As AI agents accelerate their integration into enterprise systems, security and compliance processes are also evolving. According to TechCrunch, cybersecurity and compliance startup Comp AI has completed a $34 million Series A round, planning to use the funds to expand its product offerings, bringing its total funding to $37.5 million.
Established last year and shifted to the compliance path
Comp AI was founded in January last year by Lewis Carhart, Claudio Fuentes, and Mariano Fuentes. The three founders previously co-operated the workflow platform LeapAI, but shut down the project after approximately two years and over one million users due to an inability to identify a sufficiently stable product-market fit.
The team said that the experience made them more familiar with product development for large language models and helped them realize that companies often need to invest significant manual time when navigating security and compliance processes like SOC 2, especially when selling to larger clients—processes that can directly impact deal velocity.
AI agents handle audit preparation tasks
Comp AI is currently developing an agent-based platform designed to automate repetitive tasks in enterprise security and compliance, including drafting security policies, gathering evidence for security audits, and continuously monitoring whether the enterprise meets relevant control requirements.
- AI agents can assist in drafting security policies.
- The platform can collect evidence for the audit process.
- The system continuously monitors compliance controls to ensure they meet requirements.
The company stated that this system does not replace independent audits or fully substitute human involvement. For example, AI agents can generate draft policies, but these still require review and approval by employees. The team believes that as AI agents take on more critical operations, human approval and safeguard measures must also be strengthened accordingly.
Continuous monitoring has become a product priority.
Comp AI also offers AI-powered penetration testing to proactively identify vulnerabilities in codebases and infrastructure. The company believes that traditional audits are more like periodic checks, but the security posture can change rapidly as companies continuously deploy new AI agents.
According to the founding team, if a company completes a SOC 2 audit and then deploys AI agents that can access customer data, modify internal permissions, or introduce new code risks, the original audit no longer reflects these changes in real time. Therefore, companies need more continuous security and compliance monitoring capabilities.
Comp AI's current approach is to start with permission management and accountability tracking, helping companies log what AI agents access, which operations they attempt, and whether they exceed predefined boundaries. The company aims to ultimately establish a continuous security verification capability to adapt to the evolving landscape of enterprise AI systems.
