Comp AI Raises $34M to Build a Continuously Agentic Future for

Comp AI Secures $34M Series A to Automate Security and Compliance with Agentic AI


Comp AI, a cybersecurity and compliance startup, announced Thursday that it has raised a $34 million Series A round led by Roo Capital and Grand Ventures. The funding brings the company's total raised to $37.5 million and will fuel product expansion.


Founding Team and Origin Story


The company was founded in January 2024 by CEO Lewis Carhart, COO Claudio Fuentes, and CTO Mariano Fuentes. Claudio and Mariano, brothers, had been building startups together for nearly a decade before meeting Carhart a few years ago. They invited him to join LeapAI, a workflow platform they were developing. Claudio served as CEO and co-founder, Carhart as head of growth, and Mariano as a senior full-stack engineer. The startup grew to more than a million users over roughly two years but was eventually shut down after the team failed to find a "sticky enough use case to warrant continued investment."


Lessons That Sparked a New Idea


Despite the shutdown, the experience proved invaluable. The founders learned how to build with large language models (LLMs) and the importance of targeting a specific use case. They also experienced firsthand the tedium of SOC 2 compliance, particularly when scaling the platform to serve larger enterprise clients.


"It's a very obscure process," Claudio said. "It took us a couple of months of doing things by hand, and the whole time it meant taking our eyes off building the product."


That pain point gave birth to a new startup idea. This time, Carhart would lead as CEO since the concept was his, the trio explained.


What Comp AI Does


Comp AI is building an agentic platform to tackle tedious security and compliance work. The platform uses AI agents to help write company security policies, collect evidence for security audits, and continuously monitor whether a company is meeting compliance controls. It represents a new generation of cybersecurity startups emerging to help companies operate more efficiently in the agentic era.


"For a lot of software companies, security and compliance are directly tied to revenue," Carhart told TechCrunch, noting that a customer might request a SOC 2 report before closing a deal. "What Comp AI automates is much of the work companies traditionally have to do around that process."


The software helps companies meet and maintain security requirements but does not replace independent audit review, the founders emphasized. Nor does it replace humans. Human workers help onboard the AI, support controls, and maintain the agentic workflow.


"An agent might draft a policy, for example, but a person still reviews and approves it," Carhart said. "As agents take on more consequential actions over time, we believe the level of safeguards and human approval should increase accordingly."


AI-Powered Penetration Testing


Comp AI also offers AI-powered penetration testing, which Carhart describes as a platform that "proactively tests codebases and infrastructures for vulnerabilities." The team hopes the Series A capital will accelerate product expansion.


The Growing Need for Continuous, Autonomous Compliance


The agentic era has brought a wave of new security risks—and with it, a surge of AI security and compliance companies like Vanta and Drata. Carhart argues that the rapid adoption and experimentation companies are doing with AI is creating demand for continuous—and perhaps autonomous—security and compliance platforms.


"Imagine a company completes..." (The article continues with Carhart elaborating on the vision for continuous, autonomous compliance.)

via TechCrunch

Related