Comp AI raises $34m to turn compliance into continuous monitoring
“Security software shouldn’t just track the work. It should understand the business, perform the work, and act as risk changes,” said Lewis Carhart, chief executive and co-founder of Comp AI. The Miami company has raised a $34m Series A led by Roo Capital and Grand Ventures, it announced on 17 September. It has raised $37.5m […] This story continues at The Next Web
“Security software shouldn’t just track the work. It should understand the business, perform the work, and act as risk changes,” said Lewis Carhart, chief executive and co-founder of Comp AI.
The Miami company has raised a $34m Series A led by Roo Capital and Grand Ventures, it announced on 17 September. It has raised $37.5m in total, TechCrunch reported.
Comp AI sells software that automates security compliance work. Its agents handle onboarding, policy and risk generation, evidence gathering, control monitoring and vendor assessments, the company said.
The company was founded in January 2025. It says it now serves more than 1,000 customers, names Corgi, Dub, OpenCode, Inference and Primer among them, and reports 15 times annual recurring revenue growth year on year.
The first generation of compliance software replaced spreadsheets, consultants and months of manual preparation, Comp AI said. Much of the work still depends on people, which leaves companies with periodic snapshots of their security.
“Historically, compliance has been an approximation of security because so much of the work could only be performed manually and periodically,” said Claudio Fuentes, the chief operating officer and a co-founder.
Carhart gave TechCrunch an example. A company finishes its SOC 2 audit, then two weeks later deploys an AI agent that can reach customer data or change permissions. “The audit didn’t become invalid; it simply wasn’t designed to tell you in real time what changed afterward,” he said.
That is the same ground OWASP covered this week, when it moved excessive agency up its top 10 list for LLM applications. Spain’s data watchdog also reported a breach by an agent on 17 September.
The round will fund an expansion beyond compliance automation into continuous cybersecurity, the company said. That covers real-time monitoring, control validation and security testing across applications and infrastructure.
Comp AI already offers AI-powered penetration testing, which tests codebases and infrastructure for vulnerabilities, Carhart told TechCrunch. The company will hire across product, engineering, operations, sales, customer success and marketing, at its Miami headquarters and its New York office.
The software does not replace an independent audit review, the founders told TechCrunch, and it does not replace people. An agent might draft a policy, but a person still reviews and approves it, Carhart said.
“As agents take on more consequential actions over time, we believe the level of safeguards and human approval should increase accordingly,” he said. OpenAI published six misalignment incidents on 16 September.
Carhart founded the company with the brothers Claudio and Mariano Fuentes, TechCrunch reported. The three previously worked on LeapAI, a workflow platform that passed a million users before they shut it down.
They closed it after failing to find a use case sticky enough to justify more investment, Claudio Fuentes told TechCrunch. Getting LeapAI through SOC 2 by hand took months and pulled them off the product, he said.
Investors have been funding this area steadily. NeuralTrust raised $20m for AI agent security in June. Trent AI raised $13m in April to build multi-agent security .
“Growing to more than 1,000 customers this quickly is remarkable,” said Nathan Owen, a general partner at Grand Ventures. He said portfolio companies of his had moved to Comp AI from other compliance platforms.