Both companies automate compliance workflows, but Comp AI's founders argue their approach goes further by making the platform open-source and leaning harder into AI agents that work around the clock.
Lewis Carhart, Comp AI's chief executive, framed the pitch plainly in an interview with TechCrunch: "For a lot of software companies, security and compliance are directly tied to revenue." Customers who lack SOC 2 or ISO 27001 certification often lose enterprise deals. Traditionally, companies hire consultants, scramble to gather documentation once or twice a year, then wait months for auditors to finish. Comp AI promises to collapse that timeline by automating evidence collection, drafting policies on the fly and monitoring compliance controls in real time rather than during annual sprints.
The company reported 15-times year-over-year growth in ARR, though it did not disclose the actual dollar figure. Carhart said the new capital will fund an expansion into live cybersecurity functions such as AI-driven penetration testing and automated control validation. The idea, he said, is to move beyond audit prep and into software that "understands the business, performs the work, and acts as risk changes."
Comp AI's platform taps into more than 580 integrations to pull evidence automatically. An open-source device agent monitors employee machines for encryption, firewall settings and screen locks. The system generates policies and risk assessments, then publishes findings in a live trust center that displays only verified controls, according to company materials. Supported frameworks include SOC 2, ISO 27001, HIPAA and GDPR, with FedRAMP documentation also available. Carhart emphasized that humans remain in the loop: "An agent might draft a policy, for example, but a person still reviews and approves it."
The company's founders bring some scar tissue to the problem. Carhart, Claudio Fuentes and Mariano Fuentes previously built Leap AI, a workflow automation platform that attracted more than one million users before shutting down. Claudio Fuentes ran into SOC 2 compliance at Leap and described the process as "very obscure" in an interview with TechCrunch. The three incorporated Comp AI as Bubba AI Inc., according to SiliconANGLE.
Named customers include Corgi, Dub, OpenCode, Inference and Primer, according to a company press release. Comp AI's own trust center lists compliance with SOC 2 Type 2, ISO 27001, HIPAA and GDPR, though the auditors behind those certifications are not identified on the page.
The company has been adding staff. It opened a 6,000-square-foot headquarters in Aventura, Florida, in late July following a renovation that cost roughly $200,000, Business Wire reported. At the time, the startup said it had seven Miami-based employees and planned to hire about 20 more within 100 days while maintaining offices in New York City and the United Kingdom. LinkedIn data showed the headcount at 11 to 50 employees in recent months. Comp AI said Series A proceeds will go toward hiring across product, engineering, sales, customer success and marketing in Miami and New York.

Comp AI maintains a public GitHub repository under an AGPL-3.0 license, positioning itself as the open-source alternative to Vanta and Drata. Whether that distinction matters to enterprise buyers remains an open question, but investors are betting on the AI angle. "AI is changing the security and compliance landscape quickly, and businesses can no longer afford to treat compliance as an annual box-checking exercise," said Varun Sridhar, a principal at Roo Capital, in the company's announcement.
Nathan Owen, general partner at Grand Ventures, added: "Growing to more than 1,000 customers this quickly is remarkable, and we believe they're just getting started."
The compliance software market has historically been reactive, built around intermittent audits and static checklists. Comp AI's bet is that the next generation of tools will operate continuously in the background, catching vulnerabilities before they become audit failures or worse. Whether the company can scale that promise alongside Vanta's towering lead will likely determine if this funding round was well timed or just another step in a much longer slog.

