In a significant development for the burgeoning field of AI-driven cybersecurity and compliance, Comp AI, a forward-thinking startup, announced the successful closure of a $34 million Series A funding round. This substantial investment, co-led by the prominent venture capital firms Roo Capital and Grand Ventures, underscores the market’s growing confidence in Comp AI’s mission to streamline and automate critical, yet often cumbersome, security and compliance processes for businesses. The infusion of capital is slated to fuel the company’s product expansion and further solidify its position as a leader in the next generation of AI-powered security solutions.
The genesis of Comp AI can be traced back to the shared experiences and entrepreneurial spirit of its co-founders: CEO Lewis Carhart, COO Claudio Fuentes, and CTO Mariano Fuentes. The brothers, Claudio and Mariano, boast a decade-long history of collaborating on startup ventures. Their paths converged with Carhart a few years prior when they invited him to join LeapAI, a workflow platform they were developing. Within LeapAI, Claudio served as CEO and co-founder, Carhart spearheaded growth initiatives, and Mariano contributed as a senior full-stack engineer. Despite achieving considerable success, scaling to over a million users, LeapAI was eventually sunsetted. The founders candidly admitted that the decision to close the platform stemmed from their inability to identify a "sticky enough use case to warrant continued investment," a crucial lesson learned in the highly competitive startup landscape.
This pivotal experience, however, proved to be an invaluable learning ground for the founding team. They gained profound insights into the practical application of Large Language Models (LLMs) and the paramount importance of pinpointing a specific, high-demand use case for any new product. Crucially, their time at LeapAI also exposed them firsthand to the arduous nature of SOC 2 compliance, a process that became particularly burdensome as they attempted to scale their platform to accommodate larger enterprise clients. Claudio Fuentes vividly recalled the challenges, describing the SOC 2 process as "very obscure." He elaborated, "It took us a couple of months of doing things by hand, and the whole time it meant taking our eyes off building the product." This frustration with manual, time-consuming compliance tasks, which directly diverted resources from core product development, served as the direct catalyst for the birth of Comp AI.
With this clear problem identified and a wealth of experience in building and scaling software, the trio decided to embark on a new venture. This time, Lewis Carhart would assume the CEO role, as the core idea originated from his insights and observations. Comp AI is dedicated to building an "agentic platform" designed to tackle the often tedious and resource-intensive aspects of security and compliance. The core of their innovative approach lies in leveraging AI agents to automate a range of critical tasks. This includes assisting in the drafting of company security policies, a process that traditionally requires significant human effort and expertise. Furthermore, Comp AI agents can meticulously collect and organize evidence required for security audits, a task that is notorious for its complexity and the potential for oversight. The platform also provides continuous monitoring capabilities, ensuring that a company consistently adheres to its defined compliance controls in real-time. Comp AI’s emergence signifies its role as part of a new wave of cybersecurity startups, focused on empowering companies to operate more efficiently and securely within the rapidly evolving "agentic era."
Lewis Carhart emphasized the direct link between robust security and compliance measures and revenue generation for many software companies. He provided a compelling example: "For a lot of software companies, security and compliance are directly tied to revenue. For instance, a customer might ask a startup for a SOC 2 report before closing a deal." He continued, "What Comp AI automates is much of the work companies traditionally have to do around that process." This highlights Comp AI’s strategic positioning to address a critical business bottleneck, transforming a potential roadblock into a catalyst for growth.
The software developed by Comp AI is engineered to assist companies in both meeting and diligently maintaining their security requirements. However, the founders are keen to clarify that their platform does not aim to replace independent audit reviews, which remain essential for external validation. Similarly, Comp AI does not seek to eliminate the need for human involvement. Instead, the company advocates for a symbiotic relationship where human workers play a crucial role in onboarding the AI, supporting compliance controls, and actively maintaining the agentic workflow. Carhart elaborated on this human-AI collaboration: "An agent might draft a policy, for example, but a person still reviews and approves it." He further articulated their vision for the future, stating, "As agents take on more consequential actions over time, we believe the level of safeguards and human approval should increase accordingly." This measured approach to AI integration prioritizes both efficiency and robust human oversight, ensuring accountability and mitigating risks.
Beyond policy and audit support, Comp AI also offers innovative AI-powered penetration testing. Carhart described this capability as "where the platform proactively tests codebases and infrastructures for vulnerabilities." This proactive approach allows companies to identify and remediate security weaknesses before they can be exploited by malicious actors. The company’s ambition is to leverage the Series A funding to significantly expand its product offerings and enhance its existing capabilities. To date, Comp AI has successfully raised a total of $37.5 million in funding, a testament to the strong investor interest in their innovative solutions.
The current technological landscape is characterized by extensive discussions surrounding the emergence of new security risks associated with the agentic era. This evolving threat landscape has, in turn, spurred the development of a new generation of AI security and compliance companies, with notable players like Vanta and Drata already making their mark. Carhart observed that the rapid adoption and experimental deployment of AI technologies by businesses are creating an urgent and undeniable need for security and compliance platforms that can operate continuously and, potentially, autonomously. He painted a vivid picture of the challenges: "Imagine a company completes its SOC 2 audit and two weeks later deploys a new AI agent that can access customer data, change permissions across an internal system, or introduce a new vulnerability through code deployment." He continued, "The audit didn’t become invalid; it simply wasn’t designed to tell you in real time what changed afterward." This highlights a critical gap in traditional compliance frameworks, which are often static and struggle to keep pace with the dynamic nature of AI deployments.
Mariano Fuentes further elaborated on the evolving needs of businesses in this new paradigm. As companies increasingly integrate AI into their operations, he explained, there is a growing necessity to meticulously track and document what an AI agent accessed, its attempted actions, and whether its activities remained within the defined operational boundaries. Comp AI is directly addressing this challenge by focusing initially on permissions and accountability. He articulated their long-term vision: "We’re building toward a security layer that can monitor and validate those kinds of risks more continuously as these systems evolve." This commitment to continuous monitoring and validation is crucial for establishing trust and ensuring responsible AI deployment. By providing granular insights into AI behavior and enforcing strict accountability, Comp AI aims to empower businesses to navigate the complexities of the agentic era with greater confidence and security. The company’s strategic focus on these critical areas positions it to become an indispensable partner for organizations embracing the transformative power of AI.

