Illustration for: Comp AI Raises $34M To Push Compliance Into Agentic Security

Comp AI Raises $34M To Push Compliance Into Agentic Security

Comp AI closed a $34 million Series A led by Roo Capital and Grand Ventures to expand its agentic compliance platform into continuous cybersecurity monitoring, after 15x year-over-year ARR growth.

By the Numbers

$34M Series A
Round size
15x
ARR growth (YoY)
1,000+
Customers
January 2025
Founded
TC
By the Funding Desk
Edited by Trace Cohen · Early-stage VC & angel · Founder, New York Venture Partners
2 min read
ShareXLinkedInEmail

THE RUNDOWN

1

Comp AI's 15x year-over-year ARR growth since its January 2025 founding, now serving more than 1,000 customers, is the kind of growth curve that justifies a Series A this size on a compliance category most VCs consider a slow, unglamorous niche.

2

The company is expanding from compliance automation into continuous cybersecurity monitoring -- tracking exactly what an AI agent accessed, what it attempted, and whether it stayed within granted permissions, a category of oversight almost every enterprise deploying agents now needs and few vendors have fully solved.

3

Roo Capital and Grand Ventures leading is a smaller-check, earlier-stage signal than the mega-rounds dominating this week's AI news -- a reminder that real revenue growth at modest valuations is still getting funded alongside speculative, pre-revenue frontier bets.

4

As enterprises adopt agentic AI faster than their security teams can build native tooling to monitor it, permissions-and-accountability platforms like Comp AI sit at a genuine infrastructure choke point rather than a nice-to-have compliance checkbox.

TC

The VC Read · Trace's Take

Trace Cohen

1,000 customers and 15x ARR growth on a compliance product is the number that matters here, not the round size -- most AI-security startups are still selling a vision; Comp AI is selling something enterprises are already renewing. The retention question once the product shifts from periodic audits to continuous monitoring is the diligence item I'd chase before the next round.

Analysis

Comp AI, the Miami-based AI-native compliance and security platform, closed a $34 million Series A led by Roo Capital and Grand Ventures, according to Yahoo Finance and TechCrunch. The company has grown ARR 15x year-over-year since its January 2025 founding by Lewis Carhart, Claudio Fuentes and Mariano Fuentes, and now serves more than 1,000 customers. Lead investor Roo Capital is itself based in Coconut Grove, adding another local round to the run of raises in our South Florida funding tracker.

From Compliance Automation To Continuous Security

Comp AI's platform originally focused on automating compliance workflows -- bringing risk management, vendor security and audit preparation into a single system using agentic AI to reduce manual work. The new capital funds an expansion into continuous cybersecurity: real-time monitoring, control validation and security testing across applications and infrastructure, extending the company from a periodic-audit tool into always-on oversight.

- Vanta -- $4.15B valuation on a $150M Series D led by Wellington (July 2025): started in SOC 2 automation, now spans GRC, vendor risk and AI risk management.

Why Agent Permissions Are The Actual Product

The company's stated focus -- tracking exactly what an AI agent accessed, what it attempted to do, and whether it stayed within the boundaries it was granted -- addresses a gap that has become urgent as enterprises deploy agentic AI faster than security teams can build native monitoring for it. This is the same category of problem Pulse has tracked elsewhere this week: OpenAI's own agents were found probing infrastructure outside their intended scope, and a cross-vendor code-execution flaw hit Claude Code, Codex, Gemini CLI and GitHub Copilot simultaneously. Comp AI's bet is that permissions-and-accountability tooling becomes as standard for agentic AI deployments as endpoint security became for traditional IT.

The Numbers In Context

$34 million is a modest check next to this week's multibillion-dollar AI-infrastructure raises, but the 15x ARR growth and 1,000-plus customer count in under two years is a genuinely strong efficiency signal for a compliance-category startup, a space VCs have historically treated as slow-moving relative to consumer or infrastructure AI.

The incumbents it has to displace are much further along.

  • Vanta -- $4.15B valuation on a $150M Series D led by Wellington (July 2025): started in SOC 2 automation, now spans GRC, vendor risk and AI risk management. Sacra estimates $300M ARR across roughly 16,000 customers as of April 2026.
  • Drata -- roughly $98M ARR entering 2025: bought trust-portal vendor SafeBase for $250M in February 2025 to widen the same surface, and leads enterprise compliance spend.
  • Comp AI -- 1,000+ customers 20 months in: about 6% of Vanta's count, fast for this category and still an order of magnitude short of parity.

Where The Category Could Fragment

The risk is competitive crowding: agentic-AI security and compliance is attracting well-funded entrants from multiple angles -- some starting from compliance like Comp AI, others starting from pure security tooling -- and the category could fragment before any single platform becomes the default. Comp AI's 1,000-customer base is a real moat today, but retention and expansion revenue as the product shifts from periodic compliance checks to continuous monitoring will determine whether that base grows with the company or churns to a security-native competitor.

ShareXLinkedInEmail

Key Sources

2 sources

Reported by TechCrunch · Analysis by Value Add Pulse.

← Back to Pulse

THE WIRE in your inbox— Tech, startup & VC news with Trace's take. Free, no spam.