Comp AI Raises $34 Million for Continuous Agentic Security and SOC 2 Compliance
Comp AI raises $34 million to expand AI agents for SOC 2 compliance, continuous control monitoring and AI-powered penetration testing for enterprises.
Summary
Comp AI raised a $34 million Series A on September 17, 2026, led by Roo Capital and Grand Ventures, bringing total funding to $37.5 million. Founded in January 2026 by CEO Lewis Carhart, COO Claudio Fuentes and CTO Mariano Fuentes, the company grew from their experience at LeapAI. Brothers Claudio and Mariano had built startups together for nearly a decade before inviting Carhart to the workflow platform, where Claudio was CEO and co-founder, Carhart led growth and Mariano was a senior full-stack engineer. LeapAI exceeded one million users during its roughly two-year run but closed after failing to find a sufficiently sticky use case.
LeapAI’s SOC 2 work took a couple of months by hand and diverted attention from product development, inspiring Comp AI’s focused use of LLMs. Its agents draft security policies, collect audit evidence and continuously monitor compliance controls, while AI-powered penetration testing probes codebases and infrastructure for vulnerabilities. Customers may require a SOC 2 report before signing software deals, tying compliance to revenue, but Comp AI does not replace independent audits or employees. People onboard the AI, support controls, maintain workflows and approve drafts, with stronger safeguards planned as agents take more consequential actions.
The Series A will support product expansion toward continuous, potentially autonomous security as AI adoption creates risks periodic audits cannot track in real time. An agent deployed two weeks after a SOC 2 audit could access customer data, change internal permissions or introduce code vulnerabilities. Comp AI is starting with permissions and accountability, aiming to record what agents accessed, attempted and whether they stayed within assigned boundaries. Vanta and Drata also compete in the expanding AI security and compliance market.
Positives
- The $34 million Series A brings Comp AI’s total funding to $37.5 million and will finance product expansion.
- LeapAI surpassed one million users in roughly two years, giving Comp AI’s founders experience building and scaling LLM products.
- Comp AI agents draft security policies, collect audit evidence and continuously monitor whether companies meet compliance controls.
- AI-powered penetration testing proactively checks codebases and infrastructure for vulnerabilities.
- Human workers onboard the AI, support controls, maintain workflows and approve agent-drafted policies.
Risks & concerns
- LeapAI closed despite exceeding one million users because its founders could not find a sufficiently sticky use case.
- Manual SOC 2 compliance consumed a couple of months and diverted the founders from product development.
- Comp AI cannot replace independent audit reviews, leaving customers responsible for formal external validation.
- New agents can access customer data, change internal permissions or introduce code vulnerabilities shortly after an audit.
- More consequential agent actions will require stronger safeguards and increased human approval.