Product1 publisher2 min readPublished
Comp AI raises $34M to monitor the controls between SOC 2 audits
The startup's agents draft security policies and gather audit evidence, and its founders say a person still approves each policy while an independent auditor still signs the report.
The Product Desk · Product desk

What happened
- Comp AI said on Thursday that it had raised a $34 million Series A round led by Roo Capital and Grand Ventures.
- Lewis Carhart, Claudio Fuentes and Mariano Fuentes founded the company last January, with Carhart taking the CEO seat because the idea was his.
- The platform's agents help write company security policies and collect evidence for security audits, and it continuously monitors whether a company is meeting its compliance controls.
- Carhart said the software helps companies meet and maintain those security requirements but does not replace actual independent audit review.
- Comp AI also sells AI-powered penetration testing that Carhart said proactively tests codebases and infrastructures for vulnerabilities.
Compiled by The Product DeskSomething wrong?How this is made
Why it matters
- constraint Automating the evidence work shortens the scramble, but the deal still waits on an independent auditor's report, so a team hoping this moves the date a customer gets its letter will be disappointed.
- decision Finance has to price this as a second line beside the audit fee and the reviewer's time, because the founders say people still onboard the AI and keep the workflow running.
- exposure The state a buyer is paying to see is the fortnight after sign-off, when an agent gets permission to touch customer data and the last audit was not built to report on it.
- contradiction Carhart argues the need is for continuous and perhaps autonomous compliance, while the company's own account of the product keeps a human approval step on every policy an agent drafts.
The buying moment is a procurement email late in a sales cycle. "For a lot of software companies, security and compliance are directly tied to revenue," Carhart told TechCrunch, giving the example of a customer that asks a startup for a SOC 2 report before closing a deal [8]. Claudio Fuentes has been on the receiving end of that request. "It took us a couple of months of doing things by hand, and the whole time it meant taking our eyes off building the product," he said of the SOC 2 process at their previous startup [6][5].
What the platform watches is the state of the systems after the auditor leaves. "Imagine a company completes its SOC 2 audit," Carhart said, "and two weeks later deploys a new AI agent that can access customer data, change permissions across an internal system, or introduce a new vulnerability through code deployment" [13]. "The audit didn't become invalid; it simply wasn't designed to tell you in real time what changed afterward" [14]. Mariano Fuentes said companies adopting AI need to show what an agent accessed, what it tried to do and whether it stayed inside the boundaries it was given. Comp AI is starting with permissions and accountability, he said [17].
Comp AI has raised $37.5 million to date [2]. Subtract the Series A and roughly $3.5 million came before it [19]. TechCrunch's report does not include pricing, a customer count, or results from any customer's audit [20], and Vanta and Drata are already selling into the same buyer [16]. The company that feels the gap hardest is the one whose next enterprise contract is waiting on a report it cannot produce. Carhart's pitch is that "What Comp AI automates is much of the work companies traditionally have to do around that process" [23].
What matters for budgeting is whether someone outside your company has to sign the artifact, and how often the underlying state changes. Policies and evidence packets get signed and change once or twice a year. An agent can draft them, and "An agent might draft a policy, for example, but a person still reviews and approves it," Carhart said [11]. Permissions and code deployments change in the weeks after an audit closes, and no auditor is looking at them then. That second box is where continuous monitoring adds something new. It also lands as a new line beside the audit fee, since human workers still onboard the AI and maintain the agentic workflow [10]. "As agents take on more consequential actions over time, we believe the level of safeguards and human approval should increase accordingly," Carhart said [12].
What to watch
- Whether Comp AI publishes pricing or customer numbers that let a buyer compare it with Vanta or Drata.
- Whether any audit firm accepts agent-collected continuous evidence in place of point-in-time sampling.
- Whether the AI penetration testing product produces findings a customer or a third party will describe on the record.