Comp AI raises $34M to monitor compliance between audits
Roo Capital and Grand Ventures backed Comp AI's move from audit preparation to continuous security monitoring.
By RuntimeWire Staff · Published
Primary source: TechCrunch
Why it matters
Comp AI is turning a recurring enterprise sales obstacle into continuous security infrastructure, with $34M to challenge established compliance platforms.

Comp AI, founded by Lewis Carhart (@lewisbuildsai), Claudio Fuentes (@claud_fuen), and Mariano Fuentes, raised a $34 million Series A to expand its AI-driven security and compliance platform, TechCrunch reported on September 17th.
Roo Capital and Grand Ventures led the round. TechCrunch's report puts Comp AI's total funding at $37.5 million. Comp AI has not published a valuation.
The financing gives Carhart and the Fuentes brothers considerably more capital for their second act together. Their first, Leap AI, attracted more than 1 million users before they shut it down after roughly two years. The founders had built a broad workflow platform around large language models and concluded that customers lacked a sufficiently persistent reason to keep using it.
Comp AI reflects the lesson they took from that experience: start with a narrow problem attached to a budget and a business deadline. The founders found that problem while pursuing larger customers for Leap AI, when SOC 2 compliance pulled them away from product work for months.
"It took us a couple of months of doing things by hand, and the whole time it meant taking our eyes off building the product," Claudio Fuentes told TechCrunch.
A narrower second act
Claudio and Mariano Fuentes had already spent close to a decade building together when they met Carhart and recruited him to Leap AI. Claudio ran Leap AI, Mariano worked as a senior full-stack engineer, and Carhart led growth. When they started Comp AI in January 2025, Carhart became CEO because the initial idea was his. Claudio took the COO role and Mariano became CTO.
The arrangement put the commercial founder closest to the compliance pain in charge of turning it into a product. Carhart's thesis is straightforward: for software vendors selling to larger businesses, compliance work becomes urgent when a prospective customer makes security approval a condition of signing.
"For a lot of software companies, security and compliance are directly tied to revenue," Carhart told TechCrunch.
Claudio brought a different mix of technical and enterprise experience. According to his biography, he is a self-taught full-stack engineer who previously led AI product work at Pypestream and co-founded Noonshot before Leap AI. He began his career producing electronic music as Klaud, including performances at Ultra Music Festival, an unusual apprenticeship in distribution for a founder now selling security infrastructure.
According to Carhart's LinkedIn profile, Comp AI launched publicly on April 16th, 2025. It announced a $2.6 million pre-seed that July, co-led by OSS Capital and Grand Ventures, with Sentry founder David Cramer and Ben Tossell participating. Grand Ventures has now returned as a Series A co-lead, giving Comp AI an investor that has watched the founders move from initial audit automation into a broader security product.
Compliance between audits
On its website, Comp AI says the platform automates evidence collection, policy generation, and continuous monitoring. Comp AI also advertises cloud monitoring and penetration testing. The same homepage advertises more than 580 integrations and names SOC 2, ISO 27001, HIPAA, GDPR, and FedRAMP among its supported frameworks.
Comp AI says more than 1,000 companies use the platform. Claudio Fuentes separately claims that Comp AI has passed $7.5 million in annual recurring revenue, according to his biography. The customer and revenue figures are self-reported.
Those metrics explain part of the Series A. The larger bet concerns what happens after an auditor finishes the report. A point-in-time audit can confirm that required controls worked during an observation period. It cannot automatically account for a new deployment, a changed permission, or an AI agent gaining access to customer data two weeks later.
Comp AI wants its agents to collect evidence continuously, flag failed controls, test infrastructure, and record what automated systems accessed or attempted. That expands Comp AI's job from helping customers prepare for an audit into monitoring the operational changes that can make yesterday's evidence stale.
Carhart offered TechCrunch a concrete example: a business can finish SOC 2 and then deploy an AI agent capable of accessing customer data, changing internal permissions, or introducing a vulnerability through a code release. The audit remains valid, though it was never designed to explain that new risk in real time.
This is where Comp AI is pushing beyond the familiar compliance automation market occupied by Vanta, Drata, Secureframe, and Sprinto. Those vendors have also expanded into continuous monitoring and AI governance. Comp AI's differentiator is its attempt to combine compliance workflows, active security testing, and open-source infrastructure in one product.
The public Comp AI repository is licensed under AGPL-3.0. Its README says 99% of the core is available under the AGPLv3 license, while enterprise components require a commercial license. That gives technical buyers a view into the agents and integrations handling sensitive evidence, while preserving paid features Comp AI can sell to larger customers.
Humans remain in the approval chain
Comp AI's agentic framing comes with an important limit. Independent auditors still issue audit reports. People onboard Comp AI, maintain workflows, review drafted policies, and approve consequential actions.
Carhart told TechCrunch that safeguards and human approval should increase as agents take on higher-impact work. That qualification matters in compliance, where an automated system can produce convincing documentation without proving that the underlying control operates as described.
The Series A will fund product expansion as Comp AI works toward monitoring permissions and accountability for autonomous software. Mariano Fuentes told TechCrunch that organizations deploying agents will need records showing what each agent accessed, what it attempted, and whether it stayed within its assigned boundaries.
Comp AI also has a physical expansion underway. In July, Comp AI established its headquarters in Aventura, Florida, where the founders planned to add 20 roles. The move put the main office near the South Florida roots of two founders while Comp AI maintained staff in New York and the United Kingdom.
For Carhart and the Fuentes brothers, the funding validates a narrower response to the failure of Leap AI. Comp AI is attached to a recurring enterprise requirement, a clear buyer, and a growing security problem created by software that can act without waiting for a human prompt. The $34 million round buys the founders time to prove that continuous compliance can become an operational security layer rather than another dashboard prepared for audit week.