Comp AI funding has delivered a $34 million Series A for the compliance startup to expand from audit preparation into continuously running security and control checks. Roo Capital and Grand Ventures led the round, according to the company and two independent reports published on September 17.

Everyone else is reporting a $34 million raise; we are explaining why the important product shift is from collecting audit evidence once to testing controls after every operational change.

Comp AI funding moves past the audit snapshot

The round matters because compliance software has traditionally been built around a deadline: gather policies, screenshots and logs, hand them to an auditor, then repeat the exercise months later. Comp AI is arguing that an AI agent should keep watching after the report is signed. That is a larger operational promise than faster paperwork, and it puts the company closer to security tooling than to a conventional checklist product.

TechCrunch reported that Roo Capital and Grand Ventures led the Series A and that total funding has reached $37.5 million. SiliconANGLE reported $36.6 million invested to date. The small difference appears to reflect rounding or the treatment of earlier capital, so this article uses the directly agreed figure—the new round is $34 million—and preserves the reported total as a range rather than forcing false precision.

Comp AI was founded in January 2025 by Lewis Carhart, Claudio Fuentes and Mariano Fuentes. TechCrunch described an earlier workflow startup built by the founders that was shut down after failing to find a sufficiently durable use case. That history helps explain the new company’s positioning: compliance is attached to a mandatory business outcome, because customers often require security evidence before signing a contract.

The company release says the platform uses agents to help with onboarding, evidence gathering, policy drafting, risk registers and vendor assessments. SiliconANGLE adds that Comp AI’s core is open source and that its supported frameworks include SOC 2 and ISO 27001. Those are product and company claims, not independently audited performance measurements, so buyers should treat them as a description of scope rather than proof of control effectiveness.

The capital is intended to take the platform beyond audit readiness into real-time monitoring, continuous control validation and testing across applications and infrastructure. That changes what success looks like. A document generator can be judged by speed and coverage; a security agent must also be judged by permissions, false positives, evidence integrity, rollback and whether human owners understand the actions it proposes.

The mechanism is straightforward. An integration reads approved systems and documents, maps evidence to a framework, flags missing controls and tracks changes. The difficult part comes after a change: deciding whether a new deployment, permission or vendor actually weakens a control. That decision needs context and may carry legal or commercial consequences, so an agent should produce traceable evidence instead of an unexplained pass-or-fail label.

How continuous compliance is intended to workA four-stage flow from approved system connections to human-reviewed remediation.Connectapproved systemsMapevidence to controlsMonitorchanges and driftReviewhuman remediation

What continuous compliance would have to prove

For customers, the practical benefit would be shorter gaps between a risky change and its discovery. A business can pass an audit and then deploy a new AI agent, alter access rights or introduce code that changes its exposure. Continuous monitoring is meant to detect that drift. It does not make an annual audit obsolete; it gives the control owner a more current record to review before the next assessment.

The competitive field is crowded. SiliconANGLE placed Comp AI alongside Vanta and Drata, two established compliance-automation providers. Comp AI’s differentiation therefore cannot rest only on using the word agentic. It will need to show that its agents reduce manual work without weakening evidence quality, and that automated security tests are safe in customer environments. Published benchmarks, audit-partner feedback and renewal data would make that case stronger.

The open-source core could lower evaluation friction for technical buyers because security teams can inspect part of the stack and test integrations before a broader rollout. Open source alone does not answer questions about the hosted service, training data, model routing or support boundaries. Procurement teams should separate what can be inspected from what remains a managed vendor promise.

There is also a governance paradox. The product is designed to monitor other agents and systems, yet its own agents require access to sensitive policy, identity, cloud and code information. A mature deployment needs least-privilege connectors, explicit write boundaries, immutable logs and a way to reproduce why an agent reached a conclusion. Those safeguards are central to the product category, not optional enterprise polish.

The funding therefore buys time for two connected tasks: broaden the product into security operations and build trust around the automation itself. Hiring, integrations and go-to-market expansion may increase reach, but evidence quality will determine whether the platform becomes part of a customer’s control plane or remains a faster preparation layer for audits.

The next useful disclosures would be retention and expansion metrics, the share of controls monitored continuously, the number of agent actions requiring human approval, and independently measured changes in audit preparation time. Until those arrive, the strongest verified conclusion is narrow: investors have committed $34 million to Comp AI’s plan to turn periodic compliance work into an always-on operating process.

Comp AI funding and disclosed adoptionBars compare the new Series A with prior capital and show adoption as a separately labelled count.Series A$34MEarlier capitalabout $3.5MCustomers1,000+ companies

Facts at a glance

Item Detail Source
New round $34 million Series A Comp AI; TechCrunch; SiliconANGLE
Lead investors Roo Capital and Grand Ventures Comp AI; TechCrunch
Disclosed customers More than 1,000 companies Comp AI; SiliconANGLE
Product direction Continuous monitoring, control validation and security testing Comp AI

What this means

Comp AI funding is a bet that compliance will become a continuous control function rather than an annual evidence sprint. The opportunity is faster detection of drift; the test is whether the agents produce permissioned, reproducible evidence that auditors and security owners can trust.

For related context, read Factory AI’s $200 million enterprise-agent round and our analysis of Hackuity’s vulnerability-operations funding.

FAQ

How much did Comp AI raise?

Comp AI announced a $34 million Series A led by Roo Capital and Grand Ventures.

What does Comp AI do?

It automates compliance evidence and policy work and plans to add continuous monitoring, control validation and security testing.

Is Comp AI an auditor?

No. Its software supports control and evidence workflows; independent auditors and accountable company owners still make formal judgments.

Why is continuous compliance different?

It watches for operational changes between audits instead of gathering evidence only near an assessment deadline.

Sources

Get the day’s top stories in your inbox

One concise email. No spam, unsubscribe anytime.