Cybersecurity and compliance firm Comp AI announced on Thursday the completion of a $34 million Series A funding round. The investment was led by Roo Capital and Grand Ventures, bringing the company’s total capital raised to $37.5 million.
Established in January 2025, Comp AI was founded by CEO Lewis Carhart, COO Claudio Fuentes, and CTO Mariano Fuentes. The founders previously collaborated for nearly a decade on various ventures. Three years ago, Claudio and Mariano invited Carhart to join LeapAI, a workflow platform they were developing, where he served as head of growth while Mariano handled engineering. Although LeapAI reached over one million users, the team ultimately shut it down after determining the product lacked a sufficiently sticky use case to justify further investment.
That experience proved instructive, particularly regarding large language model development and the importance of identifying specific product applications. During the effort to scale LeapAI for enterprise clients, the founders found the SOC 2 compliance process excessively tedious. “It’s a very obscure process,” Claudio Fuentes noted. “It took us a couple of months of doing things by hand, and the whole time it meant taking our eyes off building the product.” This frustration sparked the creation of Comp AI.
Carhart, who originated the concept, now leads the company as CEO. Comp AI is constructing an agentic platform designed to handle labor-intensive security and compliance tasks. The system assists in drafting security policies, gathering evidence for audits, and continuously monitoring adherence to compliance controls. The startup positions itself within a new generation of cybersecurity firms emerging to support operational efficiency in the agentic era.
“For a lot of software companies, security and compliance are directly tied to revenue,” Carhart explained, citing instances where customers request SOC 2 reports prior to closing deals. “What Comp AI automates is much of the work companies traditionally have to do around that process.”
The platform aids organizations in meeting security standards but does not substitute for independent audit reviews or human oversight. According to the founders, human workers remain essential for onboarding the AI, supporting controls, and maintaining workflows. “An agent might draft a policy, for example, but a person still reviews and approves it,” Carhart said. “As agents take on more consequential actions over time, we believe the level of safeguards and human approval should increase accordingly.”
Additionally, the company provides AI-driven penetration testing, proactively scanning codebases and infrastructure for vulnerabilities. The newly raised funds will support product expansion.
The rise of agentic AI has intensified discussions regarding new security risks, prompting the growth of companies like Vanta and Drata. Carhart argued that the rapid adoption and experimentation with AI are driving demand for continuous, potentially autonomous, security and compliance solutions. He illustrated this with a scenario where a company completes a SOC 2 audit but deploys a new AI agent two weeks later that accesses customer data or introduces vulnerabilities. “The audit didn’t become invalid; it simply wasn’t designed to tell you in real time what changed afterward,” he said.
Mariano Fuentes emphasized that as companies integrate more AI, they must demonstrate what agents accessed, their intended actions, and whether they remained within defined boundaries. Comp AI aims to address this by focusing on permissions and accountability, building a security layer that continuously monitors and validates risks as these systems evolve.
This is a clever pivot from their failed LeapAI experience. Focusing on the compliance pain point makes total sense for their new venture.
Agentic security is crucial now, but I worry about liability when AI handles evidence gathering autonomously without oversight.
Finally, someone automates the tedious SOC 2 paperwork. Continuous monitoring beats the old annual audit model every time.